$join=' LEFT JOIN '.get_table_prefix().'content_privacy priv ON priv.content_id='.db_cast($table_alias.'.'.$first_id_field,'CHAR').' AND '.db_string_equal_to('priv.content_type',$content_type);
$join=' LEFT JOIN '.$table.' ON priv.content_id='.db_cast($table_alias.'.'.$first_id_field,'CHAR').' AND '.db_string_equal_to('priv.content_type',$content_type);
}
$where=' AND (';
// Pass: If no privacy row defined at all
$where.='priv.content_id IS NULL';
// Pass: If guest viewing allowed
$where.=' OR priv.guest_view=1';
if(!is_guest($viewing_member_id)){
// Pass: If self
if($cma_info!==null){
$where.=' OR '.$table_alias.'.'.$cma_info['submitter_field'].'='.strval($viewing_member_id);
}
// Pass: If all member viewing allowed
$where.=' OR priv.member_view=1';
// Pass: If friends
if(addon_installed('chat')){
$where.=' OR priv.friend_view=1 AND EXISTS(SELECT * FROM '.get_table_prefix().'chat_friends f WHERE f.member_liked='.(is_null($submitter)?($table_alias.'.'.$cma_info['submitter_field']):strval($submitter)).' AND f.member_likes='.strval($viewing_member_id).')';
if(($cma_info!==null)||($submitter!==null)){
$where.=' OR priv.friend_view=1 AND EXISTS(SELECT * FROM '.get_table_prefix().'chat_friends f WHERE f.member_likes='.(($submitter===null)?($table_alias.'.'.$cma_info['submitter_field']):strval($submitter)).' AND f.member_liked='.strval($viewing_member_id).')';
}
}
$where.=' OR '.(is_null($submitter)?($table_alias.'.'.$cma_info['submitter_field']):strval($submitter)).'='.strval($viewing_member_id);
$where.=' OR EXISTS(SELECT * FROM '.get_table_prefix().'content_privacy__members pm WHERE pm.member_id='.strval($viewing_member_id).' AND pm.content_id='.(is_null($submitter)?db_cast($table_alias.'.'.$first_id_field,'CHAR'):strval($submitter)).' AND '.db_string_equal_to('pm.content_type',$content_type).')';
// Pass: If on allow-list
$where.=' OR EXISTS(SELECT * FROM '.get_table_prefix().'content_privacy__members pm WHERE pm.member_id='.strval($viewing_member_id).' AND pm.content_id='.(($submitter===null)?db_cast($table_alias.'.'.$first_id_field,'CHAR'):strval($submitter)).' AND '.db_string_equal_to('pm.content_type',$content_type).')';
// Pass: If some other condition
if($additional_or!=''){
$where.=' OR '.$additional_or;
}
@@ -84,36 +117,31 @@ function get_privacy_where_clause($content_type, $table_alias, $viewing_member_i
* @param ID_TEXT $content_type The content type
* @param ID_TEXT $content_id The content ID
* @param ?MEMBER $viewing_member_id Viewing member to check privacy against (null: current member)
* @param string $additional_or Additional OR clause for letting the user through
* @param ?MEMBER $submitter Member owning the content (null: do dynamically in query via content hook). Usually pass as null