]> git.donarmstrong.com Git - roundcube.git/blobdiff - program/steps/mail/func.inc
Imported Upstream version 0.3
[roundcube.git] / program / steps / mail / func.inc
index 3a971bd4052387f6c54f55e686fa68b758ac1509..d2c54a76b0dc51a0b266bce3b8025e427b5b1b9f 100644 (file)
@@ -5,7 +5,7 @@
  | program/steps/mail/func.inc                                           |
  |                                                                       |
  | This file is part of the RoundCube Webmail client                     |
- | Copyright (C) 2005, RoundCube Dev. - Switzerland                      |
+ | Copyright (C) 2005-2009, RoundCube Dev. - Switzerland                 |
  | Licensed under the GNU GPL                                            |
  |                                                                       |
  | PURPOSE:                                                              |
  | Author: Thomas Bruederli <roundcube@gmail.com>                        |
  +-----------------------------------------------------------------------+
 
- $Id: func.inc 429 2006-12-22 22:26:24Z thomasb $
+ $Id: func.inc 2880 2009-08-27 09:52:52Z alec $
 
 */
 
-require_once('lib/html2text.inc');
-require_once('lib/enriched.inc');
+$EMAIL_ADDRESS_PATTERN = '([a-z0-9][a-z0-9\-\.\+\_]*@[a-z0-9][a-z0-9\-\.]*\\.[a-z]{2,5})';
 
+// actions that do not require imap connection
+$NOIMAP_ACTIONS = array('spell', 'addcontact', 'autocomplete', 'upload', 'display-attachment', 'remove-attachment');
 
-$EMAIL_ADDRESS_PATTERN = '/([a-z0-9][a-z0-9\-\.\+\_]*@[a-z0-9]([a-z0-9\-][.]?)*[a-z0-9]\\.[a-z]{2,5})/i';
 
-if (empty($_SESSION['mbox'])){
-  $_SESSION['mbox'] = $IMAP->get_mailbox_name();
-}
+// log in to imap server
+if (!in_array($RCMAIL->action, $NOIMAP_ACTIONS) && !$RCMAIL->imap_connect()) {
+  $RCMAIL->kill_session();
 
-// set imap properties and session vars
-if (strlen($_GET['_mbox']))
-  {
-  $IMAP->set_mailbox($_GET['_mbox']);
-  $_SESSION['mbox'] = $_GET['_mbox'];
-  }
+  if ($OUTPUT->ajax_call)
+    $OUTPUT->redirect(array(), 2000);
 
-if (strlen($_GET['_page']))
-  {
-  $IMAP->set_page($_GET['_page']);
-  $_SESSION['page'] = $_GET['_page'];
-  }
+  $OUTPUT->set_env('task', 'login');
+  $OUTPUT->send('login');
+}
 
-// set mailbox to INBOX if not set
-if (empty($_SESSION['mbox']))
+
+// set imap properties and session vars
+if ($mbox = get_input_value('_mbox', RCUBE_INPUT_GPC))
+  $IMAP->set_mailbox(($_SESSION['mbox'] = $mbox));
+else
   $_SESSION['mbox'] = $IMAP->get_mailbox_name();
 
+if (!empty($_GET['_page']))
+  $IMAP->set_page(($_SESSION['page'] = intval($_GET['_page'])));
+
 // set default sort col/order to session
 if (!isset($_SESSION['sort_col']))
   $_SESSION['sort_col'] = $CONFIG['message_sort_col'];
 if (!isset($_SESSION['sort_order']))
   $_SESSION['sort_order'] = $CONFIG['message_sort_order'];
-  
-
-// define url for getting message parts
-if (strlen($_GET['_uid']))
-  $GET_URL = sprintf('%s&_action=get&_mbox=%s&_uid=%d', $COMM_PATH, $IMAP->get_mailbox_name(), $_GET['_uid']);
-
-
-// set current mailbox in client environment
-$OUTPUT->add_script(sprintf("%s.set_env('mailbox', '%s');", $JS_OBJECT_NAME, $IMAP->get_mailbox_name()));
-
-if ($CONFIG['trash_mbox'])
-  $OUTPUT->add_script(sprintf("%s.set_env('trash_mailbox', '%s');", $JS_OBJECT_NAME, $CONFIG['trash_mbox']));
-
-if ($CONFIG['drafts_mbox'])
-  $OUTPUT->add_script(sprintf("%s.set_env('drafts_mailbox', '%s');", $JS_OBJECT_NAME, $CONFIG['drafts_mbox']));
-
-if ($CONFIG['junk_mbox'])
-  $OUTPUT->add_script(sprintf("%s.set_env('junk_mailbox', '%s');", $JS_OBJECT_NAME, $CONFIG['junk_mbox']));
-
-// return the mailboxlist in HTML
-function rcmail_mailbox_list($attrib)
-  {
-  global $IMAP, $CONFIG, $OUTPUT, $JS_OBJECT_NAME, $COMM_PATH;
-  static $s_added_script = FALSE;
-  static $a_mailboxes;
-
-  // add some labels to client
-  rcube_add_label('purgefolderconfirm');
-  
-// $mboxlist_start = rcube_timer();
-  
-  $type = $attrib['type'] ? $attrib['type'] : 'ul';
-  $add_attrib = $type=='select' ? array('style', 'class', 'id', 'name', 'onchange') :
-                                  array('style', 'class', 'id');
-                                  
-  if ($type=='ul' && !$attrib['id'])
-    $attrib['id'] = 'rcmboxlist';
-
-  // allow the following attributes to be added to the <ul> tag
-  $attrib_str = create_attrib_string($attrib, $add_attrib);
-  $out = '<' . $type . $attrib_str . ">\n";
-  
-  // add no-selection option
-  if ($type=='select' && $attrib['noselection'])
-    $out .= sprintf('<option value="0">%s</option>'."\n",
-                    rcube_label($attrib['noselection']));
-  
-  // get mailbox list
-  $mbox_name = $IMAP->get_mailbox_name();
-  
-  // for these mailboxes we have localized labels
-  $special_mailboxes = array('inbox', 'sent', 'drafts', 'trash', 'junk');
-
-
-  // build the folders tree
-  if (empty($a_mailboxes))
-    {
-    // get mailbox list
-    $a_folders = $IMAP->list_mailboxes();
-    $delimiter = $IMAP->get_hierarchy_delimiter();
-    $a_mailboxes = array();
 
-// rcube_print_time($mboxlist_start, 'list_mailboxes()');
-
-    foreach ($a_folders as $folder)
-      rcmail_build_folder_tree($a_mailboxes, $folder, $delimiter);
-    }
-
-// var_dump($a_mailboxes);
-
-  if ($type=='select')
-    $out .= rcmail_render_folder_tree_select($a_mailboxes, $special_mailboxes, $mbox_name, $attrib['maxlength']);
-   else
-    $out .= rcmail_render_folder_tree_html($a_mailboxes, $special_mailboxes, $mbox_name, $attrib['maxlength']);
-
-// rcube_print_time($mboxlist_start, 'render_folder_tree()');
-
-
-  if ($type=='ul')
-    $OUTPUT->add_script(sprintf("%s.gui_object('mailboxlist', '%s');", $JS_OBJECT_NAME, $attrib['id']));
-
-  return $out . "</$type>";
-  }
-
-
-
-
-// create a hierarchical array of the mailbox list
-function rcmail_build_folder_tree(&$arrFolders, $folder, $delm='/', $path='')
+// set message set for search result
+if (!empty($_REQUEST['_search']) && isset($_SESSION['search'][$_REQUEST['_search']]))
   {
-  $pos = strpos($folder, $delm);
-  if ($pos !== false)
-    {
-    $subFolders = substr($folder, $pos+1);
-    $currentFolder = substr($folder, 0, $pos);
-    }
-  else
-    {
-    $subFolders = false;
-    $currentFolder = $folder;
-    }
-
-  $path .= $currentFolder;
-
-  if (!isset($arrFolders[$currentFolder]))
-    {
-    $arrFolders[$currentFolder] = array('id' => $path,
-                                        'name' => rcube_charset_convert($currentFolder, 'UTF-7'),
-                                        'folders' => array());
-    }
-
-  if (!empty($subFolders))
-    rcmail_build_folder_tree($arrFolders[$currentFolder]['folders'], $subFolders, $delm, $path.$delm);
-  }
-  
-
-// return html for a structured list <ul> for the mailbox tree
-function rcmail_render_folder_tree_html(&$arrFolders, &$special, &$mbox_name, $maxlength, $nestLevel=0)
-  {
-  global $JS_OBJECT_NAME, $COMM_PATH, $IMAP, $CONFIG, $OUTPUT;
-
-  $idx = 0;
-  $out = '';
-  foreach ($arrFolders as $key => $folder)
-    {
-    $zebra_class = ($nestLevel*$idx)%2 ? 'even' : 'odd';
-    $title = '';
-
-    $folder_lc = strtolower($folder['id']);
-    if (in_array($folder_lc, $special))
-      $foldername = rcube_label($folder_lc);
-    else
-      {
-      $foldername = $folder['name'];
-
-      // shorten the folder name to a given length
-      if ($maxlength && $maxlength>1)
-        {
-        $fname = abbrevate_string($foldername, $maxlength);
-        if ($fname != $foldername)
-          $title = ' title="'.rep_specialchars_output($foldername, 'html', 'all').'"';
-        $foldername = $fname;
-        }
-      }
-
-    // add unread message count display
-    if ($unread_count = $IMAP->messagecount($folder['id'], 'RECENT', ($folder['id']==$mbox_name)))
-      $foldername .= sprintf(' (%d)', $unread_count);
-
-    // make folder name safe for ids and class names
-    $folder_css = $class_name = preg_replace('/[^a-z0-9\-_]/', '', $folder_lc);
-
-    // set special class for Sent, Drafts, Trash and Junk
-    if ($folder['id']==$CONFIG['sent_mbox'])
-      $class_name = 'sent';
-    else if ($folder['id']==$CONFIG['drafts_mbox'])
-      $class_name = 'drafts';
-    else if ($folder['id']==$CONFIG['trash_mbox'])
-      $class_name = 'trash';
-    else if ($folder['id']==$CONFIG['junk_mbox'])
-      $class_name = 'junk';
-
-    $out .= sprintf('<li id="rcmbx%s" class="mailbox %s %s%s%s"><a href="%s&amp;_mbox=%s"'.
-                    ' onclick="return %s.command(\'list\',\'%s\')"'.
-                    ' onmouseover="return %s.focus_mailbox(\'%s\')"' .            
-                    ' onmouseout="return %s.unfocus_mailbox(\'%s\')"' .
-                    ' onmouseup="return %s.mbox_mouse_up(\'%s\')"%s>%s</a>',
-                    $folder_css,
-                    $class_name,
-                    $zebra_class,
-                    $unread_count ? ' unread' : '',
-                    addslashes($folder['id'])==addslashes($mbox_name) ? ' selected' : '',
-                    $COMM_PATH,
-                    urlencode($folder['id']),
-                    $JS_OBJECT_NAME,
-                    addslashes($folder['id']),
-                    $JS_OBJECT_NAME,
-                    addslashes($folder['id']),
-                    $JS_OBJECT_NAME,
-                    addslashes($folder['id']),
-                    $JS_OBJECT_NAME,
-                    addslashes($folder['id']),
-                    $title,
-                    rep_specialchars_output($foldername, 'html', 'all'));
-
-    if (!empty($folder['folders']))
-      $out .= "\n<ul>\n" . rcmail_render_folder_tree_html($folder['folders'], $special, $mbox_name, $maxlength, $nestLevel+1) . "</ul>\n";
-
-    $out .= "</li>\n";
-    $idx++;
-    }
-
-  return $out;
+  $IMAP->set_search_set($_SESSION['search'][$_REQUEST['_search']]);
+  $OUTPUT->set_env('search_request', $_REQUEST['_search']);
+  $OUTPUT->set_env('search_text', $_SESSION['last_text_search']);
   }
 
