comment.module 65.4 KB
Newer Older
1
<?php
2
// $Id$
Dries's avatar
 
Dries committed
3

Dries's avatar
Dries committed
4 5
/**
 * @file
Dries's avatar
 
Dries committed
6
 * Enables users to comment on published content.
Dries's avatar
Dries committed
7 8 9 10 11 12
 *
 * When enabled, the Drupal comment module creates a discussion
 * board for each Drupal node. Users can post comments to discuss
 * a forum topic, weblog post, story, collaborative book page, etc.
 */

13
/*
Dries's avatar
Dries committed
14
 * Constants to define a comment's published state
15
 */
Dries's avatar
Dries committed
16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59
define('COMMENT_PUBLISHED', 0);
define('COMMENT_NOT_PUBLISHED', 1);

/**
 * Constants to define the viewing modes for comment listings
 */
define('COMMENT_MODE_FLAT_COLLAPSED', 0);
define('COMMENT_MODE_FLAT_EXPANDED', 1);
define('COMMENT_MODE_THREADED_COLLAPSED', 2);
define('COMMENT_MODE_THREADED_EXPANDED', 3);

/**
 * Constants to define the viewing orders for comment listings
 */
define('COMMENT_ORDER_NEWEST_FIRST', 0);
define('COMMENT_ORDER_OLDEST_FIRST', 1);

/**
 * Constants to define the position of the comment controls
 */
define('COMMENT_CONTROLS_ABOVE', 0);
define('COMMENT_CONTROLS_BELOW', 1);
define('COMMENT_CONTROLS_ABOVE_BELOW', 2);
define('COMMENT_CONTROLS_HIDDEN', 3);

/**
 * Constants to define the anonymous poster contact handling
 */
define('COMMENT_ANONYMOUS_MAYNOT_CONTACT', 0);
define('COMMENT_ANONYMOUS_MAY_CONTACT', 1);
define('COMMENT_ANONYMOUS_MUST_CONTACT', 2);

/**
 * Constants to define the comment form location
 */
define('COMMENT_FORM_SEPARATE_PAGE', 0);
define('COMMENT_FORM_BELOW', 1);

/**
 * Constants to define a node's comment state
 */
define('COMMENT_NODE_DISABLED', 0);
define('COMMENT_NODE_READ_ONLY', 1);
define('COMMENT_NODE_READ_WRITE', 2);
60

61 62 63 64 65 66
/**
 * Constants to define if comment preview is optional or required
 */
define('COMMENT_PREVIEW_OPTIONAL', 0);
define('COMMENT_PREVIEW_REQUIRED', 1);

67 68 69
/**
 * Implementation of hook_help().
 */
70
function comment_help($section) {
Dries's avatar
 
Dries committed
71
  switch ($section) {
Dries's avatar
 
Dries committed
72
    case 'admin/help#comment':
73
      $output = '<p>'. t('The comment module creates a discussion board for each post. Users can post comments to discuss a forum topic, weblog post, story, collaborative book page, etc. The ability to comment is an important part of involving members in a communtiy dialogue.') .'</p>';
74
      $output .= '<p>'. t('An administrator can give comment permissions to user groups, and users can (optionally) edit their last comment, assuming no others have been posted since.  Attached to each comment board is a control panel for customizing the way that comments are displayed. Users can control the chronological ordering of posts (newest or oldest first) and the number of posts to display on each page.  Comments behave like other user submissions. Filters, smileys and HTML that work in nodes will also work with comments. The comment module provides specific features to inform site members when new comments have been posted.') .'</p>';
75 76 77 78 79 80 81 82 83 84
      $output .= t('<p>You can</p>
<ul>
<li>control access for various comment module functions through access permissions <a href="%admin-access">administer &gt;&gt; access control</a>.</li>
<li>administer comments <a href="%admin-comment-configure"> administer &gt;&gt; comments &gt;&gt; configure</a>.</li>
</ul>
', array('%admin-access' => url('admin/access'), '%admin-comment-configure' => url('admin/comment/configure')));
      $output .= '<p>'. t('For more information please read the configuration and customization handbook <a href="%comment">Comment page</a>.', array('%comment' => 'http://www.drupal.org/handbook/modules/comment/')) .'</p>';
      return $output;
    case 'admin/modules#description':
      return t('Allows users to comment on and discuss published content.');
Dries's avatar
 
Dries committed
85
    case 'admin/comment':
86
    case 'admin/comment/new':
87
      return t("<p>Below is a list of the latest comments posted to your site. Click on a subject to see the comment, the author's name to edit the author's user information , \"edit\" to modify the text, and \"delete\" to remove their submission.</p>");
Dries's avatar
 
Dries committed
88
    case 'admin/comment/approval':
89
      return t("<p>Below is a list of the comments posted to your site that need approval. To approve a comment, click on \"edit\" and then change its \"moderation status\" to Approved. Click on a subject to see the comment, the author's name to edit the author's user information, \"edit\" to modify the text, and \"delete\" to remove their submission.</p>");
Dries's avatar
Dries committed
90 91
    case 'admin/comment/configure':
    case 'admin/comment/configure/settings':
92
      return t("<p>Comments can be attached to any node, and their settings are below. The display comes in two types: a \"flat list\" where everything is flush to the left side, and comments come in chronological order, and a \"threaded list\" where replies to other comments are placed immediately below and slightly indented, forming an outline. They also come in two styles: \"expanded\", where you see both the title and the contents, and \"collapsed\" where you only see the title. Preview comment forces a user to look at their comment by clicking on a \"Preview\" button before they can actually add the comment.</p>");
93
   }
Dries's avatar
 
Dries committed
94 95
}

Dries's avatar
 
Dries committed
96 97 98
/**
 * Implementation of hook_menu().
 */
Dries's avatar
 
Dries committed
99
function comment_menu($may_cache) {
Dries's avatar
 
Dries committed
100 101
  $items = array();

Dries's avatar
 
Dries committed
102 103 104 105 106 107 108 109 110 111 112 113
  if ($may_cache) {
    $access = user_access('administer comments');
    $items[] = array('path' => 'admin/comment', 'title' => t('comments'),
      'callback' => 'comment_admin_overview', 'access' => $access);

