T.ME/BIBIL_0DAY
CasperSecurity


Server : Apache/2
System : Linux server-15-235-50-60 5.15.0-164-generic #174-Ubuntu SMP Fri Nov 14 20:25:16 UTC 2025 x86_64
User : gositeme ( 1004)
PHP Version : 8.2.29
Disable Function : exec,system,passthru,shell_exec,proc_close,proc_open,dl,popen,show_source,posix_kill,posix_mkfifo,posix_getpwuid,posix_setpgid,posix_setsid,posix_setuid,posix_setgid,posix_seteuid,posix_setegid,posix_uname
Directory :  /home/gositeme/domains/soundstudiopro.com/public_html/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Current File : /home/gositeme/domains/soundstudiopro.com/public_html/admin_view_email.php
<?php
/**
 * View Email Details
 * Displays the full content of an email from the email logs
 */

session_start();
require_once 'config/database.php';

// Check if admin
if (!isset($_SESSION['is_admin']) || !$_SESSION['is_admin']) {
    die("Admin access required");
}

$pdo = getDBConnection();
$email_id = intval($_GET['id'] ?? 0);

if (!$email_id) {
    die("Email ID required");
}

// Get email log entry
$stmt = $pdo->prepare("
    SELECT 
        el.*,
        u.name as user_name,
        u.email as user_email
    FROM email_logs el
    LEFT JOIN users u ON el.user_id = u.id
    WHERE el.id = ?
");
$stmt->execute([$email_id]);
$email_log = $stmt->fetch(PDO::FETCH_ASSOC);

if (!$email_log) {
    die("Email not found");
}

// Reconstruct email content based on email_type and order_id
$email_content = null;
$email_subject = $email_log['subject'];

if ($email_log['email_type'] === 'order_confirmation' || $email_log['email_type'] === 'invoice') {
    // For order confirmations/invoices, reconstruct from order_id
    require_once 'config/email.php';
    
    // Try to extract order number from subject if order_id is not set
    $order_identifier = $email_log['order_id'];
    if (!$order_identifier && preg_match('/Order #(SSP-\d{8}-[A-Z0-9]+)/i', $email_log['subject'], $matches)) {
        $order_identifier = $matches[1];
    }
    
    if ($order_identifier) {
        // Try to extract order details from order_id
        // Order ID format: SSP-YYYYMMDD-XXXXXXXX or payment intent ID
        
        // Check if it's a Stripe payment intent
        if (strpos($order_identifier, 'pi_') === 0) {
            // It's a Stripe payment intent - get purchase details
            $stmt = $pdo->prepare("
                SELECT 
                    tp.*,
                    mt.title as track_title,
                    mt.price as track_price,
                    u.name as artist_name
                FROM track_purchases tp
                JOIN music_tracks mt ON tp.track_id = mt.id
                JOIN users u ON mt.user_id = u.id
                WHERE tp.stripe_payment_intent_id = ?
                ORDER BY tp.purchase_date DESC
            ");
            $stmt->execute([$order_identifier]);
            $purchases = $stmt->fetchAll(PDO::FETCH_ASSOC);
            
            if (!empty($purchases)) {
                $track_ids = array_column($purchases, 'track_id');
                $total_amount = array_sum(array_column($purchases, 'price_paid'));
                
                $invoice_data = generateInvoiceEmail(
                    $email_log['recipient_name'] ?: $email_log['user_name'] ?: 'Customer',
                    $email_log['recipient_email'],
                    [
                        'track_ids' => $track_ids,
                        'total_amount' => $total_amount,
                        'purchase_date' => $purchases[0]['purchase_date'],
                        'payment_method' => $purchases[0]['payment_method'] ?: 'stripe',
                        'payment_intent_id' => $order_identifier
                    ]
                );
                $email_content = $invoice_data['html'];
            }
        } else {
            // Try to parse order number format: SSP-YYYYMMDD-XXXXXXXX
            // For now, try to find purchases around the email date
            $stmt = $pdo->prepare("
                SELECT 
                    tp.*,
                    mt.title as track_title,
                    mt.price as track_price,
                    u.name as artist_name
                FROM track_purchases tp
                JOIN music_tracks mt ON tp.track_id = mt.id
                JOIN users u ON mt.user_id = u.id
                WHERE tp.user_id = ?
                AND DATE(tp.purchase_date) = DATE(?)
                ORDER BY tp.purchase_date DESC
            ");
            $stmt->execute([$email_log['user_id'], $email_log['sent_at']]);
            $purchases = $stmt->fetchAll(PDO::FETCH_ASSOC);
            
            if (!empty($purchases)) {
                $track_ids = array_column($purchases, 'track_id');
                $total_amount = array_sum(array_column($purchases, 'price_paid'));
                