-
-// return html for a flat list <select> for the mailbox tree
-function rcmail_render_folder_tree_select(&$arrFolders, &$special, &$mbox_name, $maxlength, $nestLevel=0)
+// set main env variables, labels and page title
+if (empty($RCMAIL->action) || $RCMAIL->action == 'list')
   {
-  global $IMAP, $OUTPUT;
+  $mbox_name = $IMAP->get_mailbox_name();
 
-  $idx = 0;
-  $out = '';
-  foreach ($arrFolders as $key=>$folder)
+  if (empty($RCMAIL->action))
     {
-    $folder_lc = strtolower($folder['id']);
-    if (in_array($folder_lc, $special))
-      $foldername = rcube_label($folder_lc);
-    else
+    // initialize searching result if search_filter is used
+    if ($_SESSION['search_filter'] && $_SESSION['search_filter'] != 'ALL')
       {
-      $foldername = $folder['name'];
-      
-      // shorten the folder name to a given length
-      if ($maxlength && $maxlength>1)
-        $foldername = abbrevate_string($foldername, $maxlength);
+      $search_request = md5($mbox_name.$_SESSION['search_filter']);
+  
+      $IMAP->search($mbox_name, $_SESSION['search_filter'], RCMAIL_CHARSET, $_SESSION['sort_col']);
+      $_SESSION['search'][$search_request] = $IMAP->get_search_set();
+      $OUTPUT->set_env('search_request', $search_request);
       }
-
-    $out .= sprintf('<option value="%s">%s%s</option>'."\n",
-                    $folder['id'],
-                    str_repeat('&nbsp;', $nestLevel*4),
-                    rep_specialchars_output($foldername, 'html', 'all'));
-
-    if (!empty($folder['folders']))
-      $out .= rcmail_render_folder_tree_select($folder['folders'], $special, $mbox_name, $maxlength, $nestLevel+1);
-
-    $idx++;
+    
+      $OUTPUT->set_env('search_mods', $_SESSION['search_mods'] ? $_SESSION['search_mods'] : array('subject'=>'subject'));
+      // make sure the message count is refreshed (for default view)
+      $IMAP->messagecount($mbox_name, 'ALL', true);
     }
-
-  return $out;
+       
+  // set current mailbox in client environment
+  $OUTPUT->set_env('mailbox', $mbox_name);
+  $OUTPUT->set_env('quota', $IMAP->get_capability('quota'));
+  $OUTPUT->set_env('delimiter', $IMAP->get_hierarchy_delimiter());
+
+  if ($CONFIG['flag_for_deletion'])
+    $OUTPUT->set_env('flag_for_deletion', true);
+  if ($CONFIG['read_when_deleted'])
+    $OUTPUT->set_env('read_when_deleted', true);
+  if ($CONFIG['skip_deleted'])
+    $OUTPUT->set_env('skip_deleted', true);
+  if ($CONFIG['display_next'])
+    $OUTPUT->set_env('display_next', true);
+         
+  if ($CONFIG['trash_mbox'])
+    $OUTPUT->set_env('trash_mailbox', $CONFIG['trash_mbox']);
+  if ($CONFIG['drafts_mbox'])
+    $OUTPUT->set_env('drafts_mailbox', $CONFIG['drafts_mbox']);
+  if ($CONFIG['junk_mbox'])
+    $OUTPUT->set_env('junk_mailbox', $CONFIG['junk_mbox']);
+
+  if (!$OUTPUT->ajax_call)
+    $OUTPUT->add_label('checkingmail', 'deletemessage', 'movemessagetotrash', 'movingmessage');
+
+  $OUTPUT->set_pagetitle(rcmail_localize_foldername($mbox_name));
   }
 
 
-// return the message list as HTML table
+/**
+ * return the message list as HTML table
+ */
 function rcmail_message_list($attrib)
   {
-  global $IMAP, $CONFIG, $COMM_PATH, $OUTPUT, $JS_OBJECT_NAME;
+  global $IMAP, $CONFIG, $COMM_PATH, $OUTPUT;
 
   $skin_path = $CONFIG['skin_path'];
-  $image_tag = '<img src="%s%s" alt="%s" border="0" />';
+  $image_tag = '<img src="%s%s" alt="%s" />';
 
   // check to see if we have some settings for sorting
   $sort_col   = $_SESSION['sort_col'];
   $sort_order = $_SESSION['sort_order'];
   
   // add some labels to client
-  rcube_add_label('from', 'to');
+  $OUTPUT->add_label('from', 'to');
 
   // get message headers
   $a_headers = $IMAP->list_headers('', '', $sort_col, $sort_order);
@@ -311,13 +139,22 @@ function rcmail_message_list($attrib)
 
   $out = '<table' . $attrib_str . ">\n";
 
+  // define list of cols to be displayed based on parameter or config
+  if (empty($attrib['columns']))
+      $a_show_cols = is_array($CONFIG['list_cols']) ? $CONFIG['list_cols'] : array('subject');
+  else
+      $a_show_cols = preg_split('/[\s,;]+/', strip_quotes($attrib['columns']));
 
-  // define list of cols to be displayed
-  $a_show_cols = is_array($CONFIG['list_cols']) ? $CONFIG['list_cols'] : array('subject');
+  // store column list in a session-variable
+  $_SESSION['list_columns'] = $a_show_cols;
+  
+  // define sortable columns
   $a_sort_cols = array('subject', 'date', 'from', 'to', 'size');
+
+  $mbox = $IMAP->get_mailbox_name();
   
   // show 'to' instead of from in sent messages
-  if (($IMAP->get_mailbox_name()==$CONFIG['sent_mbox'] || $IMAP->get_mailbox_name()==$CONFIG['drafts_mbox']) && ($f = array_search('from', $a_show_cols))
+  if (($mbox==$CONFIG['sent_mbox'] || $mbox==$CONFIG['drafts_mbox']) && ($f = array_search('from', $a_show_cols))
       && !array_search('to', $a_show_cols))
     $a_show_cols[$f] = 'to';
   
@@ -326,9 +163,8 @@ function rcmail_message_list($attrib)
   $out .= '<col class="icon" />';
 
   foreach ($a_show_cols as $col)
-    $out .= sprintf('<col class="%s" />', $col);
+    $out .= ($col!='attachment') ? sprintf('<col class="%s" />', $col) : '<col class="icon" />';
 
-  $out .= '<col class="icon" />';
   $out .= "</colgroup>\n";
 
   // add table title
@@ -338,11 +174,21 @@ function rcmail_message_list($attrib)
   foreach ($a_show_cols as $col)
     {
     // get column name
-    $col_name = rep_specialchars_output(rcube_label($col));
+    switch ($col)
+      {
+      case 'flag':
+        $col_name = sprintf($image_tag, $skin_path, $attrib['unflaggedicon'], '');
+        break;
+      case 'attachment':
+        $col_name = sprintf($image_tag, $skin_path, $attrib['attachmenticon'], '');
+        break;
+      default:
+        $col_name = Q(rcube_label($col));
+    }
 
     // make sort links
     $sort = '';
-    if ($IMAP->get_capability('sort') && in_array($col, $a_sort_cols))
+    if (in_array($col, $a_sort_cols))
       {
       // have buttons configured
       if (!empty($attrib['sortdescbutton']) || !empty($attrib['sortascbutton']))
@@ -352,61 +198,60 @@ function rcmail_message_list($attrib)
         // asc link
         if (!empty($attrib['sortascbutton']))
           {
-          $sort .= rcube_button(array('command' => 'sort',
-                                      'prop' => $col.'_ASC',
-                                      'image' => $attrib['sortascbutton'],
-                                      'align' => 'absmiddle',
-                                      'title' => 'sortasc'));
+          $sort .= $OUTPUT->button(array(
+            'command' => 'sort',
+            'prop' => $col.'_ASC',
+            'image' => $attrib['sortascbutton'],
+            'align' => 'absmiddle',
+            'title' => 'sortasc'));
           }       
         