    // Tabs:
    $items[] = array('path' => 'admin/comment/list', 'title' => t('list'),
      'type' => MENU_DEFAULT_LOCAL_TASK, 'weight' => -10);
    $items[] = array('path' => 'admin/comment/configure', 'title' => t('configure'),
      'callback' => 'comment_configure', 'access' => $access, 'type' => MENU_LOCAL_TASK);

    // Subtabs:
114
    $items[] = array('path' => 'admin/comment/list/new', 'title' => t('published comments'),
Dries's avatar
 
Dries committed
115 116 117
      'type' => MENU_DEFAULT_LOCAL_TASK, 'weight' => -10);
    $items[] = array('path' => 'admin/comment/list/approval', 'title' => t('approval queue'),
      'callback' => 'comment_admin_overview', 'access' => $access,
118
      'callback arguments' => array('approval'),
Dries's avatar
 
Dries committed
119 120 121 122 123 124
      'type' => MENU_LOCAL_TASK);

    $items[] = array('path' => 'admin/comment/configure/settings', 'title' => t('settings'),
      'type' => MENU_DEFAULT_LOCAL_TASK, 'weight' => -10);

    $access = user_access('post comments');
125
    $items[] = array('path' => 'comment/edit', 'title' => t('edit comment'),
Dries's avatar
 
Dries committed
126
      'callback' => 'comment_edit', 'access' => $access, 'type' => MENU_CALLBACK);
127 128
    $items[] = array('path' => 'comment/delete', 'title' => t('delete comment'),
      'callback' => 'comment_delete', 'access' => $access, 'type' => MENU_CALLBACK);
Dries's avatar
 
Dries committed
129
  }
Dries's avatar
 
Dries committed
130 131
  else {
    if (arg(0) == 'comment' && arg(1) == 'reply' && is_numeric(arg(2))) {
132
      $node = node_load(arg(2));
Dries's avatar
 
Dries committed
133 134 135 136 137 138 139 140 141 142
      if ($node->nid) {
        $items[] = array('path' => 'comment/reply', 'title' => t('reply to comment'),
          'callback' => 'comment_reply', 'access' => node_access('view', $node), 'type' => MENU_CALLBACK);
      }
    }
    if ((arg(0) == 'node') && is_numeric(arg(1)) && is_numeric(arg(2))) {
      $items[] = array('path' => ('node/'. arg(1) .'/'. arg(2)), 'title' => t('view'),
        'callback' => 'node_page',
        'type' => MENU_CALLBACK);
    }
Dries's avatar
 
Dries committed
143
  }
Dries's avatar
 
Dries committed
144 145 146 147 148 149 150 151

  return $items;
}

/**
 * Implementation of hook_perm().
 */
function comment_perm() {
152
  return array('access comments', 'post comments', 'administer comments', 'post comments without approval');
Dries's avatar
 
Dries committed
153 154 155 156 157 158 159 160 161 162 163 164
}

/**
 * Implementation of hook_block().
 *
 * Generates a block with the most recent comments.
 */
function comment_block($op = 'list', $delta = 0) {
  if ($op == 'list') {
    $blocks[0]['info'] = t('Recent comments');
    return $blocks;
  }
165
  else if ($op == 'view' && user_access('access comments')) {
Dries's avatar
 
Dries committed
166
    $block['subject'] = t('Recent comments');
167
    $block['content'] = theme('comment_block');
Dries's avatar
 
Dries committed
168 169 170 171
    return $block;
  }
}

172 173 174 175 176 177 178 179 180
function theme_comment_block() {
  $result = db_query_range(db_rewrite_sql('SELECT c.nid, c.* FROM {comments} c INNER JOIN {node} n ON n.nid = c.nid WHERE n.status = 1 AND c.status = %d ORDER BY c.timestamp DESC', 'c'), COMMENT_PUBLISHED, 0, 10);
  $items = array();
  while ($comment = db_fetch_object($result)) {
    $items[] = l($comment->subject, 'node/'. $comment->nid, NULL, NULL, 'comment-'. $comment->cid) .'<br />'. t('%time ago', array('%time' => format_interval(time() - $comment->timestamp)));
  }
  return theme('item_list', $items);
}

Dries's avatar
 
Dries committed
181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203
/**
 * Implementation of hook_link().
 */
function comment_link($type, $node = 0, $main = 0) {
  $links = array();

  if ($type == 'node' && $node->comment) {

    if ($main) {
      // Main page: display the number of comments that have been posted.

      if (user_access('access comments')) {
        $all = comment_num_all($node->nid);
        $new = comment_num_new($node->nid);

        if ($all) {
          $links[] = l(format_plural($all, '1 comment', '%count comments'), "node/$node->nid", array('title' => t('Jump to the first comment of this posting.')), NULL, 'comment');

          if ($new) {
            $links[] = l(format_plural($new, '1 new comment', '%count new comments'), "node/$node->nid", array('title' => t('Jump to the first new comment of this posting.')), NULL, 'new');
          }
        }
        else {
Dries's avatar
Dries committed
204
          if ($node->comment == COMMENT_NODE_READ_WRITE) {
Dries's avatar
 
Dries committed
205 206 207 208 209 210 211 212 213 214 215 216 217 218
            if (user_access('post comments')) {
              $links[] = l(t('add new comment'), "comment/reply/$node->nid", array('title' => t('Add a new comment to this page.')));
            }
            else {
              $links[] = theme('comment_post_forbidden');
            }
          }
        }
      }
    }
    else {
      // Node page: add a "post comment" link if the user is allowed to
      // post comments, if this node is not read-only, and if the comment form isn't already shown

Dries's avatar
Dries committed
219
      if ($node->comment == COMMENT_NODE_READ_WRITE && variable_get('comment_form_location', COMMENT_FORM_SEPARATE_PAGE) == COMMENT_FORM_SEPARATE_PAGE) {
Dries's avatar
 