                $invoice_data = generateInvoiceEmail(
                    $email_log['recipient_name'] ?: $email_log['user_name'] ?: 'Customer',
                    $email_log['recipient_email'],
                    [
                        'track_ids' => $track_ids,
                        'total_amount' => $total_amount,
                        'purchase_date' => $purchases[0]['purchase_date'],
                        'payment_method' => $purchases[0]['payment_method'] ?: 'stripe',
                        'payment_intent_id' => $order_identifier
                    ]
                );
                $email_content = $invoice_data['html'];
            }
        }
    } elseif ($email_log['user_id']) {
        // Fallback: try to find purchases by user and date
        $stmt = $pdo->prepare("
            SELECT 
                tp.*,
                mt.title as track_title,
                mt.price as track_price,
                u.name as artist_name
            FROM track_purchases tp
            JOIN music_tracks mt ON tp.track_id = mt.id
            JOIN users u ON mt.user_id = u.id
            WHERE tp.user_id = ?
            AND DATE(tp.purchase_date) = DATE(?)
            ORDER BY tp.purchase_date DESC
        ");
        $stmt->execute([$email_log['user_id'], $email_log['sent_at']]);
        $purchases = $stmt->fetchAll(PDO::FETCH_ASSOC);
        
        if (!empty($purchases)) {
            $track_ids = array_column($purchases, 'track_id');
            $total_amount = array_sum(array_column($purchases, 'price_paid'));
            
            $invoice_data = generateInvoiceEmail(
                $email_log['recipient_name'] ?: $email_log['user_name'] ?: 'Customer',
                $email_log['recipient_email'],
                [
                    'track_ids' => $track_ids,
                    'total_amount' => $total_amount,
                    'purchase_date' => $purchases[0]['purchase_date'],
                    'payment_method' => $purchases[0]['payment_method'] ?: 'stripe'
                ]
            );
            $email_content = $invoice_data['html'];
        }
    }
}

// If we couldn't reconstruct, show a basic template
if (!$email_content) {
    $email_content = '
    <div style="max-width: 600px; margin: 0 auto; background: white; border-radius: 8px; overflow: hidden; box-shadow: 0 4px 20px rgba(0, 0, 0, 0.3); padding: 30px;">
        <h2 style="color: #667eea;">' . htmlspecialchars($email_log['subject']) . '</h2>
        <p><strong>Recipient:</strong> ' . htmlspecialchars($email_log['recipient_email']) . '</p>
        <p><strong>Sent:</strong> ' . date('F j, Y \a\t g:i A', strtotime($email_log['sent_at'])) . '</p>
        <p><strong>Status:</strong> ' . htmlspecialchars($email_log['status']) . '</p>
        <p><strong>Email Type:</strong> ' . htmlspecialchars($email_log['email_type']) . '</p>
        ' . ($email_log['order_id'] ? '<p><strong>Order ID:</strong> ' . htmlspecialchars($email_log['order_id']) . '</p>' : '') . '
        ' . ($email_log['error_message'] ? '<p style="color: #ef4444;"><strong>Error:</strong> ' . htmlspecialchars($email_log['error_message']) . '</p>' : '') . '
        <p style="margin-top: 20px; color: #666;">Email content could not be reconstructed. This may be a system email or the order details are no longer available.</p>
    </div>';
}