         // desc link
         if (!empty($attrib['sortdescbutton']))
           {
-          $sort .= rcube_button(array('command' => 'sort',
-                                      'prop' => $col.'_DESC',
-                                      'image' => $attrib['sortdescbutton'],
-                                      'align' => 'absmiddle',
-                                      'title' => 'sortdesc'));        
+          $sort .= $OUTPUT->button(array(
+            'command' => 'sort',
+            'prop' => $col.'_DESC',
+            'image' => $attrib['sortdescbutton'],
+            'align' => 'absmiddle',
+            'title' => 'sortdesc'));
           }
         }
       // just add a link tag to the header
       else
         {
-        $col_name = sprintf('<a href="./#sort" onclick="return %s.command(\'sort\',\'%s\',this)" title="%s">%s</a>',
-                            $JS_OBJECT_NAME,
-                            $col,
-                            rcube_label('sortby'),
-                            $col_name);
+        $col_name = sprintf(
+          '<a href="./#sort" onclick="return %s.command(\'sort\',\'%s\',this)" title="%s">%s</a>',
+          JS_OBJECT_NAME,
+          $col,
+          rcube_label('sortby'),
+          $col_name);
         }
       }
       
     $sort_class = $col==$sort_col ? " sorted$sort_order" : '';
 
     // put it all together
-    $out .= '<td class="'.$col.$sort_class.'" id="rcmHead'.$col.'">' . "$col_name$sort</td>\n";    
+    if ($col!='attachment')
+      $out .= '<td class="'.$col.$sort_class.'" id="rcm'.$col.'">' . "$col_name$sort</td>\n";
+    else    
+      $out .= '<td class="icon" id="rcm'.$col.'">' . "$col_name$sort</td>\n";
     }
 
-  $out .= '<td class="icon">'.($attrib['attachmenticon'] ? sprintf($image_tag, $skin_path, $attrib['attachmenticon'], '') : '')."</td>\n";
   $out .= "</tr></thead>\n<tbody>\n";
 
   // no messages in this mailbox
   if (!sizeof($a_headers))
-    {
-    $out .= rep_specialchars_output(
-                               sprintf('<tr><td colspan="%d">%s</td></tr>',
-                   sizeof($a_show_cols)+2,
-                   rcube_label('nomessagesfound')));
-    }
-
+    $OUTPUT->show_message('nomessagesfound', 'notice');
 
   $a_js_message_arr = array();
 
   // create row for each message
   foreach ($a_headers as $i => $header)  //while (list($i, $header) = each($a_headers))
     {
-    $message_icon = $attach_icon = '';
+    $message_icon = $attach_icon = $flagged_icon = '';
     $js_row_arr = array();
-    $zebra_class = $i%2 ? 'even' : 'odd';
+    $zebra_class = $i%2 ? ' even' : ' odd';
 
     // set messag attributes to javascript array
     if ($header->deleted)
@@ -415,50 +260,76 @@ function rcmail_message_list($attrib)
       $js_row_arr['unread'] = true;
     if ($header->answered)
       $js_row_arr['replied'] = true;
+    if ($header->forwarded)
+      $js_row_arr['forwarded'] = true;
+    if ($header->flagged)
+      $js_row_arr['flagged'] = true;
+
     // set message icon  
     if ($attrib['deletedicon'] && $header->deleted)
       $message_icon = $attrib['deletedicon'];
+    else if ($attrib['repliedicon'] && $header->answered)
+      {
+      if ($attrib['forwardedrepliedicon'] && $header->forwarded)
+        $message_icon = $attrib['forwardedrepliedicon'];
+      else
+        $message_icon = $attrib['repliedicon'];
+      }
+    else if ($attrib['forwardedicon'] && $header->forwarded)
+      $message_icon = $attrib['forwardedicon'];
     else if ($attrib['unreadicon'] && !$header->seen)
       $message_icon = $attrib['unreadicon'];
-    else if ($attrib['repliedicon'] && $header->answered)
-      $message_icon = $attrib['repliedicon'];
     else if ($attrib['messageicon'])
       $message_icon = $attrib['messageicon'];
+
+    if ($attrib['flaggedicon'] && $header->flagged)
+      $flagged_icon = $attrib['flaggedicon'];
+    else if ($attrib['unflaggedicon'] && !$header->flagged)
+      $flagged_icon = $attrib['unflaggedicon'];
     
-       // set attachment icon
+    // set attachment icon
     if ($attrib['attachmenticon'] && preg_match("/multipart\/m/i", $header->ctype))
       $attach_icon = $attrib['attachmenticon'];
         
-    $out .= sprintf('<tr id="rcmrow%d" class="message%s%s %s">'."\n",
+    $out .= sprintf('<tr id="rcmrow%d" class="message%s%s%s%s">'."\n",
                     $header->uid,
                     $header->seen ? '' : ' unread',
                     $header->deleted ? ' deleted' : '',
-                    $zebra_class);    
+                    $header->flagged ? ' flagged' : '',
+                    $zebra_class);
     
     $out .= sprintf("<td class=\"icon\">%s</td>\n", $message_icon ? sprintf($image_tag, $skin_path, $message_icon, '') : '');
-        
+
+    $IMAP->set_charset(!empty($header->charset) ? $header->charset : $CONFIG['default_charset']);
+  
     // format each col
     foreach ($a_show_cols as $col)
       {
       if ($col=='from' || $col=='to')
-        $cont = rep_specialchars_output(rcmail_address_string($header->$col, 3, $attrib['addicon']));
+        $cont = Q(rcmail_address_string($header->$col, 3, false, $attrib['addicon']), 'show');
       else if ($col=='subject')
         {
-        $cont = rep_specialchars_output($IMAP->decode_header($header->$col), 'html', 'all');
-        // firefox/mozilla temporary workaround to pad subject with content so that whitespace in rows responds to drag+drop
-        $cont .= '<img src="./program/blank.gif" height="5" width="1000" alt="" />';
+        $action = $mbox==$CONFIG['drafts_mbox'] ? 'compose' : 'show';
+        $uid_param = $mbox==$CONFIG['drafts_mbox'] ? '_draft_uid' : '_uid';
+        $cont = abbreviate_string(trim($IMAP->decode_header($header->$col)), 160);
+        if (empty($cont)) $cont = rcube_label('nosubject');
+        $cont = $OUTPUT->browser->ie ? Q($cont) : sprintf('<a href="%s" onclick="return rcube_event.cancel(event)">%s</a>', Q(rcmail_url($action, array($uid_param=>$header->uid, '_mbox'=>$mbox))), Q($cont));
         }
+      else if ($col=='flag')
+        $cont = $flagged_icon ? sprintf($image_tag, $skin_path, $flagged_icon, '') : '';
       else if ($col=='size')
         $cont = show_bytes($header->$col);
       else if ($col=='date')
-        $cont = format_date($header->date); //date('m.d.Y G:i:s', strtotime($header->date));
+        $cont = format_date($header->date);
       else
-        $cont = rep_specialchars_output($header->$col, 'html', 'all');
+        $cont = Q($header->$col);
         
-         $out .= '<td class="'.$col.'">' . $cont . "</td>\n";
+      if ($col!='attachment')
+        $out .= '<td class="'.$col.'">' . $cont . "</td>\n";
+      else
+        $out .= sprintf("<td class=\"icon\">%s</td>\n", $attach_icon ? sprintf($image_tag, $skin_path, $attach_icon, '') : '&nbsp;');
       }
 
-    $out .= sprintf("<td class=\"icon\">%s</td>\n", $attach_icon ? sprintf($image_tag, $skin_path, $attach_icon, '') : '');
     $out .= "</tr>\n";
     
     if (sizeof($js_row_arr))
@@ -468,178 +339,255 @@ function rcmail_message_list($attrib)
   // complete message table
   $out .= "</tbody></table>\n";
   
-  
   $message_count = $IMAP->messagecount();
   
   // set client env
-  $javascript .= sprintf("%s.gui_object('mailcontframe', '%s');\n", $JS_OBJECT_NAME, 'mailcontframe');
-  $javascript .= sprintf("%s.gui_object('messagelist', '%s');\n", $JS_OBJECT_NAME, $attrib['id']);
-  $javascript .= sprintf("%s.set_env('messagecount', %d);\n", $JS_OBJECT_NAME, $message_count);
-  $javascript .= sprintf("%s.set_env('current_page', %d);\n", $JS_OBJECT_NAME, $IMAP->list_page);
-  $javascript .= sprintf("%s.set_env('pagecount', %d);\n", $JS_OBJECT_NAME, ceil($message_count/$IMAP->page_size));
-  $javascript .= sprintf("%s.set_env('sort_col', '%s');\n", $JS_OBJECT_NAME, $sort_col);
-  $javascript .= sprintf("%s.set_env('sort_order', '%s');\n", $JS_OBJECT_NAME, $sort_order);
+  $OUTPUT->add_gui_object('mailcontframe', 'mailcontframe');
+  $OUTPUT->add_gui_object('messagelist', $attrib['id']);
+  $OUTPUT->set_env('messagecount', $message_count);
+  $OUTPUT->set_env('current_page', $IMAP->list_page);
+  $OUTPUT->set_env('pagecount', ceil($message_count/$IMAP->page_size));
+  $OUTPUT->set_env('sort_col', $sort_col);
+  $OUTPUT->set_env('sort_order', $sort_order);
   