Dries committed
220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236
        if (user_access('post comments')) {
          $links[] = l(t('add new comment'), "comment/reply/$node->nid", array('title' => t('Share your thoughts and opinions related to this posting.')), NULL, 'comment');
        }
        else {
          $links[] = theme('comment_post_forbidden');
        }
      }
    }
  }

  if ($type == 'comment') {
    $links = comment_links($node, $main);
  }

  return $links;
}

237
function comment_form_alter($form_id, &$form) {
238 239 240 241
  if (isset($form['type'])) {
    if ($form['type']['#value'] .'_node_settings' == $form_id) {
      $form['workflow']['comment_'. $form['type']['#value']] = array('#type' => 'radios', '#title' => t('Default comment setting'), '#default_value' => variable_get('comment_'. $form['type']['#value'], COMMENT_NODE_READ_WRITE), '#options' => array(t('Disabled'), t('Read only'), t('Read/Write')), '#description' => t('Users with the <em>administer comments</em> permission will be able to override this setting.'));
    }
242
    if ($form['type']['#value'] .'_node_form' == $form_id) {
243
      $node = $form['#node'];
244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264
      if (user_access('administer comments')) {
        $form['user_comments'] = array(
          '#type' => 'fieldset',
          '#title' => t('User comments'),
          '#collapsible' => TRUE,
          '#collapsed' => TRUE,
          '#weight' => 30,
        );
        $form['user_comments']['comment'] = array(
          '#type' => 'radios',
          '#parents' => array('comment'),
          '#default_value' => $node->comment,
          '#options' => array(t('Disabled'), t('Read only'), t('Read/Write')),
        );
      }
      else {
        $form['user_comments']['comment'] = array(
          '#type' => 'value',
          '#value' => $node->comment,
        );
      }
265
    }
266 267 268
  }
}

Dries's avatar
 
Dries committed
269 270
/**
 * Implementation of hook_nodeapi().
Dries's avatar
 
Dries committed
271
 *
Dries's avatar
 
Dries committed
272 273 274 275 276
 */
function comment_nodeapi(&$node, $op, $arg = 0) {
  switch ($op) {
    case 'fields':
      return array('comment');
277

Dries's avatar
 
Dries committed
278
    case 'load':
279
      return db_fetch_array(db_query("SELECT last_comment_timestamp, last_comment_name, comment_count FROM {node_comment_statistics} WHERE nid = %d", $node->nid));
280 281 282 283
      break;

    case 'prepare':
      if (!isset($node->comment)) {
Dries's avatar
Dries committed
284
        $node->comment = variable_get("comment_$node->type", COMMENT_NODE_READ_WRITE);
Dries's avatar
 
Dries committed
285 286
      }
      break;
287

Dries's avatar
 
Dries committed
288
    case 'insert':
289
      db_query('INSERT INTO {node_comment_statistics} (nid, last_comment_timestamp, last_comment_name, last_comment_uid, comment_count) VALUES (%d, %d, NULL, %d, 0)', $node->nid, $node->created, $node->uid);
Dries's avatar
 
Dries committed
290
      break;
291

Dries's avatar
 
Dries committed
292
    case 'delete':
Dries's avatar
 
Dries committed
293 294
      db_query('DELETE FROM {comments} WHERE nid = %d', $node->nid);
      db_query('DELETE FROM {node_comment_statistics} WHERE nid = %d', $node->nid);
Dries's avatar
 
Dries committed
295
      break;
296

Dries's avatar
Dries committed
297 298
    case 'update index':
      $text = '';
299
      $comments = db_query('SELECT subject, comment, format FROM {comments} WHERE nid = %d AND status = %d', $node->nid, COMMENT_PUBLISHED);
Dries's avatar
Dries committed
300
      while ($comment = db_fetch_object($comments)) {
301
        $text .= '<h2>'. check_plain($comment->subject) .'</h2>'. check_markup($comment->comment, $comment->format, FALSE);
Dries's avatar
Dries committed
302 303
      }
      return $text;
304

Dries's avatar
Dries committed
305 306 307
    case 'search result':
      $comments = db_result(db_query('SELECT comment_count FROM {node_comment_statistics} WHERE nid = %d', $node->nid));
      return format_plural($comments, '1 comment', '%count comments');
308

Steven Wittens's avatar
- Typo  
Steven Wittens committed
309
    case 'rss item':
Steven Wittens's avatar
Steven Wittens committed
310
      return array(array('key' => 'comments', 'value' => url('node/'. $node->nid, NULL, 'comment', TRUE)));
Dries's avatar
 
Dries committed
311 312 313 314 315 316 317 318 319 320 321
  }
}

/**
 * Implementation of hook_user().
 *
 * Provides signature customization for the user's comments.
 */
function comment_user($type, $edit, &$user, $category = NULL) {
  if ($type == 'form' && $category == 'account') {
    // when user tries to edit his own data
322 323 324 325 326 327 328 329 330 331
    $form['comment_settings'] = array(
      '#type' => 'fieldset',
      '#title' => t('Comment settings'),
      '#collapsible' => TRUE,
      '#weight' => 4);
    $form['comment_settings']['signature'] = array(
      '#type' => 'textarea',
      '#title' => t('Signature'),
      '#default_value' => $edit['signature'],
      '#description' => t('Your signature will be publicly displayed at the end of your comments.'));
332 333

    return $form;
Dries's avatar
 
Dries committed
334 335 336
  }
}

337
/**
Dries's avatar
 
Dries committed
338
 * Menu callback; presents the comment settings page.
339
 */
Dries's avatar
 
Dries committed
340
function comment_configure() {
341 342
  $form['viewing_options'] = array(
    '#type' => 'fieldset',
343
    '#title' => t('Viewing options'),
344 345 346 347
    '#collapsible' => TRUE,
    '#collapsed' => TRUE,
    '#weight' => 0,
  );
Dries's avatar
 
Dries committed
348

Dries's avatar
Dries committed
349 350 351 352 353
  $form['viewing_options']['comment_default_mode'] = array(
    '#type' => 'radios',
    '#title' => t('Default display mode'),
    '#default_value' => variable_get('comment_default_mode', COMMENT_MODE_THREADED_EXPANDED),
    '#options' => _comment_get_modes(),
354
    '#description' => t('The default view for comments. Expanded views display the body of the comment. Threaded views keep replies together.'),
Dries's avatar
Dries committed
355
  );
356

