<?php
	define('thisscript','contactpage');
	
	require_once "global.php";

	if ($general['onlymemberaccesscontact']){
		if (empty($userid)){
			redirecting('home');
		}
	}
	
	require_once 'class/Contact.php';
	$contact= new Contact();
	
	/* sanitize post, get, request */
	$_GET['msg'] = ((empty($_GET['msg']))?"":$_GET['msg']);
	$_GET['type'] = ((empty($_GET['type']))?"":$_GET['type']);
	$_POST['submits'] = ((empty($_POST['submits']))?"":$_POST['submits']);
	$_POST['name'] = ((empty($_POST['name']))?"":$_POST['name']);
	$_POST['email'] = ((empty($_POST['email']))?"":$_POST['email']);
	$_POST['telp'] = ((empty($_POST['telp']))?"":$_POST['telp']);
	$_POST['pesan'] = ((empty($_POST['pesan']))?"":$_POST['pesan']);
	$_POST['scodes'] = ((empty($_POST['scodes']))?"":$_POST['scodes']);
	$_POST['messageid'] = ((empty($_POST['messageid']))?"":$_POST['messageid']);
	$_REQUEST['id'] = ((empty($_REQUEST['id']))?"":$_REQUEST['id']);
	/* end sanitize */
	
	$errmsg = '';
	$fullname = '';
	$email = '';
	$telp = '';
	$contents = '';
	$idmessageoptions = '';

	if ($_POST['submits'] == 'Contact Us'){
		session_start();
		$fullname = trim($_POST['name']);
		$messageid = trim($_POST['messageid']);
		$email = trim($_POST['email']);
		$telp = trim($_POST['telp']);
		$contents = trim($_POST['pesan']);
		$scodes = trim($_POST['scodes']);
		
		if ($_SESSION['sc_code_contact'] == md5(strtolower($scodes))){
			$messsid = $db->fetch_one("SELECT * FROM messagetype WHERE messageid='".$db->clean($messageid)."'");
			$typemessage = empty($messsid['typemessage_'.$langid])?'':$messsid['typemessage_'.$langid];

			$contact->moveToContact();
			
			if (!empty($messsid['email'])){
				$toaddress = $messsid['email'];
				$headers = "Content-type: text/html; charset=iso-8859-1\r\n";
				$headers .= "From: ".$fullname." <".$email.">";
				$subject = $general['sitename'].' - Message From '.$fullname;
				$mailcontent = '<div align="left"><b>Contact Message</b></div><br />
					<table border="0" cellpadding="3" cellspacing="0">
					<tr>
						<td align="left">Name</td>
						<td align="center">:</td>
						<td align="left">'.$fullname.'</td>
					</tr>
					<tr>
						<td align="left">Email</td>
						<td align="center">:</td>
						<td align="left">'.$email.'</td>
					</tr>
					<tr>
						<td align="left">Phone</td>
						<td align="center">:</td>
						<td align="left">'.$telp.'</td>
					</tr>
					<tr>
						<td align="left">Date</td>
						<td align="center">:</td>
						<td align="left">'.date("d M Y H:i:s", $nwtm).'</td>
					</tr>
					<tr>
						<td align="left" valign="top">Message</td>
						<td align="center" valign="top">:</td>
						<td align="left" valign="top">'.nl2br($contents).'</td>
					</tr>
					</table>';
	
				if ($emailsetting['enablesendmail']){
					mail($toaddress, $subject, $mailcontent, $headers);
				}
			}
			
			redirecting('contactus?msg=success');
		}
		else{
			$errmsg = $phrase['errorcode'];
		}
	}
	
	/* get type of message */
	$allmessage = $contact->getMessageType('partial');
	$idmessageoptions = '';
	if (sizeof($allmessage) > 0){
		if (!empty($_POST['messageid'])){
			foreach ($allmessage as $amess){
				$idmessageoptions .= '<option value="'.$amess['messageid'].'"'.(($_POST['messageid'] == $amess['messageid'])?' selected':'').'>'.htmlspecialchars($amess['typemessage_'.$langid]).'</option>';
			}
		}
		else if (!empty($_GET['type'])){
			foreach ($allmessage as $amess){
				$idmessageoptions .= '<option value="'.$amess['messageid'].'"'.(($_GET['type'] == $amess['connector'])?' selected':'').'>'.htmlspecialchars($amess['typemessage_'.$langid]).'</option>';
			}
		}
		else{
			foreach ($allmessage as $amess){
				$idmessageoptions .= '<option value="'.$amess['messageid'].'">'.htmlspecialchars($amess['typemessage_'.$langid]).'</option>';
			}
		}
	}
	
	$navigations =' &raquo; <b><a href="contactus">'.$phrase['contact_us'].'</a></b>';	
	require_once "incl/global_template.php";
	
	$tmpl = gettemplate('contactpage');
	eval("\$template = \"$tmpl\";");
	echo $template;
	
?>