   if ($attrib['messageicon'])
-    $javascript .= sprintf("%s.set_env('messageicon', '%s%s');\n", $JS_OBJECT_NAME, $skin_path, $attrib['messageicon']);
+    $OUTPUT->set_env('messageicon', $skin_path . $attrib['messageicon']);
   if ($attrib['deletedicon'])
-    $javascript .= sprintf("%s.set_env('deletedicon', '%s%s');\n", $JS_OBJECT_NAME, $skin_path, $attrib['deletedicon']);
+    $OUTPUT->set_env('deletedicon', $skin_path . $attrib['deletedicon']);
   if ($attrib['unreadicon'])
-    $javascript .= sprintf("%s.set_env('unreadicon', '%s%s');\n", $JS_OBJECT_NAME, $skin_path, $attrib['unreadicon']);
+    $OUTPUT->set_env('unreadicon', $skin_path . $attrib['unreadicon']);
   if ($attrib['repliedicon'])
-    $javascript .= sprintf("%s.set_env('repliedicon', '%s%s');\n", $JS_OBJECT_NAME, $skin_path, $attrib['repliedicon']);
+    $OUTPUT->set_env('repliedicon', $skin_path . $attrib['repliedicon']);
+  if ($attrib['forwardedicon'])
+    $OUTPUT->set_env('forwardedicon', $skin_path . $attrib['forwardedicon']);
+  if ($attrib['forwardedrepliedicon'])
+    $OUTPUT->set_env('forwardedrepliedicon', $skin_path . $attrib['forwardedrepliedicon']);
   if ($attrib['attachmenticon'])
-    $javascript .= sprintf("%s.set_env('attachmenticon', '%s%s');\n", $JS_OBJECT_NAME, $skin_path, $attrib['attachmenticon']);
-    
-  $javascript .= sprintf("%s.set_env('messages', %s);", $JS_OBJECT_NAME, array2js($a_js_message_arr));
+    $OUTPUT->set_env('attachmenticon', $skin_path . $attrib['attachmenticon']);
+  if ($attrib['flaggedicon'])
+    $OUTPUT->set_env('flaggedicon', $skin_path . $attrib['flaggedicon']);
+  if ($attrib['unflaggedicon'])
+    $OUTPUT->set_env('unflaggedicon', $skin_path . $attrib['unflaggedicon']);
   
-  $OUTPUT->add_script($javascript);  
+  $OUTPUT->set_env('messages', $a_js_message_arr);
+  $OUTPUT->set_env('coltypes', $a_show_cols);
+  
+  $OUTPUT->include_script('list.js');
   
   return $out;
   }
 
 
-
-
-// return javascript commands to add rows to the message list
-function rcmail_js_message_list($a_headers, $insert_top=FALSE)
+/**
+ * return javascript commands to add rows to the message list
+ * or to replace the whole list (IE only)
+ */
+function rcmail_js_message_list($a_headers, $insert_top=FALSE, $replace=TRUE)
   {
-  global $CONFIG, $IMAP;
+  global $CONFIG, $IMAP, $OUTPUT;
+
+  if (empty($_SESSION['list_columns']))
+    $a_show_cols = is_array($CONFIG['list_cols']) ? $CONFIG['list_cols'] : array('subject');
+  else
+    $a_show_cols = $_SESSION['list_columns'];
 
-  $commands = '';
-  $a_show_cols = is_array($CONFIG['list_cols']) ? $CONFIG['list_cols'] : array('subject');
+  $mbox = $IMAP->get_mailbox_name();
 
   // show 'to' instead of from in sent messages
-  if (strtolower($IMAP->get_mailbox_name())=='sent' && ($f = array_search('from', $a_show_cols))
-      && !array_search('to', $a_show_cols))
+  if (($mbox == $CONFIG['sent_mbox'] || $mbox == $CONFIG['drafts_mbox'])
+      && (($f = array_search('from', $a_show_cols)) !== false) && array_search('to', $a_show_cols) === false)
     $a_show_cols[$f] = 'to';
 
-  $commands .= sprintf("this.set_message_coltypes(%s);\n", array2js($a_show_cols)); 
+  $browser = new rcube_browser;
+
+  $OUTPUT->command('set_message_coltypes', $a_show_cols);
+  if ($browser->ie && $replace)
+    $OUTPUT->command('offline_message_list', true);
 
   // loop through message headers
-  for ($n=0; $a_headers[$n]; $n++)
+  foreach ($a_headers as $n => $header)
     {
-    $header = $a_headers[$n];
     $a_msg_cols = array();
     $a_msg_flags = array();
-      
+    
+    if (empty($header))
+      continue;
+
+    $IMAP->set_charset(!empty($header->charset) ? $header->charset : $CONFIG['default_charset']);
+
+    // remove 'attachment' and 'flag' columns, we don't need them here
+    if(($key = array_search('attachment', $a_show_cols)) !== FALSE)
+      unset($a_show_cols[$key]);
+    if(($key = array_search('flag', $a_show_cols)) !== FALSE)
+      unset($a_show_cols[$key]);
+
     // format each col; similar as in rcmail_message_list()
     foreach ($a_show_cols as $col)
       {
       if ($col=='from' || $col=='to')
-        $cont = rep_specialchars_output(rcmail_address_string($header->$col, 3));
+        $cont = Q(rcmail_address_string($header->$col, 3), 'show');
       else if ($col=='subject')
-        $cont = rep_specialchars_output($IMAP->decode_header($header->$col), 'html', 'all');
+        {
+        $action = $mbox==$CONFIG['drafts_mbox'] ? 'compose' : 'show';
+        $uid_param = $mbox==$CONFIG['drafts_mbox'] ? '_draft_uid' : '_uid';
+       $cont = abbreviate_string(trim($IMAP->decode_header($header->$col)), 160);
+        if (!$cont) $cont = rcube_label('nosubject');
+        $cont = $browser->ie ? Q($cont) : sprintf('<a href="%s" onclick="return rcube_event.cancel(event)">%s</a>', Q(rcmail_url($action, array($uid_param=>$header->uid, '_mbox'=>$mbox))), Q($cont));
+        }
       else if ($col=='size')
         $cont = show_bytes($header->$col);
       else if ($col=='date')
-        $cont = format_date($header->date); //date('m.d.Y G:i:s', strtotime($header->date));
+        $cont = format_date($header->date);
       else
-        $cont = rep_specialchars_output($header->$col, 'html', 'all');
+        $cont = Q($header->$col);
           
       $a_msg_cols[$col] = $cont;
       }
 
-    $a_msg_flags['deleted'] = $header->deleted ? 1 : 0;
-    $a_msg_flags['unread'] = $header->seen ? 0 : 1;
-    $a_msg_flags['replied'] = $header->answered ? 1 : 0;
-    $commands .= sprintf("this.add_message_row(%s, %s, %s, %b, %b);\n",
-                         $header->uid,
-                         array2js($a_msg_cols),
-                         array2js($a_msg_flags),
-                         preg_match("/multipart\/m/i", $header->ctype),
-                         $insert_top);
+    if ($header->deleted)
+      $a_msg_flags['deleted'] = 1;
+    if (!$header->seen)
+      $a_msg_flags['unread'] = 1;
+    if ($header->answered)
+      $a_msg_flags['replied'] = 1;
+    if ($header->forwarded)
+      $a_msg_flags['forwarded'] = 1;
+    if ($header->flagged)
+      $a_msg_flags['flagged'] = 1;
+
+    $OUTPUT->command('add_message_row',
+      $header->uid,
+      $a_msg_cols,
+      $a_msg_flags,
+      preg_match("/multipart\/m/i", $header->ctype),
+      $insert_top);
     }
 
-  return $commands;
+    if ($browser->ie && $replace)
+      $OUTPUT->command('offline_message_list', false);
   }
 
 
-// return code for search function
-function rcmail_search_form($attrib)
+/**
+ * return an HTML iframe for loading mail content
+ */
+function rcmail_messagecontent_frame($attrib)
   {
-  global $OUTPUT, $JS_OBJECT_NAME;
-
-  // add some labels to client
-  rcube_add_label('searching');
-
-  $attrib['name'] = '_q';
+  global $OUTPUT;
   
   if (empty($attrib['id']))
-    $attrib['id'] = 'rcmqsearchbox';
-  
-  $input_q = new textfield($attrib);
-  $out = $input_q->show();
+    $attrib['id'] = 'rcmailcontentwindow';
 
-  $OUTPUT->add_script(sprintf("%s.gui_object('qsearchbox', '%s');",
-                              $JS_OBJECT_NAME,
-                              $attrib['id']));
+  $attrib['name'] = $attrib['id'];
 
-  // add form tag around text field
-  if (empty($attrib['form']))
-    $out = sprintf('<form name="rcmqsearchform" action="./" '.
-                   'onsubmit="%s.command(\'search\');return false" style="display:inline;">%s</form>',
-                   $JS_OBJECT_NAME,
-                   $out);
+  $OUTPUT->set_env('contentframe', $attrib['id']);
+  $OUTPUT->set_env('blankpage', $attrib['src'] ? $OUTPUT->abs_url($attrib['src']) : 'program/blank.gif');
 
-  return $out;
-  } 
+  return html::iframe($attrib);
+  }
 
 
+/**
+ *
+ */
 function rcmail_messagecount_display($attrib)
   {
-  global $IMAP, $OUTPUT, $JS_OBJECT_NAME;
+  global $IMAP, $OUTPUT;
   
   if (!$attrib['id'])
     $attrib['id'] = 'rcmcountdisplay';
 
-  $OUTPUT->add_script(sprintf("%s.gui_object('countdisplay', '%s');",
-                              $JS_OBJECT_NAME,
-                              $attrib['id']));
+  $OUTPUT->add_gui_object('countdisplay', $attrib['id']);
 
-  // allow the following attributes to be added to the <span> tag
-  $attrib_str = create_attrib_string($attrib, array('style', 'class', 'id'));
-
-  
-  $out = '<span' . $attrib_str . '>';
-  $out .= rcmail_get_messagecount_text();
-  $out .= '</span>';
-  return $out;
+  return html::span($attrib, rcmail_get_messagecount_text());
   }
 