Dries's avatar
Dries committed
357 358 359
  $form['viewing_options']['comment_default_order'] = array(
    '#type' => 'radios',
    '#title' => t('Default display order'),
360
    '#default_value' => variable_get('comment_default_order', COMMENT_ORDER_NEWEST_FIRST),
Dries's avatar
Dries committed
361
    '#options' => _comment_get_orders(),
362
    '#description' => t('The default sorting for new users and anonymous users while viewing comments. These users may change their view using the comment control panel. For registered users, this change is remembered as a persistent user preference.'),
Dries's avatar
Dries committed
363
  );
Dries's avatar
 
Dries committed
364

365
  $form['viewing_options']['comment_default_per_page'] = array(
366 367 368 369
    '#type' => 'select',
    '#title' => t('Default comments per page'),
    '#default_value' => variable_get('comment_default_per_page', 50),
    '#options' => _comment_per_page(),
370
    '#description' => t('Default number of comments for each page: more comments are distributed in several pages.'),
371 372
  );

Dries's avatar
Dries committed
373 374 375 376 377 378 379 380 381
  $form['viewing_options']['comment_controls'] = array(
    '#type' => 'radios',
    '#title' => t('Comment controls'),
    '#default_value' => variable_get('comment_controls', COMMENT_CONTROLS_HIDDEN),
    '#options' => array(
      t('Display above the comments'),
      t('Display below the comments'),
      t('Display above and below the comments'),
      t('Do not display')),
382
    '#description' => t('Position of the comment controls box.  The comment controls let the user change the default display mode and display order of comments.'),
Dries's avatar
Dries committed
383
  );
384

385 386
  $form['posting_settings'] = array(
    '#type' => 'fieldset',
387
    '#title' => t('Posting settings'),
388 389 390 391
    '#collapsible' => TRUE,
    '#collapsed' => TRUE,
    '#weight' => 0,
  );
392

Dries's avatar
Dries committed
393 394 395 396 397 398 399 400
  $form['posting_settings']['comment_anonymous'] = array(
    '#type' => 'radios',
    '#title' => t('Comment controls'),
    '#default_value' => variable_get('comment_anonymous', COMMENT_ANONYMOUS_MAYNOT_CONTACT),
    '#options' => array(
      COMMENT_ANONYMOUS_MAYNOT_CONTACT => t('Anonymous posters may not enter their contact information'),
      COMMENT_ANONYMOUS_MAY_CONTACT => t('Anonymous posters may leave their contact information'),
      COMMENT_ANONYMOUS_MUST_CONTACT => t('Anonymous posters must leave their contact information')),
401
    '#description' => t('This feature is only useful if you allow anonymous users to post comments.  See the <a href="%url">permissions page</a>.', array('%url' => url('admin/access/permissions'))),
Dries's avatar
Dries committed
402
  );
403 404

  $form['posting_settings']['comment_subject_field'] = array(
405 406 407 408
    '#type' => 'radios',
    '#title' => t('Comment subject field'),
    '#default_value' => variable_get('comment_subject_field', 1),
    '#options' => array(t('Disabled'), t('Enabled')),
409
    '#description' => t('Can users provide a unique subject for their comments?'),
410 411
  );

412 413 414 415 416 417
  $form['posting_settings']['comment_preview'] = array(
    '#type' => 'radios',
    '#title' => t('Preview comment'),
    '#default_value' => variable_get('comment_preview', COMMENT_PREVIEW_REQUIRED),
    '#options' => array(t('Optional'), t('Required')),
  );
418

Dries's avatar
Dries committed
419 420 421 422
  $form['posting_settings']['comment_form_location'] = array(
    '#type' => 'radios',
    '#title' => t('Location of comment submission form'),
    '#default_value' => variable_get('comment_form_location', COMMENT_FORM_SEPARATE_PAGE),
423
    '#options' => array(t('Display on separate page'), t('Display below post or comments')),
Dries's avatar
Dries committed
424
  );
425 426

  return system_settings_form('comment_settings_form', $form);
Dries's avatar
 
Dries committed
427 428
}

429 430 431 432 433 434 435 436 437 438
/**
 * This is *not* a hook_access() implementation. This function is called
 * to determine whether the current user has access to a particular comment.
 *
 * Authenticated users can edit their comments as long they have not been
 * replied to. This prevents people from changing or revising their
 * statements based on the replies their posts got. Furthermore, users
 * can't reply to their own comments and are encouraged instead to extend
 * their original comment.
 */
Dries's avatar
 
Dries committed
439
function comment_access($op, $comment) {
Dries's avatar
 
Dries committed
440 441
  global $user;

442
  if ($op == 'edit') {
443
    return ($user->uid && $user->uid == $comment->uid && comment_num_replies($comment->cid) == 0) || user_access('administer comments');
Dries's avatar
 
Dries committed
444 445
  }
}
446

Dries's avatar
 
Dries committed
447
function comment_node_url() {
Dries's avatar
Dries committed
448
  return arg(0) .'/'. arg(1);
Dries's avatar
 
Dries committed
449
}
Dries's avatar
 
Dries committed
450

Dries's avatar
 
Dries committed
451 452 453
function comment_edit($cid) {
  global $user;

454
  $comment = db_fetch_object(db_query('SELECT c.*, u.uid, u.name AS registered_name, u.data FROM {comments} c INNER JOIN {users} u ON c.uid = u.uid WHERE c.cid = %d', $cid));
Dries's avatar
 
Dries committed
455
  $comment = drupal_unpack($comment);
456
  $comment->name = $comment->uid ? $comment->registered_name : $comment->name;
457
  if (comment_access('edit', $comment)) {
458
    return comment_form((array)$comment);
459 460 461
  }
  else {
    drupal_access_denied();
Dries's avatar
 
Dries committed
462 463 464
  }
}

Dries's avatar
Dries committed
465
function comment_reply($nid, $pid = NULL) {
466
  // set the breadcrumb trail
467
  $node = node_load($nid);
468
  menu_set_location(array(array('path' => "node/$nid", 'title' => $node->title), array('path' => "comment/reply/$nid")));
Dries's avatar
 
Dries committed
469

470
  $op = isset($_POST['op']) ? $_POST['op'] : '';
Dries's avatar
 
Dries committed
471

472
  $output = '';
Dries's avatar
 
Dries committed
473

Dries's avatar
Dries committed
474 475 476
  // or are we merely showing the form?
  if (user_access('access comments')) {