?>
<!DOCTYPE html>
<html lang="en">
<head>
    <meta charset="UTF-8">
    <meta name="viewport" content="width=device-width, initial-scale=1.0">
    <title>View Email - <?= htmlspecialchars($email_log['subject']) ?></title>
    <style>
        * {
            margin: 0;
            padding: 0;
            box-sizing: border-box;
        }
        body {
            font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, Oxygen, Ubuntu, Cantarell, sans-serif;
            background: #1a1a1a;
            color: white;
            padding: 20px;
        }
        .header {
            background: rgba(255, 255, 255, 0.05);
            border-radius: 12px;
            padding: 20px;
            margin-bottom: 20px;
            display: flex;
            justify-content: space-between;
            align-items: center;
        }
        .header h1 {
            font-size: 1.5rem;
            color: white;
        }
        .back-btn {
            background: #667eea;
            color: white;
            padding: 10px 20px;
            border-radius: 8px;
            text-decoration: none;
            display: inline-block;
        }
        .back-btn:hover {
            background: #5568d3;
        }
        .email-info {
            background: rgba(255, 255, 255, 0.05);
            border-radius: 12px;
            padding: 20px;
            margin-bottom: 20px;
        }
        .email-info table {
            width: 100%;
            border-collapse: collapse;
        }
        .email-info td {
            padding: 8px;
            border-bottom: 1px solid rgba(255, 255, 255, 0.1);
        }
        .email-info td:first-child {
            font-weight: bold;
            color: #a0aec0;
            width: 150px;
        }
        .email-preview {
            background: white;
            border-radius: 12px;
            padding: 20px;
            margin-bottom: 20px;
            box-shadow: 0 4px 20px rgba(0, 0, 0, 0.3);
        }
        .status-badge {
            display: inline-block;
            padding: 4px 12px;
            border-radius: 12px;
            font-size: 0.85rem;
            font-weight: 600;
        }
        .status-sent {
            background: rgba(34, 197, 94, 0.2);
            color: #22c55e;
        }
        .status-failed {
            background: rgba(239, 68, 68, 0.2);
            color: #ef4444;
        }
        .status-pending {
            background: rgba(245, 158, 11, 0.2);
            color: #f59e0b;
        }
    </style>
</head>
<body>
    <div class="header">
        <h1>📧 Email Details</h1>
        <a href="/admin.php?tab=email" class="back-btn">← Back to Email Management</a>
    </div>
    
    <div class="email-info">
        <table>
            <tr>
                <td>Email ID:</td>
                <td><?= $email_log['id'] ?></td>
            </tr>
            <tr>
                <td>Recipient:</td>
                <td><?= htmlspecialchars($email_log['recipient_email']) ?></td>
            </tr>
            <tr>
                <td>Recipient Name:</td>
                <td><?= htmlspecialchars($email_log['recipient_name'] ?: $email_log['user_name'] ?: 'N/A') ?></td>
            </tr>
            <tr>
                <td>Subject:</td>
                <td><?= htmlspecialchars($email_log['subject']) ?></td>
            </tr>
            <tr>
                <td>Email Type:</td>
                <td><?= htmlspecialchars($email_log['email_type']) ?></td>
            </tr>
            <tr>
                <td>Status:</td>
                <td><span class="status-badge status-<?= $email_log['status'] ?>"><?= ucfirst($email_log['status']) ?></span></td>
            </tr>
            <tr>
                <td>Sent At:</td>
                <td><?= date('F j, Y \a\t g:i A', strtotime($email_log['sent_at'])) ?></td>
            </tr>
            <?php if ($email_log['order_id']): ?>
            <tr>
                <td>Order ID:</td>
                <td><?= htmlspecialchars($email_log['order_id']) ?></td>
            </tr>
            <?php endif; ?>
            <?php if ($email_log['user_id']): ?>
            <tr>
                <td>User ID:</td>
                <td><a href="/admin.php?tab=users&user_id=<?= $email_log['user_id'] ?>" style="color: #667eea;"><?= $email_log['user_id'] ?></a> (<?= htmlspecialchars($email_log['user_name'] ?: 'N/A') ?>)</td>
            </tr>
            <?php endif; ?>
            <?php if ($email_log['error_message']): ?>
            <tr>
                <td>Error:</td>
                <td style="color: #ef4444;"><?= htmlspecialchars($email_log['error_message']) ?></td>
            </tr>
            <?php endif; ?>
        </table>
    </div>
    
    <div class="email-preview">
        <h2 style="color: #333; margin-bottom: 20px;">Email Content Preview</h2>
        <?= $email_content ?>
    </div>
</body>
</html>


CasperSecurity Mini