 
+/**
+ *
+ */
 function rcmail_quota_display($attrib)
   {
-  global $IMAP, $OUTPUT, $JS_OBJECT_NAME;
+  global $OUTPUT, $COMM_PATH;
 
   if (!$attrib['id'])
     $attrib['id'] = 'rcmquotadisplay';
 
-  $OUTPUT->add_script(sprintf("%s.gui_object('quotadisplay', '%s');", $JS_OBJECT_NAME, $attrib['id']));
+  if(isset($attrib['display']))
+    $_SESSION['quota_display'] = $attrib['display'];
 
-  // allow the following attributes to be added to the <span> tag
-  $attrib_str = create_attrib_string($attrib, array('style', 'class', 'id'));
-  
-  if (!$IMAP->get_capability('QUOTA'))
-    $quota_text = rcube_label('unknown');
-  else if (!($quota_text = $IMAP->get_quota()))
+  $OUTPUT->add_gui_object('quotadisplay', $attrib['id']);
+
+  return html::span($attrib, rcmail_quota_content(NULL, $attrib));
+  }
+
+
+/**
+ *
+ */
+function rcmail_quota_content($quota=NULL, $attrib=NULL)
+  {
+  global $IMAP, $COMM_PATH, $RCMAIL;
+
+  $display = isset($_SESSION['quota_display']) ? $_SESSION['quota_display'] : '';
+
+  if (is_array($quota) && !empty($quota['used']) && !empty($quota['total']))
+    {
+      if (!isset($quota['percent']))
+        $quota['percent'] = $quota['used'] / $quota['total'];
+    }
+  elseif (!$IMAP->get_capability('QUOTA'))
+    return rcube_label('unknown');
+  else
+    $quota = $IMAP->get_quota();
+
+  if ($quota && !($quota['total']==0 && $RCMAIL->config->get('quota_zero_as_unlimited')))
+    {
+    $quota_text = sprintf('%s / %s (%.0f%%)',
+                          show_bytes($quota['used'] * 1024),
+                          show_bytes($quota['total'] * 1024),
+                          $quota['percent']);
+
+    // show quota as image (by Brett Patterson)
+    if ($display == 'image' && function_exists('imagegif'))
+      {
+      if (!$attrib['width'])
+        $attrib['width'] = isset($_SESSION['quota_width']) ? $_SESSION['quota_width'] : 100;
+      else
+       $_SESSION['quota_width'] = $attrib['width'];
+
+      if (!$attrib['height'])
+        $attrib['height'] = isset($_SESSION['quota_height']) ? $_SESSION['quota_height'] : 14;
+      else
+       $_SESSION['quota_height'] = $attrib['height'];
+           
+      $quota_text = sprintf('<img src="./bin/quotaimg.php?u=%s&amp;q=%d&amp;w=%d&amp;h=%d" width="%d" height="%d" alt="%s" title="%s / %s" />',
+                            $quota['used'], $quota['total'],
+                            $attrib['width'], $attrib['height'],
+                            $attrib['width'], $attrib['height'],
+                            $quota_text,
+                            show_bytes($quota['used'] * 1024),
+                            show_bytes($quota['total'] * 1024));
+      }
+    }
+  else
     $quota_text = rcube_label('unlimited');
 
-  $out = '<span' . $attrib_str . '>';
-  $out .= $quota_text;
-  $out .= '</span>';
-  return $out;
+  return $quota_text;
   }
 
 
+/**
+ *
+ */
 function rcmail_get_messagecount_text($count=NULL, $page=NULL)
   {
   global $IMAP, $MESSAGE;
   
-  if (isset($MESSAGE['index']))
+  if (isset($MESSAGE->index))
     {
     return rcube_label(array('name' => 'messagenrof',
-                             'vars' => array('nr'  => $MESSAGE['index']+1,
+                             'vars' => array('nr'  => $MESSAGE->index+1,
                                              'count' => $count!==NULL ? $count : $IMAP->messagecount())));
     }
 
@@ -657,342 +605,302 @@ function rcmail_get_messagecount_text($count=NULL, $page=NULL)
                                               'to'    => min($max, $start_msg + $IMAP->page_size - 1),
                                               'count' => $max)));
 
-  return rep_specialchars_output($out);
+  return Q($out);
   }
 
+/**
+ *
+ */
+function rcmail_mailbox_name_display($attrib)
+{
+    global $RCMAIL;
 
-function rcmail_print_body($part, $safe=FALSE, $plain=FALSE) // $body, $ctype_primary='text', $ctype_secondary='plain', $encoding='7bit', $safe=FALSE, $plain=FALSE)
-  {
-  global $IMAP, $REMOTE_OBJECTS, $JS_OBJECT_NAME;
-
-  // extract part properties: body, ctype_primary, ctype_secondary, encoding, parameters
-  extract($part);
-  
-  $block = $plain ? '%s' : '%s'; //'<div style="display:block;">%s</div>';
-  $body = $IMAP->mime_decode($body, $encoding);  
-  $body = $IMAP->charset_decode($body, $parameters);
+    if (!$attrib['id'])
+        $attrib['id'] = 'rcmmailboxname';
 
-  // text/html
-  if ($ctype_secondary=='html')
-    {
-    if (!$safe)  // remove remote images and scripts
-      {
-      $remote_patterns = array('/(src|background)=(["\']?)([hftps]{3,5}:\/{2}[^"\'\s]+)(\2|\s|>)/Ui',
-                           //  '/(src|background)=(["\']?)([\.\/]+[^"\'\s]+)(\2|\s|>)/Ui',
-                               '/(<base.*href=["\']?)([hftps]{3,5}:\/{2}[^"\'\s]+)([^<]*>)/i',
-                               '/(<link.*href=["\']?)([hftps]{3,5}:\/{2}[^"\'\s]+)([^<]*>)/i',
-                               '/url\s*\(["\']?([hftps]{3,5}:\/{2}[^"\'\s]+)["\']?\)/i',
-                               '/url\s*\(["\']?([\.\/]+[^"\'\s]+)["\']?\)/i',
-                               '/<script.+<\/script>/Umis');
-
-      $remote_replaces = array('',  // '\\1=\\2#\\4',
-                            // '\\1=\\2#\\4',
-                               '',
-                               '',  // '\\1#\\3',
-                               'none',
-                               'none',
-                               '');
-      
-      // set flag if message containes remote obejcts that where blocked
-      foreach ($remote_patterns as $pattern)
-        {
-        if (preg_match($pattern, $body))
-          {
-          $REMOTE_OBJECTS = TRUE;
-          break;
-          }
-        }
+    $RCMAIL->output->add_gui_object('mailboxname', $attrib['id']);
 
-      $body = preg_replace($remote_patterns, $remote_replaces, $body);
-      }
+    return html::span($attrib, rcmail_get_mailbox_name_text());
+}
 
-    return sprintf($block, rep_specialchars_output($body, 'html', '', FALSE));
-    }
+function rcmail_get_mailbox_name_text()
+{
+    global $RCMAIL;
+    return rcmail_localize_foldername($RCMAIL->imap->get_mailbox_name());
+}
 
-  // text/enriched
-  if ($ctype_secondary=='enriched')
-    {
-    $body = enriched_to_html($body);
-    return sprintf($block, rep_specialchars_output($body, 'html'));
+/**
+ * Sets message is_safe flag according to 'show_images' option value
+ *
+ * @param object rcube_message Message
+ */
+function rcmail_check_safe(&$message)
+{
+  global $RCMAIL;
+
+  $show_images = $RCMAIL->config->get('show_images');
+  if (!$message->is_safe
+    && !empty($show_images)
+    && $message->has_html_part())
+  {
+    switch($show_images) {
+      case '1': // known senders only
+        $CONTACTS = new rcube_contacts($RCMAIL->db, $_SESSION['user_id']);
+        if ($CONTACTS->search('email', $message->sender['mailto'], true, false)->count) {
+          $message->set_safe(true);
+        }
+      break;
+      case '2': // always
+        $message->set_safe(true);
+      break;
     }
-  else
-    {
-    // make links and email-addresses clickable
-    $convert_patterns = $convert_replaces = $replace_strings = array();
-    
-    $url_chars = 'a-z0-9_\-\+\*\$\/&%=@#:';
-    $url_chars_within = '\?\.~,!';
-
-    $convert_patterns[] = "/([\w]+):\/\/([a-z0-9\-\.]+[a-z]{2,4}([$url_chars$url_chars_within]*[$url_chars])?)/ie";
-    $convert_replaces[] = "rcmail_str_replacement('<a href=\"\\1://\\2\" target=\"_blank\">\\1://\\2</a>', \$replace_strings)";
-
-    $convert_patterns[] = "/([^\/:]|\s)(www\.)([a-z0-9\-]{2,}[a-z]{2,4}([$url_chars$url_chars_within]*[$url_chars])?)/ie";
-    $convert_replaces[] = "rcmail_str_replacement('\\1<a href=\"http://\\2\\3\" target=\"_blank\">\\2\\3</a>', \$replace_strings)";
-    
-    $convert_patterns[] = '/([a-z0-9][a-z0-9\-\.\+\_]*@[a-z0-9]([a-z0-9\-][.]?)*[a-z0-9]\\.[a-z]{2,5})/ie';
-    $convert_replaces[] = "rcmail_str_replacement('<a href=\"mailto:\\1\" onclick=\"return $JS_OBJECT_NAME.command(\'compose\',\'\\1\',this)\">\\1</a>', \$replace_strings)";
-
-    $body = wordwrap(trim($body), 80);
-    $body = preg_replace($convert_patterns, $convert_replaces, $body);
-
-    // split body into single lines
-    $a_lines = preg_split('/\r?\n/', $body);
-
-    // colorize quoted parts
-    for($n=0; $n<sizeof($a_lines); $n++)
-      {
-      $line = $a_lines[$n];
-
-      if ($line{2}=='>')
-        $color = 'red';
-      else if ($line{1}=='>')
-        $color = 'green';
-      else if ($line{0}=='>')
-        $color = 'blue';
-      else
-        $color = FALSE;
+  }
+}
 