477 478 479 480 481 482 483
    if ($op == t('Preview comment')) {
      if (user_access('post comments')) {
        $output .= comment_form(array('pid' => $pid, 'nid' => $nid), NULL);
      }
      else {
        drupal_set_message(t('You are not authorized to post comments.'), 'error');
      }
Dries's avatar
 
Dries committed
484 485
    }
    else {
486 487 488 489 490 491 492 493 494 495 496 497 498 499 500 501 502 503 504 505 506 507 508
      // if this is a reply to another comment, show that comment first
      // else, we'll just show the user the node they're commenting on.
      if ($pid) {
        $comment = db_fetch_object(db_query('SELECT c.*, u.uid, u.name AS registered_name, u.picture, u.data FROM {comments} c INNER JOIN {users} u ON c.uid = u.uid WHERE c.cid = %d AND c.status = %d', $pid, COMMENT_PUBLISHED));
        $comment = drupal_unpack($comment);
        $comment->name = $comment->uid ? $comment->registered_name : $comment->name;
        $output .= theme('comment_view', $comment);
      }
      else if (user_access('access content')) {
        $output .= node_view($node);
        $pid = 0;
      }

      // should we show the reply box?
      if (node_comment_mode($nid) != COMMENT_NODE_READ_WRITE) {
        drupal_set_message(t("This discussion is closed: you can't post new comments."), 'error');
      }
      else if (user_access('post comments')) {
        $output .= comment_form(array('pid' => $pid, 'nid' => $nid), t('Reply'));
      }
      else {
        drupal_set_message(t('You are not authorized to post comments.'), 'error');
      }
Dries's avatar
 
Dries committed
509
    }
Kjartan's avatar
Kjartan committed
510 511
  }
  else {
512
    drupal_set_message(t('You are not authorized to view comments.'), 'error');
Dries's avatar
 
Dries committed
513
  }
Dries's avatar
 
Dries committed
514

Dries's avatar
 
Dries committed
515
  return $output;
Dries's avatar
 
Dries committed
516 517
}

518 519 520 521 522 523 524 525 526 527 528
/**
 * Accepts a submission of new or changed comment content.
 *
 * @param $edit
 *   A comment array.
 *
 * @return
 *   If the comment is successfully saved the comment ID is returned.  If the comment
 *   is not saved, FALSE is returned.
 */
function comment_save($edit) {
Dries's avatar
 
Dries committed
529
  global $user;
530
  if (user_access('post comments') && (user_access('administer coments') || node_comment_mode($edit['nid']) == COMMENT_NODE_READ_WRITE)) {
Dries's avatar
 
Dries committed
531
    if (!form_get_errors()) {
532 533
      // Check for duplicate comments.  Note that we have to use the
      // validated/filtered data to perform such check.
534
      $duplicate = db_result(db_query("SELECT COUNT(cid) FROM {comments} WHERE pid = %d AND nid = %d AND subject = '%s' AND comment = '%s'", $edit['pid'], $edit['nid'], $edit['subject'], $edit['comment']), 0);
Dries's avatar
 
Dries committed
535
      if ($duplicate != 0) {
536
        watchdog('content', t('Comment: duplicate %subject.', array('%subject' => theme('placeholder', $edit['subject']))), WATCHDOG_WARNING);
Dries's avatar
 
Dries committed
537
      }
Dries's avatar
 
Dries committed
538

539
      if ($edit['cid']) {
540
        // Update the comment in the database.
541
        db_query("UPDATE {comments} SET status = '%s', timestamp = %d, subject = '%s', comment = '%s', format = '%s', uid = %d, name = '%s', mail = '%s', homepage = '%s' WHERE cid = %d", $edit['status'], $edit['timestamp'], $edit['subject'], $edit['comment'], $edit['format'], $edit['uid'], $edit['name'], $edit['mail'], $edit['homepage'], $edit['cid']);
Dries's avatar
 
Dries committed
542

Dries's avatar
 
Dries committed
543 544
        _comment_update_node_statistics($edit['nid']);

545
        // Allow modules to respond to the updating of a comment.
546 547
        comment_invoke_comment($edit, 'update');

Dries's avatar
 
Dries committed
548

Dries's avatar
Dries committed
549
        // Add an entry to the watchdog log.
550
        watchdog('content', t('Comment: updated %subject.', array('%subject' => theme('placeholder', $edit['subject']))), WATCHDOG_NOTICE, l(t('view'), 'node/'. $edit['nid'], NULL, NULL, 'comment-'. $edit['cid']));
Dries's avatar
 
Dries committed
551 552
      }
      else {
553
        // Add the comment to database.
554
        $status = user_access('post comments without approval') ? COMMENT_PUBLISHED : COMMENT_NOT_PUBLISHED;
555
        $roles = variable_get('comment_roles', array());
Dries's avatar
 
Dries committed
556 557 558 559 560 561
        $score = 0;

        foreach (array_intersect(array_keys($roles), array_keys($user->roles)) as $rid) {
          $score = max($roles[$rid], $score);
        }

Dries's avatar
 
Dries committed
562 563
        $users = serialize(array(0 => $score));

564 565
        // Here we are building the thread field.  See the comment
        // in comment_render().
566
        if ($edit['pid'] == 0) {
567 568
          // This is a comment with no parent comment (depth 0): we start
          // by retrieving the maximum thread level.
569
          $max = db_result(db_query('SELECT MAX(thread) FROM {comments} WHERE nid = %d', $edit['nid']));
Dries's avatar
 
Dries committed
570

571 572
          // Strip the "/" from the end of the thread.
          $max = rtrim($max, '/');
Dries's avatar
 
Dries committed
573

574 575 576 577 578
          // Next, we increase this value by one.  Note that we can't
          // use 1, 2, 3, ... 9, 10, 11 because we order by string and
          // 10 would be right after 1.  We use 1, 2, 3, ..., 9, 91,
          // 92, 93, ... instead.  Ugly but fast.
          $decimals = (string) substr($max, 0, strlen($max) - 1);
Dries's avatar
 
Dries committed
579 580 581 582 583 584 585 586 587
          $units = substr($max, -1, 1);
          if ($units) {
            $units++;
          }
          else {
            $units = 1;
          }

          if ($units == 10) {
588
            $units = '90';
Dries's avatar
 
Dries committed
589 590
          }

591
          // Finally, build the thread field for this new comment.
592
          $thread = $decimals . $units .'/';
Dries's avatar
 
