<% if not fromThisDomain("fwd.asp?") then response.redirect (forumdir&"first.asp?error=referer") response.end end if if request.form("jsenabled")="false" then response.redirect (forumdir&"first.asp") response.end end if dim rights,allforum allforum = application(dbName&"foruminfo") Dim objPermission Set objPermission = new PermissionSetting With objPermission .memID = memID .appid = request.form("appid") .GetPermission(false) rights = .post End With Set objPermission = nothing if rights < 1 then response.write RightViolationMessage response.end end if erase allforum if request.form("to")="" then response.clear response.redirect "fwd.asp?back=reject" response.end end if dim messageID, objRS, strSQL, author, mbody dim senderE,senderN,mailTo,mailCC,mailBCC,subject,body,msubject messageID = request.form("messageID") mailTo = request.form("to") set objRS = Server.createobject("ADODB.RECORDSET") strSQL = dbOwnerPrefix&"spForwardpro ("& messageID &")" objRS.open strSQL, datastore, , , adCmdStoredProc mbody = objRS("Body") author = objRS("author") msubject = SQLout(objRS("subject")) senderN = memLogin & " from " & Application(dbName&"ForumTitle") senderE = Application(dbName&"adminEmail") Set objRS = objRS.nextrecordset body = objRS("forward_msg") objRS.close Set objRS = nothing Body = replace(Body,"#sender#", senderN) Body = replace(Body,"#subject#", msubject) Body = replace(Body,"#author#", author) Body = replace(Body,"#body#", SQLText(mbody)) Body = replace(Body,"#forumtitle#", Application(dbName&"ForumTitle")) Body = replace(Body,"#forumdir#", forumdir) Body = replace(body,"#today#", SQLdate(SQLNowDate(), Application(dbName&"timeoffset"), true)) Body = replace(Body,"#msglocation#", forumdir&"fb.asp?m="&messageID) subject = split(body,vbcrlf)(0) body = replace(body,subject&vbcrlf,"",1,1,vbBinaryCompare) if request.form("cc") = "on" then mailCC = request.form("mailCC") else mailCC = "" mailBCC = "" '=========================================================================== call mailRoutine(senderE,senderN,mailTo,mailCC,mailBCC,subject,body) '=========================================================================== response.clear response.redirect "fwd.asp?action=complete" response.end %>