-      $line = rep_specialchars_output($line, 'html', 'replace', FALSE);
-        
-      if ($color)
-        $a_lines[$n] = sprintf('<font color="%s">%s</font>', $color, $line);
-      else
-        $a_lines[$n] = $line;
-      }
+/**
+ * Cleans up the given message HTML Body (for displaying)
+ *
+ * @param string HTML
+ * @param array  Display parameters 
+ * @param array  CID map replaces (inline images)
+ * @return string Clean HTML
+ */
+function rcmail_wash_html($html, $p = array(), $cid_replaces)
+{
+  global $REMOTE_OBJECTS;
+  
+  $p += array('safe' => false, 'inline_html' => true);
+
+  // special replacements (not properly handled by washtml class)
+  $html_search = array(
+    '/(<\/nobr>)(\s+)(<nobr>)/i',      // space(s) between <NOBR>
+    '/<title>.*<\/title>/i',           // PHP bug #32547 workaround: remove title tag
+    '/^(\0\0\xFE\xFF|\xFF\xFE\0\0|\xFE\xFF|\xFF\xFE|\xEF\xBB\xBF)/',   // byte-order mark (only outlook?)
+    '/<html\s[^>]+>/i',                        // washtml/DOMDocument cannot handle xml namespaces
+  );
+  $html_replace = array(
+    '\\1'.' &nbsp; '.'\\3',
+    '',
+    '',
+    '<html>',
+  );
+  $html = preg_replace($html_search, $html_replace, $html);
+
+  // fix (unknown/malformed) HTML tags before "wash"
+  $html = preg_replace_callback('/(<[\/!]*)([^ >]+)/', 'rcmail_html_tag_callback', $html);
+
+  // charset was converted to UTF-8 in rcube_imap::get_message_part(),
+  // -> change charset specification in HTML accordingly
+  $charset_pattern = '(<meta\s+[^>]*)(content=[\'"]?\w+\/\w+;\s*charset)=([a-z0-9-_]+)';
+  if (preg_match("/$charset_pattern/Ui", $html)) {
+    $html = preg_replace("/$charset_pattern/i", '\\1\\2='.RCMAIL_CHARSET, $html);
+  }
+  else {
+    // add meta content-type to malformed messages, washtml cannot work without that
+    if (!preg_match('/<head[^>]*>(.*)<\/head>/Uims', $html))
+      $html = '<head></head>'. $html;
+    $html = substr_replace($html, '<meta http-equiv="Content-Type" content="text/html; charset='.RCMAIL_CHARSET.'" />', intval(stripos($html, '<head>')+6), 0);
+  }
 
-    // insert the links for urls and mailtos
-    $body = preg_replace("/##string_replacement\{([0-9]+)\}##/e", "\$replace_strings[\\1]", join("\n", $a_lines));
+  // turn relative into absolute urls
+  $html = rcmail_resolve_base($html);
+
+  // clean HTML with washhtml by Frederic Motte
+  $wash_opts = array(
+    'show_washed' => false,
+    'allow_remote' => $p['safe'],
+    'blocked_src' => "./program/blocked.gif",
+    'charset' => RCMAIL_CHARSET,
+    'cid_map' => $cid_replaces,
+    'html_elements' => array('body'),
+  );
     
-    return sprintf($block, "<pre>\n".$body."\n</pre>");
-    }
+  if (!$p['inline_html']) {
+    $wash_opts['html_elements'] = array('html','head','title','body');
   }
-
-
-
-// add a string to the replacement array and return a replacement string
-function rcmail_str_replacement($str, &$rep)
-  {
-  static $count = 0;
-  $rep[$count] = stripslashes($str);
-  return "##string_replacement{".($count++)."}##";
+  if ($p['safe']) {
+    $wash_opts['html_elements'][] = 'link';
+    $wash_opts['html_attribs'] = array('rel','type');
   }
+    
+  $washer = new washtml($wash_opts);
+  $washer->add_callback('form', 'rcmail_washtml_callback');
 
+  // allow CSS styles, will be sanitized by rcmail_washtml_callback()
+  $washer->add_callback('style', 'rcmail_washtml_callback');
+    
+  $html = $washer->wash($html);
+  $REMOTE_OBJECTS = $washer->extlinks;
+  
+  return $html;
+}
 
-function rcmail_parse_message($structure, $arg=array(), $recursive=FALSE)
-  {
-  global $IMAP;
-  static $sa_inline_objects = array();
-
-  // arguments are: (bool)$prefer_html, (string)$get_url
-  extract($arg);
-
-  $a_attachments = array();
-  $a_return_parts = array();
-  $out = '';
 
-  $message_ctype_primary = strtolower($structure->ctype_primary);
-  $message_ctype_secondary = strtolower($structure->ctype_secondary);
+/**
+ * Convert the given message part to proper HTML
+ * which can be displayed the message view
+ *
+ * @param object rcube_message_part Message part
+ * @param array  Display parameters array 
+ * @return string Formatted HTML string
+ */
+function rcmail_print_body($part, $p = array())
+{
+  global $RCMAIL;
+  
+  // trigger plugin hook
+  $data = $RCMAIL->plugins->exec_hook('message_part_before',
+    array('type' => $part->ctype_secondary, 'body' => $part->body) + $p + array('safe' => false, 'plain' => false, 'inline_html' => true));
+
+  // convert html to text/plain
+  if ($data['type'] == 'html' && $data['plain']) {
+    $txt = new html2text($data['body'], false, true);
+    $body = $txt->get_text();
+    $part->ctype_secondary = 'plain';
+  }
+  // text/html
+  else if ($data['type'] == 'html') {
+    $body = rcmail_wash_html($data['body'], $data, $part->replaces);
+    $part->ctype_secondary = $data['type'];
+  }
+  // text/enriched
+  else if ($data['type'] == 'enriched') {
+    $part->ctype_secondary = 'html';
+    require_once('lib/enriched.inc');
+    $body = Q(enriched_to_html($data['body']), 'show');
+  }
+  else {
+    // assert plaintext
+    $body = $part->body;
+    $part->ctype_secondary = $data['type'] = 'plain';
+  }
+  
+  // free some memory (hopefully)
+  unset($data['body']);
 
-  // show message headers
-  if ($recursive && is_array($structure->headers) && isset($structure->headers['subject']))
-    $a_return_parts[] = array('type' => 'headers',
-                              'headers' => $structure->headers);
+  // plaintext postprocessing
+  if ($part->ctype_secondary == 'plain') {
+    // make links and email-addresses clickable
+    $replacements = new rcube_string_replacer;
+    
+    // search for patterns like links and e-mail addresses
+    $body = preg_replace_callback($replacements->link_pattern, array($replacements, 'link_callback'), $body);
+    $body = preg_replace_callback($replacements->mailto_pattern, array($replacements, 'mailto_callback'), $body);
 
-  // print body if message doesn't have multiple parts
-  if ($message_ctype_primary=='text')
-    {
-    $a_return_parts[] = array('type' => 'content',
-                              'body' => $structure->body,
-                              'ctype_primary' => $message_ctype_primary,
-                              'ctype_secondary' => $message_ctype_secondary,
-                              'parameters' => $structure->ctype_parameters,
-                              'encoding' => $structure->headers['content-transfer-encoding']);
-    }
+    // split body into single lines
+    $a_lines = preg_split('/\r?\n/', $body);
+    $q_lines = array();
+    $quote_level = 0;
 
-  // message contains alternative parts
-  else if ($message_ctype_primary=='multipart' && $message_ctype_secondary=='alternative' && is_array($structure->parts))
-    {
-    // get html/plaintext parts
-    $plain_part = $html_part = $print_part = $related_part = NULL;
+    // find/mark quoted lines...
+    for ($n=0, $cnt=count($a_lines); $n < $cnt; $n++) {
+      $q = 0;
     
-    foreach ($structure->parts as $p => $sub_part)
-      {
-      $sub_ctype_primary = strtolower($sub_part->ctype_primary);
-      $sub_ctype_secondary = strtolower($sub_part->ctype_secondary);
-
-      // check if sub part is 
-      if ($sub_ctype_primary=='text' && $sub_ctype_secondary=='plain')
-        $plain_part = $p;
-      else if ($sub_ctype_primary=='text' && $sub_ctype_secondary=='html')
-        $html_part = $p;
-      else if ($sub_ctype_primary=='text' && $sub_ctype_secondary=='enriched')
-        $enriched_part = $p;
-      else if ($sub_ctype_primary=='multipart' && $sub_ctype_secondary=='related')
-        $related_part = $p;
+      if ($a_lines[$n][0] == '>' && preg_match('/^(>+\s*)+/', $a_lines[$n], $regs)) {
+        $q = strlen(preg_replace('/\s/', '', $regs[0]));
+       $a_lines[$n] = substr($a_lines[$n], strlen($regs[0]));
+
+        if ($q > $quote_level)
+          $q_lines[$n]['quote'] = $q - $quote_level;
+        else if ($q < $quote_level)
+          $q_lines[$n]['endquote'] = $quote_level - $q;
       }
+      else if ($quote_level > 0)
+        $q_lines[$n]['endquote'] = $quote_level;
 
-    // parse related part (alternative part could be in here)
-    if ($related_part!==NULL && $prefer_html)
-      {
-      list($parts, $attachmnts) = rcmail_parse_message($structure->parts[$related_part], $arg, TRUE);
-      $a_return_parts = array_merge($a_return_parts, $parts);
-      $a_attachments = array_merge($a_attachments, $attachmnts);
-      }
+      $quote_level = $q;
+    }
 