Dries committed
593 594
        }
        else {
595 596
          // This is comment with a parent comment: we increase
          // the part of the thread value at the proper depth.
Dries's avatar
 
Dries committed
597 598

          // Get the parent comment:
599
          $parent = _comment_load($edit['pid']);
Dries's avatar
 
Dries committed
600

601
          // Strip the "/" from the end of the parent thread.
602
          $parent->thread = (string) rtrim((string) $parent->thread, '/');
Dries's avatar
 
Dries committed
603

604
          // Get the max value in _this_ thread.
Dries's avatar
 
Dries committed
605
          $max = db_result(db_query("SELECT MAX(thread) FROM {comments} WHERE thread LIKE '%s.%%' AND nid = %d", $parent->thread, $edit['nid']));
Dries's avatar
 
Dries committed
606

607 608
          if ($max == '') {
            // First child of this parent.
609
            $thread = $parent->thread .'.1/';
Dries's avatar
 
Dries committed
610 611
          }
          else {
612 613
            // Strip the "/" at the end of the thread.
            $max = rtrim($max, '/');
Dries's avatar
 
Dries committed
614

615 616 617
            // We need to get the value at the correct depth.
            $parts = explode('.', $max);
            $parent_depth = count(explode('.', $parent->thread));
Dries's avatar
 
Dries committed
618 619
            $last = $parts[$parent_depth];

620 621 622 623
            // Next, we increase this value by one.  Note that we can't
            // use 1, 2, 3, ... 9, 10, 11 because we order by string and
            // 10 would be right after 1.  We use 1, 2, 3, ..., 9, 91,
            // 92, 93, ... instead.  Ugly but fast.
Dries's avatar
 
Dries committed
624 625 626 627
            $decimals = (string)substr($last, 0, strlen($last) - 1);
            $units = substr($last, -1, 1);
            $units++;
            if ($units == 10) {
628
              $units = '90';
Dries's avatar
 
Dries committed
629 630
            }

631
            // Finally, build the thread field for this new comment.
632
            $thread = $parent->thread .'.'. $decimals . $units .'/';
Dries's avatar
 
Dries committed
633 634 635
          }
        }

636
        $edit['cid'] = db_next_id('{comments}_cid');
Dries's avatar
 
Dries committed
637 638 639 640 641 642
        $edit['timestamp'] = time();

        if ($edit['uid'] = $user->uid) {
          $edit['name'] = $user->name;
        }

643
        db_query("INSERT INTO {comments} (cid, nid, pid, uid, subject, comment, format, hostname, timestamp, status, score, users, thread, name, mail, homepage) VALUES (%d, %d, %d, %d, '%s', '%s', %d, '%s', %d, %d, %d, '%s', '%s', '%s', '%s', '%s')", $edit['cid'], $edit['nid'], $edit['pid'], $edit['uid'], $edit['subject'], $edit['comment'], $edit['format'], $_SERVER['REMOTE_ADDR'], $edit['timestamp'], $status, $score, $users, $thread, $edit['name'], $edit['mail'], $edit['homepage']);
Dries's avatar
 
Dries committed
644 645

        _comment_update_node_statistics($edit['nid']);
Dries's avatar
 
Dries committed
646

647
        // Tell the other modules a new comment has been submitted.
648
        comment_invoke_comment($edit, 'insert');
Dries's avatar
 
Dries committed
649

650
        // Add an entry to the watchdog log.
651
        watchdog('content', t('Comment: added %subject.', array('%subject' => theme('placeholder', $edit['subject']))), WATCHDOG_NOTICE, l(t('view'), 'node/'. $edit['nid'], NULL, NULL, 'comment-'. $edit['cid']));
Dries's avatar
 
Dries committed
652
      }
Dries's avatar
 
Dries committed
653

654
      // Clear the cache so an anonymous user can see his comment being added.
Dries's avatar
 
Dries committed
655
      cache_clear_all();
Dries's avatar
 
Dries committed
656

Dries's avatar
 
Dries committed
657
      // Explain the approval queue if necessary, and then
Dries's avatar
 
Dries committed
658
      // redirect the user to the node he's commenting on.
659
      if ($status == COMMENT_NOT_PUBLISHED) {
Dries's avatar
 
Dries committed
660
        drupal_set_message(t('Your comment has been queued for moderation by site administrators and will be published after approval.'));
Dries's avatar
 
Dries committed
661
      }
662
      return $edit['cid'];
Dries's avatar
 
Dries committed
663 664
    }
    else {
665
      return FALSE;
Dries's avatar
 
Dries committed
666 667
    }
  }
Dries's avatar
 
Dries committed
668
  else {
669
    $txt = t('Comment: unauthorized comment submitted or comment submitted to a closed node %subject.', array('%subject' => theme('placeholder', $edit['subject'])));
670 671 672
    watchdog('content', $txt, WATCHDOG_WARNING);
    drupal_set_message($txt, 'error');
    return FALSE;
Dries's avatar
 
Dries committed
673 674 675 676
  }
}

function comment_links($comment, $return = 1) {
Dries's avatar
 
Dries committed
677
  global $user;
Dries's avatar
 
Dries committed
678

Dries's avatar
 
Dries committed
679
  $links = array();
Dries's avatar
 
Dries committed
680

681
  // If we are viewing just this comment, we link back to the node.
Dries's avatar
 
Dries committed
682
  if ($return) {
683
    $links[] = l(t('parent'), comment_node_url(), NULL, NULL, "comment-$comment->cid");
Dries's avatar
 
Dries committed
684
  }
Dries's avatar
 
Dries committed
685

686
  if (node_comment_mode($comment->nid) == COMMENT_NODE_READ_WRITE) {
687
    if (user_access('administer comments') && user_access('post comments')) {
688 689
      $links[] = l(t('delete'), "comment/delete/$comment->cid");
      $links[] = l(t('edit'), "comment/edit/$comment->cid");
Dries's avatar
 
Dries committed
690
      $links[] = l(t('reply'), "comment/reply/$comment->nid/$comment->cid");
691
    }
692 693
    else if (user_access('post comments')) {
      if (comment_access('edit', $comment)) {
Dries's avatar
 
