Код: Выделить всё
$to_username = phpbb_clean_username($HTTP_POST_VARS['username']);
$sql = "SELECT user_id, user_notify_pm, user_email, user_lang, user_active, user_level
FROM " . USERS_TABLE . "
WHERE username = '" . str_replace("\'", "''", $to_username) . "'
AND user_id <> " . ANONYMOUS;
if ( !($result = $db->sql_query($sql)) )
{
$error = TRUE;
$error_msg = $lang['No_such_user'];
}
if ( ($to_userdata['user_level'] != ADMIN && $to_userdata['user_level'] != MOD ) && $userdata['user_level'] == USER && !$error )
{
$error = TRUE;
$error_msg = sprintf($lang['Disable_pm_msg'], $to_username);
} }