-    // print html/plain part
-    else if ($html_part!==NULL && $prefer_html)
-      $print_part = $structure->parts[$html_part];
-    else if ($enriched_part!==NULL)
-      $print_part = $structure->parts[$enriched_part];
-    else if ($plain_part!==NULL)
-      $print_part = $structure->parts[$plain_part];
-
-    // show message body
-    if (is_object($print_part))
-      $a_return_parts[] = array('type' => 'content',
-                                'body' => $print_part->body,
-                                'ctype_primary' => strtolower($print_part->ctype_primary),
-                                'ctype_secondary' => strtolower($print_part->ctype_secondary),
-                                'parameters' => $print_part->ctype_parameters,
-                                'encoding' => $print_part->headers['content-transfer-encoding']);
-    // show plaintext warning
-    else if ($html_part!==NULL)
-      $a_return_parts[] = array('type' => 'content',
-                                'body' => rcube_label('htmlmessage'),
-                                'ctype_primary' => 'text',
-                                'ctype_secondary' => 'plain');
-                                
-    // add html part as attachment
-    if ($html_part!==NULL && $structure->parts[$html_part]!==$print_part)
-      {
-      $html_part = $structure->parts[$html_part];
-      $a_attachments[] = array('filename' => rcube_label('htmlmessage'),
-                               'encoding' => $html_part->headers['content-transfer-encoding'],
-                               'mimetype' => 'text/html',
-                               'part_id'  => $html_part->mime_id,
-                               'size'     => strlen($IMAP->mime_decode($html_part->body, $html_part->headers['content-transfer-encoding'])));
+    // quote plain text
+    $body = Q(join("\n", $a_lines), 'replace', false);
+
+    // colorize signature
+    if (($sp = strrpos($body, '-- ')) !== false)
+      if (($sp == 0 || $body[$sp-1] == "\n") && $body[$sp+3] == "\n") {
+       $body = substr($body, 0, max(0, $sp))
+           .'<span class="sig">'.substr($body, $sp).'</span>';
       }
-    }
 
-  // message contains multiple parts
-  else if ($message_ctype_primary=='multipart' && is_array($structure->parts))
-    {
-    foreach ($structure->parts as $mail_part)
-      {
-      $primary_type = strtolower($mail_part->ctype_primary);
-      $secondary_type = strtolower($mail_part->ctype_secondary);
+    // colorize quoted lines
+    $a_lines = preg_split('/\n/', $body);
+    foreach ($q_lines as $i => $q)
+      if ($q['quote'])
+        $a_lines[$i] = str_repeat('<blockquote>', $q['quote']) . $a_lines[$i];
+      else if ($q['endquote'])
+        $a_lines[$i] = str_repeat('</blockquote>', $q['endquote']) . $a_lines[$i];
 
-      // multipart/alternative
-      if ($primary_type=='multipart') // && ($secondary_type=='alternative' || $secondary_type=='mixed' || $secondary_type=='related'))
-        {
-        list($parts, $attachmnts) = rcmail_parse_message($mail_part, $arg, TRUE);
+    // insert the links for urls and mailtos
+    $body = $replacements->resolve(join("\n", $a_lines));
+  }
 
-        $a_return_parts = array_merge($a_return_parts, $parts);
-        $a_attachments = array_merge($a_attachments, $attachmnts);
-        }
+  // allow post-processing of the message body
+  $data = $RCMAIL->plugins->exec_hook('message_part_after', array('type' => $part->ctype_secondary, 'body' => $body) + $data);
 
-      // part text/[plain|html] OR message/delivery-status
-      else if (($primary_type=='text' && ($secondary_type=='plain' || $secondary_type=='html') && $mail_part->disposition!='attachment') ||
-               ($primary_type=='message' && $secondary_type=='delivery-status'))
-        {
-        $a_return_parts[] = array('type' => 'content',
-                                  'body' => $mail_part->body,
-                                  'ctype_primary' => $primary_type,
-                                  'ctype_secondary' => $secondary_type,
-                                  'parameters' => $mail_part->ctype_parameters,
-                                  'encoding' => $mail_part->headers['content-transfer-encoding']);
-        }
+  return $data['type'] == 'html' ? $data['body'] : html::tag('pre', array(), $data['body']);
+}
 
-      // part message/*
-      else if ($primary_type=='message')
-        {
-        /* don't parse headers here; they're parsed within the recursive call to rcmail_parse_message()
-        if ($mail_part->parts[0]->headers)
-          $a_return_parts[] = array('type' => 'headers',
-                                    'headers' => $mail_part->parts[0]->headers);
-        */
-                                      
-        list($parts, $attachmnts) = rcmail_parse_message($mail_part->parts[0], $arg, TRUE);
-
-        $a_return_parts = array_merge($a_return_parts, $parts);
-        $a_attachments = array_merge($a_attachments, $attachmnts);
-        }
 
-      // part is file/attachment
-      else if ($mail_part->disposition=='attachment' || $mail_part->disposition=='inline' || $mail_part->headers['content-id'] ||
-               (empty($mail_part->disposition) && ($mail_part->d_parameters['filename'] || $mail_part->ctype_parameters['name'])))
-        {
-        if ($message_ctype_secondary=='related' && $mail_part->headers['content-id'])
-          $sa_inline_objects[] = array('filename' => rcube_imap::decode_mime_string($mail_part->d_parameters['filename']),
-                                       'mimetype' => strtolower("$primary_type/$secondary_type"),
-                                       'part_id'  => $mail_part->mime_id,
-                                       'content_id' => preg_replace(array('/^</', '/>$/'), '', $mail_part->headers['content-id']));
-
-        else if ($mail_part->d_parameters['filename'])
-          $a_attachments[] = array('filename' => rcube_imap::decode_mime_string($mail_part->d_parameters['filename']),
-                                   'encoding' => strtolower($mail_part->headers['content-transfer-encoding']),
-                                   'mimetype' => strtolower("$primary_type/$secondary_type"),
-                                   'part_id'  => $mail_part->mime_id,
-                                   'size'     => strlen($IMAP->mime_decode($mail_part->body, $mail_part->headers['content-transfer-encoding'])) /*,
-                                   'content'  => $mail_part->body */);
-                                   
-        else if ($mail_part->ctype_parameters['name'])
-          $a_attachments[] = array('filename' => rcube_imap::decode_mime_string($mail_part->ctype_parameters['name']),
-                                   'encoding' => strtolower($mail_part->headers['content-transfer-encoding']),
-                                   'mimetype' => strtolower("$primary_type/$secondary_type"),
-                                   'part_id'  => $mail_part->mime_id,
-                                   'size'     => strlen($IMAP->mime_decode($mail_part->body, $mail_part->headers['content-transfer-encoding'])) /*,
-                                   'content'  => $mail_part->body */);
-                                   
-        else if ($mail_part->headers['content-description'])
-         $a_attachments[] = array('filename' => rcube_imap::decode_mime_string($mail_part->headers['content-description']),
-                                  'encoding' => strtolower($mail_part->headers['content-transfer-encoding']),
-                                   'mimetype' => strtolower("$primary_type/$secondary_type"),
-                                   'part_id'  => $mail_part->mime_id,
-                                   'size'     => strlen($IMAP->mime_decode($mail_part->body, $mail_part->headers['content-transfer-encoding'])) /*,
-                                   'content'  => $mail_part->body */);
-        }
-      }
+/**
+ * add a string to the replacement array and return a replacement string
+ */
+function rcmail_str_replacement($str, &$rep)
+{
+  static $count = 0;
+  $rep[$count] = stripslashes($str);
+  return "##string_replacement{".($count++)."}##";
+}
 
 
-    // if this was a related part try to resolve references
-    if ($message_ctype_secondary=='related' && sizeof($sa_inline_objects))
-      {
-      $a_replace_patters = array();
-      $a_replace_strings = array();
-        
-      foreach ($sa_inline_objects as $inline_object)
-        {
-        $a_replace_patters[] = 'cid:'.$inline_object['content_id'];
-        $a_replace_strings[] = sprintf($get_url, $inline_object['part_id']);
-        }
+/**
+ * Callback function for washtml cleaning class
+ */
+function rcmail_washtml_callback($tagname, $attrib, $content)
+{
+  switch ($tagname) {
+    case 'form':
+      $out = html::div('form', $content);
+      break;
       
-      foreach ($a_return_parts as $i => $return_part)
-        {
-        if ($return_part['type']!='content')
-          continue;
-
-        // decode body and replace cid:...
-        $a_return_parts[$i]['body'] = str_replace($a_replace_patters, $a_replace_strings, $IMAP->mime_decode($return_part['body'], $return_part['encoding']));
-        $a_return_parts[$i]['encoding'] = '7bit';
-        }
+    case 'style':
+      // decode all escaped entities and reduce to ascii strings
+      $stripped = preg_replace('/[^a-zA-Z\(:]/', '', rcmail_xss_entity_decode($content));
+      
+      // now check for evil strings like expression, behavior or url()
+      if (!preg_match('/expression|behavior|url\(|import/', $stripped)) {
+        $out = html::tag('style', array('type' => 'text/css'), $content);
+        break;
       }
-    }
     
+    default:
+      $out = '';
+  }
+  
+  return $out;
+}
 
-  // join all parts together
-  //$out .= join($part_delimiter, $a_return_parts);
 
-  return array($a_return_parts, $a_attachments);
-  }
+/**
+ * Callback function for HTML tags fixing
+ */
+function rcmail_html_tag_callback($matches)
+{
+  $tagname = $matches[2];
 
+  $tagname = preg_replace(array(
+    '/:.*$/',          // Microsoft's Smart Tags <st1:xxxx>
+    '/[^a-z0-9_-]/i',  // forbidden characters
+    ), '', $tagname);
 
+  return $matches[1].$tagname;
+}
 
 
-// return table with message headers
+/**
+ * return table with message headers
+ */
 function rcmail_message_headers($attrib, $headers=NULL)
   {
-  global $IMAP, $OUTPUT, $MESSAGE;
+  global $IMAP, $OUTPUT, $MESSAGE, $PRINT_MODE, $RCMAIL;
   static $sa_attrib;
   