Dries committed
694
        $links[] = l(t('edit'), "comment/edit/$comment->cid");
Dries's avatar
 
Dries committed
695
      }
Dries's avatar
 
Dries committed
696
      $links[] = l(t('reply'), "comment/reply/$comment->nid/$comment->cid");
Dries's avatar
 
Dries committed
697 698
    }
    else {
699
      $links[] = theme('comment_post_forbidden');
Dries's avatar
 
Dries committed
700
    }
Dries's avatar
 
Dries committed
701
  }
Dries's avatar
 
Dries committed
702

Dries's avatar
 
Dries committed
703
  return $links;
Dries's avatar
 
Dries committed
704 705
}

Dries's avatar
 
Dries committed
706
function comment_render($node, $cid = 0) {
Dries's avatar
 
Dries committed
707 708
  global $user;

709 710 711 712
  $mode = $_GET['mode'];
  $order = $_GET['order'];
  $comments_per_page = $_GET['comments_per_page'];
  $comment_page = $_GET['comment_page'];
Dries's avatar
 
Dries committed
713

714
  $output = '';
Dries's avatar
 
Dries committed
715

716 717
  if (user_access('access comments')) {
    // Pre-process variables.
Dries's avatar
 
Dries committed
718
    $nid = $node->nid;
Dries's avatar
 
Dries committed
719 720
    if (empty($nid)) {
      $nid = 0;
Dries's avatar
 
Dries committed
721 722 723
    }

    if (empty($mode)) {
Dries's avatar
Dries committed
724
      $mode = $user->mode ? $user->mode : ($_SESSION['comment_mode'] ? $_SESSION['comment_mode'] : variable_get('comment_default_mode', COMMENT_MODE_THREADED_EXPANDED));
Dries's avatar
 
Dries committed
725 726 727
    }

    if (empty($order)) {
Dries's avatar
Dries committed
728
      $order = $user->sort ? $user->sort : ($_SESSION['comment_sort'] ? $_SESSION['comment_sort'] : variable_get('comment_default_order', COMMENT_ORDER_NEWEST_FIRST));
Dries's avatar
 
Dries committed
729 730
    }

Dries's avatar
 
Dries committed
731
    if (empty($comments_per_page)) {
732
      $comments_per_page = $user->comments_per_page ? $user->comments_per_page : ($_SESSION['comment_comments_per_page'] ? $_SESSION['comment_comments_per_page'] : variable_get('comment_default_per_page', '50'));
Dries's avatar
 
Dries committed
733
    }
Dries's avatar
 
Dries committed
734

Dries's avatar
 
Dries committed
735
    $output .= "<a id=\"comment\"></a>\n";
Dries's avatar
 
Dries committed
736

Kjartan's avatar
Kjartan committed
737
    if ($cid) {
738
      // Single comment view.
739
      $result = db_query('SELECT c.cid, c.pid, c.nid, c.subject, c.comment, c.format, c.timestamp, c.name, c.mail, c.homepage, u.uid, u.name AS registered_name, u.picture, u.data, c.score, c.users FROM {comments} c INNER JOIN {users} u ON c.uid = u.uid WHERE c.cid = %d AND c.status = %d GROUP BY c.cid, c.pid, c.nid, c.subject, c.comment, c.format, c.timestamp, c.name, c.mail, u.picture, c.homepage, u.uid, u.name, u.picture, u.data, c.score, c.users', $cid, COMMENT_PUBLISHED);
Dries's avatar
 
Dries committed
740

Dries's avatar
 
Dries committed
741
      if ($comment = db_fetch_object($result)) {
742
        $comment->name = $comment->uid ? $comment->registered_name : $comment->name;
743
        $output .= theme('comment_view', $comment, module_invoke_all('link', 'comment', $comment, 1));
Dries's avatar
 
Dries committed
744
      }
Dries's avatar
 
Dries committed
745
    }
Dries's avatar
 
Dries committed
746
    else {
747
      // Multiple comment view
748
      $query .= "SELECT c.cid as cid, c.pid, c.nid, c.subject, c.comment, c.format, c.timestamp, c.name, c.mail, c.homepage, u.uid, u.name AS registered_name, u.picture, u.data, c.score, c.users, c.thread FROM {comments} c INNER JOIN {users} u ON c.uid = u.uid WHERE c.nid = %d AND c.status = %d";
Dries's avatar
 
Dries committed
749

750
      $query .= ' GROUP BY c.cid, c.pid, c.nid, c.subject, c.comment, c.format, c.timestamp, c.name, c.mail, u.picture, c.homepage, u.uid, u.name, u.picture, u.data, c.score, c.users, c.thread';
Dries's avatar
 
Dries committed
751

Dries's avatar
 
Dries committed
752 753 754 755 756 757 758 759 760 761 762 763 764 765 766 767 768 769 770 771 772 773 774 775 776 777 778 779 780 781 782 783 784 785 786 787 788 789 790 791 792 793 794 795 796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813
      /*
      ** We want to use the standard pager, but threads would need every
      ** comment to build the thread structure, so we need to store some
      ** extra info.
      **
      ** We use a "thread" field to store this extra info. The basic idea
      ** is to store a value and to order by that value. The "thread" field
      ** keeps this data in a way which is easy to update and convenient
      ** to use.
      **
      ** A "thread" value starts at "1". If we add a child (A) to this
      ** comment, we assign it a "thread" = "1.1". A child of (A) will have
      ** "1.1.1". Next brother of (A) will get "1.2". Next brother of the
      ** parent of (A) will get "2" and so on.
      **
      ** First of all note that the thread field stores the depth of the
      ** comment: depth 0 will be "X", depth 1 "X.X", depth 2 "X.X.X", etc.
      **
      ** Now to get the ordering right, consider this example:
      **
      ** 1
      ** 1.1
      ** 1.1.1
      ** 1.2
      ** 2
      **
      ** If we "ORDER BY thread ASC" we get the above result, and this is
      ** the natural order sorted by time.  However, if we "ORDER BY thread
      ** DESC" we get:
      **
      ** 2
      ** 1.2
      ** 1.1.1
      ** 1.1
      ** 1
      **
      ** Clearly, this is not a natural way to see a thread, and users
      ** will get confused. The natural order to show a thread by time
      ** desc would be:
      **
      ** 2
      ** 1
      ** 1.2
      ** 1.1
      ** 1.1.1
      **
      ** which is what we already did before the standard pager patch. To
      ** achieve this we simply add a "/" at the end of each "thread" value.
      ** This way out thread fields will look like depicted below:
      **
      ** 1/
      ** 1.1/
      ** 1.1.1/
      ** 1.2/
      ** 2/
      **
      ** we add "/" since this char is, in ASCII, higher than every number,
      ** so if now we "ORDER BY thread DESC" we get the correct order.  Try
      ** it, it works ;).  However this would spoil the "ORDER BY thread ASC"
      ** Here, we do not need to consider the trailing "/" so we use a
      ** substring only.
      */
Dries's avatar
 
