Журнал изменений
Standardises the naming of per-module admin help files: the old full-word names (english.html, russian.html, …) are replaced with two-letter ISO 639-1 codes (en.html, ru.html, …) that match the language identifiers used everywhere else in the codebase.
Core changes:
- Renamed per-module info files:
faq, files, forum, help, jokes, links, media, money, news, pages, shop, voting, whois → all six language variants renamed
- english.html → en.html, french.html → fr.html,
german.html → de.html, polish.html → pl.html,
russian.html → ru.html, ukrainian.html → uk.html
- Global RSS info files migrated to module (admin/info/):
- admin/info/rss-de/en/fr/pl/ru/uk.html → deleted (old global location)
- modules/rss/admin/info/de/en/fr/pl/ru/uk.html → added (module-local)
- Whois admin info files:
- admin/info/whois-.html → modules/whois/admin/info/.html (ISO names)
Benefits:
- Consistent file naming aligned with ISO 639-1 language codes
- Easier programmatic lookup: adm_info() can resolve locale to filename directly
- Removes ambiguity between long-name and code-based file resolution
Technical notes:
- Content of HTML files unchanged; pure rename operation
- adm_info() callers must use ISO codes (already the standard)
Three independent bugs fixed in the forum public module: duplicate named placeholders in WHERE clauses, reused placeholders in INSERT (l_uid/l_name/ l_time sharing names with earlier params), and a missing head()/foot() pair when a category has no topics.
Core changes:
- Unique WHERE placeholders (modules/forum/index.php):
- category query: :id → :parentid / :cid (used twice in OR condition)
- move(): :val → :id_val / :pid_val in UPDATE SET catid query
- INSERT named params fix (modules/forum/index.php):
l_uid, l_name, l_time now bound as :l_uid / :l_name / :l_time
- Previously reused :postid / :postname / :time — caused rebind errors
- Empty-category guard (modules/forum/index.php):
Added else branch: renders head() + setTemplateWarning(_NO_INFO)
- Prevents blank page when forum category contains no threads
- 5-second redirect back to forum root
Benefits:
- Eliminates PDO named-parameter rebind errors in forum queries
- Proper HTTP response (head/foot wrapper) for empty forum categories
- INSERT now correctly stores l_uid / l_name / l_time independently
Technical notes:
- All bound values remain identical; only parameter names changed
- No schema or API changes; backward compatible
PDO does not allow reusing the same named placeholder more than once in a single query; duplicate :word bindings caused silent data loss or driver errors. Each LIKE column now gets its own numbered parameter.
Core changes:
- Unique LIKE parameters (modules/search/index.php):
- auto_links: :word → :word1, :word2, :word3 (sitename/description/link)
- faq: :word → :word1, :word2 (title/hometext)
- files: :word → :word1, :word2, :word3 (title/description/bodytext)
- forum: :word → :word1, :word2 (title/hometext)
- jokes: :word → :word1, :word2 (title/joke)
- links: :word → :word1, :word2, :word3, :word4 (title/description/bodytext/url)
- media: :word → :word1/:word2/:word3 per search type branch
- news, pages, faq, content: same pattern applied throughout
Benefits:
- Eliminates PDO parameter rebind errors on multi-column LIKE searches
- All LIKE values are bound with the same '%'.$word.'%' value — no logic change
- Consistent placeholder naming across all search branches
Technical notes:
- Pure parameter-naming fix; SQL logic and result sets are unchanged
- Backward compatible: no schema or API changes
Extends getVar() with a new 'defis' filter type that URL-encodes string input while leaving pre-encoded defaults untouched; also normalises all filter key lookups to lowercase so callers may use any casing.
Core changes:
- New filter type (core/security.php):
Add 'defis' => urlencode(trim($v)) to the filters map
- Returns '' (not false) for blank strings
- Skips encoding when the value comes from $default
- Case-insensitive dispatch (core/security.php):
All $filters[$type] lookups replaced with $filters[strtolower($type)]
- Covers both the array-branch and the scalar-branch paths
- Prevents silent no-ops when callers pass mixed-case type strings
- Special defis path (core/security.php):
Dedicated early-return block for 'defis' type
- Falls back to $default as-is (already encoded)
- Returns false only when both value and default are empty
Benefits:
- Enables safe URL-segment encoding via getVar() without raw urlencode() calls
- Eliminates filter-miss bugs caused by type-string casing differences
- Consistent fallback semantics across all filter types
Technical notes:
- No change to existing filter behaviour or function signature
- Backward compatible: callers using lowercase types are unaffected
- 'defis' default is passed through unchanged (expected to be pre-encoded)
Removes stale global variable declarations from forum() and view() to keep function signatures accurate and reduce unnecessary imports.
Core changes:
- Forum frontend (modules/forum/index.php):
- forum(): remove unused $user global
- view(): remove unused $admin_file and $locale globals
Benefits:
- Accurate global declarations prevent confusion during maintenance
- Slight reduction in unnecessary variable imports per request
- Architecture alignment with the $afile rename across the codebase
Technical notes:
- No behavioral change
- Backward compatible
Rewrites the files admin module using standard SLAED conventions: canonical function names, getVar() input handling, prepared SQL statements, and modern template calls. Copyright year updated to 2026.
Core changes:
- Files admin (modules/files/admin/index.php):
- Replace files_navi() with navi() using getAdminTabs()
Rename functions to short canonical names
- files_add() -> add(), files_delete() -> del(), etc.
- Replace all raw $_POST/$_GET with getVar()
- Use prepared SQL statements with named placeholders throughout
- Replace tpl_eval()/tpl_warn() with setTemplateBasic()/setTemplateWarning()
- Replace $admin_file with $afile throughout
- Update op= route names to match new function names
- Switch to single-quoted strings consistently
- Update copyright year to 2026
Benefits:
- SQL injection eliminated throughout the module
- Input validated at entry points via getVar()
- Consistent architecture with other modernized admin modules
- Maintainability improved by short canonical function names
Technical notes:
- op= route values changed to match new function names
- Backward compatible with the database schema
Rewrites the clients admin module using standard SLAED conventions: canonical function names, getVar() input handling, prepared SQL statements, and modern template calls. SQL injection in save/delete queries eliminated. Missing exit after redirects added.
Core changes:
- Clients admin (modules/clients/admin/index.php):
- Replace clients_navi() with navi() using getAdminTabs()
Rename functions to short canonical names:
- clients_add() -> add()
- clients_save() -> save()
- clients_delete() -> del()
- clients_active() -> status()
- clients_info() -> info()
- Replace all raw $_POST/$_GET with getVar()
- Fix SQL injection in save(): prepared statements with named placeholders
- Replace tpl_eval()/tpl_warn() with setTemplateBasic()/setTemplateWarning()
- Replace $admin_file with $afile throughout
- Add exit after header() in del() and status()
- Rewrite switch to compact form with named cases
- Add missing newline at end of file
Benefits:
- SQL injection in save and delete queries eliminated
- Input sanitized via getVar() throughout
- Missing exit after redirect now present
- Consistent naming convention across admin modules
Technical notes:
- op= route values changed to match new function names
- Backward compatible with the database schema
Rewrites the auto_links admin module to follow current SLAED architecture: standard function naming, getVar() input handling, prepared SQL statements, and modern template calls. SQL injection in the stats query is eliminated. Copyright year updated to 2026.
Core changes:
- Auto-links admin (modules/auto_links/admin/index.php):
- Replace auto_links_navi() with navi() using getAdminTabs()
Rename all functions to short canonical names:
- auto_links_stat() -> stats()
- auto_links_add() -> add()
- auto_links_save() -> save()
- auto_links_delete() -> del()
- auto_links_conf() -> conf()
- auto_links_conf_save() -> confsave()
- auto_links_info() -> info()
- nullhits() and noindel() extracted from switch as named functions
- Replace all raw $_POST/$_GET with getVar()
- Fix SQL injection in stats(): prepared statement with :lid placeholder
- Replace tpl_eval()/tpl_warn() with setTemplateBasic()/setTemplateWarning()
- Replace $admin_file/$aroute with $afile throughout
- Use $conf['auto_links'] sub-array instead of $confal
- Rewrite switch to compact form with named cases
- Remove closing ?>
- Update copyright year to 2026
Benefits:
- SQL injection in stats query eliminated
- Input validated through getVar() at all entry points
- Consistent naming convention with other modernized modules
- Maintainability improved by short, readable function names
Technical notes:
- op= route values changed to match new function names
- $confal replaced by $conf['auto_links'] sub-array
- Routing layer must map new op names
Aligns the account admin and frontend module with the canonical $afile variable, and removes unused globals from checkuser() and view().
Core changes:
- Account admin (modules/account/admin/index.php):
Replace $aroute with $afile in navi(), users(), add(), addsave(), newuser(), nullpoints(), nullsave(), conf(), save(), newdel(), del()
- Fix navi() call spacing: navi(0,0,0,0) -> navi(0, 0, 0, 0)
- Account frontend (modules/account/index.php):
- Replace $admin_file with $afile in view()
- Remove unused $conf from checkuser() globals
Benefits:
- Consistent $afile usage across frontend and admin sides
- Eliminates unnecessary global imports
- Architecture alignment with modernized modules
Technical notes:
- No behavioral change; pure identifier rename
- Backward compatible
Eliminates the legacy $aroute variable from all four admin panel modules, replacing it with the canonical $afile identifier. Also removes the pwd field from admin list and edit queries to avoid exposing password hashes unnecessarily in list views.
Core changes:
- Admins manager (admin/modules/admins.php):
- Replace $aroute with $afile in admins(), add(), save(), del()
- Remove pwd column from SELECT in admins() list query
- Remove pwd from SELECT and list() destructuring in add()
- Blocks manager (admin/modules/blocks.php):
Replace $aroute with $afile in all functions
- add(), fileadd(), fileedit(), fix(), addsave(), filecode()
- filecodesave(), edit(), editsave(), change(), del()
- Config manager (admin/modules/config.php):
- Replace $aroute with $afile in config(), save()
- Modules manager (admin/modules/modules.php):
- Replace $aroute with $afile in navi(), modules(), edit(), status(), save()
Benefits:
- Consistent use of $afile across the entire admin panel
- Removing pwd from queries reduces attack surface in list views
- Simpler global declarations in each function
Technical notes:
- No behavioral change beyond the variable rename
- $afile is injected by the admin bootstrap
- Backward compatible