Dries committed
814

Dries's avatar
Dries committed
815 816
      if ($order == COMMENT_ORDER_NEWEST_FIRST) {
        if ($mode == COMMENT_MODE_FLAT_COLLAPSED || $mode == COMMENT_MODE_FLAT_EXPANDED) {
817
          $query .= ' ORDER BY c.timestamp DESC';
Dries's avatar
 
Dries committed
818 819
        }
        else {
820
          $query .= ' ORDER BY c.thread DESC';
Dries's avatar
 
Dries committed
821
        }
Dries's avatar
 
Dries committed
822
      }
Dries's avatar
Dries committed
823 824
      else if ($order == COMMENT_ORDER_OLDEST_FIRST) {
        if ($mode == COMMENT_MODE_FLAT_COLLAPSED || $mode == COMMENT_MODE_FLAT_EXPANDED) {
825
          $query .= ' ORDER BY c.timestamp';
Dries's avatar
 
Dries committed
826 827 828 829 830 831 832 833 834
        }
        else {

          /*
          ** See comment above.  Analysis learns that this doesn't cost
          ** too much.  It scales much much better than having the whole
          ** comment structure.
          */

835
          $query .= ' ORDER BY SUBSTRING(c.thread, 1, (LENGTH(c.thread) - 1))';
Dries's avatar
 
Dries committed
836
        }
Dries's avatar
 
Dries committed
837 838
      }

839 840
      // Start a form, for use with comment control.
      $result = pager_query($query, $comments_per_page, 0, "SELECT COUNT(*) FROM {comments} WHERE nid = %d AND status = %d", $nid, COMMENT_PUBLISHED);
Dries's avatar
Dries committed
841
      if (db_num_rows($result) && (variable_get('comment_controls', COMMENT_CONTROLS_HIDDEN) == COMMENT_CONTROLS_ABOVE || variable_get('comment_controls', COMMENT_CONTROLS_HIDDEN) == COMMENT_CONTROLS_ABOVE_BELOW)) {
842
        $output .= comment_controls($mode, $order, $comments_per_page);
Dries's avatar
 
Dries committed
843
      }
Dries's avatar
 
Dries committed
844

Dries's avatar
 
Dries committed
845
      while ($comment = db_fetch_object($result)) {
Dries's avatar
 
Dries committed
846
        $comment = drupal_unpack($comment);
847
        $comment->name = $comment->uid ? $comment->registered_name : $comment->name;
848
        $comment->depth = count(explode('.', $comment->thread)) - 1;
Dries's avatar
 
Dries committed
849

Dries's avatar
Dries committed
850
        if ($mode == COMMENT_MODE_FLAT_COLLAPSED) {
851
          $output .= theme('comment_flat_collapsed', $comment);
Dries's avatar
 
Dries committed
852
        }
Dries's avatar
Dries committed
853
        else if ($mode == COMMENT_MODE_FLAT_EXPANDED) {
854
          $output .= theme('comment_flat_expanded', $comment);
Dries's avatar
 
Dries committed
855
        }
Dries's avatar
Dries committed
856
        else if ($mode == COMMENT_MODE_THREADED_COLLAPSED) {
857
          $output .= theme('comment_thread_collapsed', $comment);
Dries's avatar
 
Dries committed
858
        }
Dries's avatar
Dries committed
859
        else if ($mode == COMMENT_MODE_THREADED_EXPANDED) {
860
          $output .= theme('comment_thread_expanded', $comment);
Dries's avatar
 
Dries committed
861
        }
Dries's avatar
 
Dries committed
862
      }
Dries's avatar
 
Dries committed
863

864 865
      // Use the standard pager; $pager_total is the number of returned rows,
      // is global and defined in pager.inc.
866
      $output .= theme('pager', NULL, $comments_per_page, 0, array('comments_per_page' => $comments_per_page));
Dries's avatar
 
Dries committed
867

Dries's avatar
Dries committed
868
      if (db_num_rows($result) && (variable_get('comment_controls', COMMENT_CONTROLS_HIDDEN) == COMMENT_CONTROLS_BELOW || variable_get('comment_controls', COMMENT_CONTROLS_HIDDEN) == COMMENT_CONTROLS_ABOVE_BELOW)) {
869
        $output .= comment_controls($mode, $order, $comments_per_page);
Dries's avatar
 
Dries committed
870 871 872 873
      }
    }

    // If enabled, show new comment form.
Dries's avatar
Dries committed
874
    if (user_access('post comments') && node_comment_mode($nid) == COMMENT_NODE_READ_WRITE && (variable_get('comment_form_location', COMMENT_FORM_SEPARATE_PAGE) == COMMENT_FORM_BELOW)) {
875
      $output .= comment_form(array('nid' => $nid), t('Post new comment'));
Dries's avatar
 
Dries committed
876 877 878
    }
  }
  return $output;
Dries's avatar
 
Dries committed
879 880
}

Dries's avatar
 
Dries committed
881

Dries's avatar
 
Dries committed
882 883 884
/**
 * Menu callback; delete a comment.
 */
Dries's avatar
Dries committed
885
function comment_delete($cid) {
Dries's avatar
 
Dries committed
886
  $comment = db_fetch_object(db_query('SELECT c.*, u.name AS registered_name, u.uid FROM {comments} c INNER JOIN {users} u ON u.uid = c.uid WHERE c.cid = %d', $cid));