   // keep header table attrib
@@ -1001,384 +909,248 @@ function rcmail_message_headers($attrib, $headers=NULL)
   else if (!is_array($attrib) && is_array($sa_attrib))
     $attrib = $sa_attrib;
   
-  
   if (!isset($MESSAGE))
     return FALSE;
 
   // get associative array of headers object
   if (!$headers)
-    $headers = is_object($MESSAGE['headers']) ? get_object_vars($MESSAGE['headers']) : $MESSAGE['headers'];
-    
-  $header_count = 0;
-  
-  // allow the following attributes to be added to the <table> tag
-  $attrib_str = create_attrib_string($attrib, array('style', 'class', 'id', 'cellpadding', 'cellspacing', 'border', 'summary'));
-  $out = '<table' . $attrib_str . ">\n";
+    $headers = is_object($MESSAGE->headers) ? get_object_vars($MESSAGE->headers) : $MESSAGE->headers;
 
   // show these headers
-  $standard_headers = array('subject', 'from', 'organization', 'to', 'cc', 'bcc', 'reply-to', 'date');
-  
-  foreach ($standard_headers as $hkey)
-    {
+  $standard_headers = array('subject', 'from', 'to', 'cc', 'bcc', 'replyto', 'date');
+  $output_headers = array();
+
+  foreach ($standard_headers as $hkey) {
     if (!$headers[$hkey])
       continue;
 
-    if ($hkey=='date' && !empty($headers[$hkey]))
-      $header_value = format_date(strtotime($headers[$hkey]));
-    else if (in_array($hkey, array('from', 'to', 'cc', 'bcc', 'reply-to')))
-      $header_value = rep_specialchars_output(rcmail_address_string($headers[$hkey], NULL, $attrib['addicon']));
-    else
-      $header_value = rep_specialchars_output($IMAP->decode_header($headers[$hkey]), '', 'all');
-
-    $out .= "\n<tr>\n";
-    $out .= '<td class="header-title">'.rep_specialchars_output(rcube_label($hkey)).":&nbsp;</td>\n";
-    $out .= '<td class="'.$hkey.'" width="90%">'.$header_value."</td>\n</tr>";
-    $header_count++;
+    if ($hkey == 'date') {
+      if ($PRINT_MODE)
+        $header_value = format_date($headers[$hkey], $RCMAIL->config->get('date_long', 'x'));
+      else
+        $header_value = format_date($headers[$hkey]);
     }
+    else if ($hkey == 'replyto') {
+      if ($headers['replyto'] != $headers['from'])
+        $header_value = rcmail_address_string($headers['replyto'], null, true, $attrib['addicon']);
+      else
+        continue;
+    }
+    else if (in_array($hkey, array('from', 'to', 'cc', 'bcc')))
+      $header_value = rcmail_address_string($headers[$hkey], null, true, $attrib['addicon']);
+    else if ($hkey == 'subject' && empty($headers[$hkey]))
+      $header_value = rcube_label('nosubject');
+    else
+      $header_value = trim($IMAP->decode_header($headers[$hkey]));
+      
+    $output_headers[$hkey] = array('title' => rcube_label($hkey), 'value' => $header_value, 'raw' => $headers[$hkey]);
+  }
+    
+  $plugin = $RCMAIL->plugins->exec_hook('message_headers_output', array('output' => $output_headers, 'headers' => $MESSAGE->headers));
+  
+  // compose html table
+  $table = new html_table(array('cols' => 2));
+  
+  foreach ($plugin['output'] as $hkey => $row) {
+    $table->add(array('class' => 'header-title'), Q($row['title']));
+    $table->add(array('class' => $hkey, 'width' => "90%"), Q($row['value'], ($hkey == 'subject' ? 'strict' : 'show')));
+  }
 
-  $out .= "\n</table>\n\n";
+  // all headers division
+  $table->add(array('colspan' => 2, 'class' => "more-headers show-headers", 'onclick' => "return ".JS_OBJECT_NAME.".command('load-headers','',this)"), '');
+  $table->add_row(array('id' => "all-headers"));
+  $table->add(array('colspan' => 2, 'class' => "all"), html::div(array('id' => 'headers-source'), ''));
+  
+  $OUTPUT->add_gui_object('all_headers_row', 'all-headers');
+  $OUTPUT->add_gui_object('all_headers_box', 'headers-source');
 
-  return $header_count ? $out : '';  
+  return $table->show($attrib);
   }
 
 
-
+/**
+ * Handler for the 'messagebody' GUI object
+ *
+ * @param array Named parameters
+ * @return string HTML content showing the message body
+ */
 function rcmail_message_body($attrib)
   {
-  global $CONFIG, $OUTPUT, $MESSAGE, $GET_URL, $REMOTE_OBJECTS, $JS_OBJECT_NAME;
-  
-  if (!is_array($MESSAGE['parts']) && !$MESSAGE['body'])
+  global $CONFIG, $OUTPUT, $MESSAGE, $IMAP, $REMOTE_OBJECTS;
+
+  if (!is_array($MESSAGE->parts) && empty($MESSAGE->body))
     return '';
     
   if (!$attrib['id'])
     $attrib['id'] = 'rcmailMsgBody';
 
-  $safe_mode = (bool)$_GET['_safe'];
-  $attrib_str = create_attrib_string($attrib, array('style', 'class', 'id'));
-  $out = '<div '. $attrib_str . ">\n";
+  $safe_mode = $MESSAGE->is_safe || intval($_GET['_safe']);
+  $out = '';
   
   $header_attrib = array();
   foreach ($attrib as $attr => $value)
     if (preg_match('/^headertable([a-z]+)$/i', $attr, $regs))
       $header_attrib[$regs[1]] = $value;
 
-
-  // this is an ecrypted message
-  // -> create a plaintext body with the according message
-  if (!sizeof($MESSAGE['parts']) && $MESSAGE['headers']->ctype=='multipart/encrypted')
+  if (!empty($MESSAGE->parts))
     {
-    $MESSAGE['parts'][0] = array('type' => 'content',
-                                 'ctype_primary' => 'text',
-                                 'ctype_secondary' => 'plain',
-                                 'body' => rcube_label('encryptedmessage'));
-    }
-  
-  if ($MESSAGE['parts'])
-    {
-    foreach ($MESSAGE['parts'] as $i => $part)
+    foreach ($MESSAGE->parts as $i => $part)
       {
-      if ($part['type']=='headers')
-        $out .= rcmail_message_headers(sizeof($header_attrib) ? $header_attrib : NULL, $part['headers']);
-      else if ($part['type']=='content')
+      if ($part->type == 'headers')
+        $out .= rcmail_message_headers(sizeof($header_attrib) ? $header_attrib : NULL, $part->headers);
+      else if ($part->type == 'content' && $part->size)
         {
-        if (empty($part['parameters']) || empty($part['parameters']['charset']))
-          $part['parameters']['charset'] = $MESSAGE['headers']->charset;
-        
-        // $body = rcmail_print_body($part['body'], $part['ctype_primary'], $part['ctype_secondary'], $part['encoding'], $safe_mode);
-        $body = rcmail_print_body($part, $safe_mode);
-        $out .= '<div class="message-part">';
-        
-        if ($part['ctype_secondary']!='plain')
-          $out .= rcmail_mod_html_body($body, $attrib['id']);
-        else
-          $out .= $body;
+        if (empty($part->ctype_parameters) || empty($part->ctype_parameters['charset']))
+          $part->ctype_parameters['charset'] = $MESSAGE->headers->charset;
+
+        // fetch part if not available
+        if (!isset($part->body))
+          $part->body = $MESSAGE->get_part_content($part->mime_id);
+
+        $body = rcmail_print_body($part, array('safe' => $safe_mode, 'plain' => !$CONFIG['prefer_html']));
 
-        $out .= "</div>\n";
+        if ($part->ctype_secondary == 'html')
+          $out .= html::div('message-htmlpart', rcmail_html4inline($body, $attrib['id']));
+        else
+          $out .= html::div('message-part', $body);
         }
       }
     }
   else
-    $out .= $MESSAGE['body'];
+    $out .= html::div('message-part', html::tag('pre', array(), Q($MESSAGE->body)));
 
+  $ctype_primary = strtolower($MESSAGE->structure->ctype_primary);
+  $ctype_secondary = strtolower($MESSAGE->structure->ctype_secondary);
 
-  $ctype_primary = strtolower($MESSAGE['structure']->ctype_primary);
-  $ctype_secondary = strtolower($MESSAGE['structure']->ctype_secondary);
-  
   // list images after mail body
-  if (get_boolean($attrib['showimages']) && $ctype_primary=='multipart' && $ctype_secondary=='mixed' &&
-      sizeof($MESSAGE['attachments']) && !strstr($message_body, '<html') && strlen($GET_URL))
+  if ($CONFIG['inline_images']
+      && $ctype_primary == 'multipart'
+      && !empty($MESSAGE->attachments) 
+      && !strstr($message_body, '<html'))
     {
-    foreach ($MESSAGE['attachments'] as $attach_prop)
-      {
-      if (strpos($attach_prop['mimetype'], 'image/')===0)
-        $out .= sprintf("\n<hr />\n<p align=\"center\"><img src=\"%s&_part=%s\" alt=\"%s\" title=\"%s\" /></p>\n",
-                        $GET_URL, $attach_prop['part_id'],
-                        $attach_prop['filename'],
-                        $attach_prop['filename']);
-      }
+    foreach ($MESSAGE->attachments as $attach_prop) {
+      if (strpos($attach_prop->mimetype, 'image/') === 0) {
+        $out .= html::tag('hr') . html::p(array('align' => "center"),
+          html::img(array(
+            'src' => $MESSAGE->get_part_url($attach_prop->mime_id),
+            'title' => $attach_prop->filename,
+            'alt' => $attach_prop->filename,
+          )));
+        }
     }
+  }
   
   // tell client that there are blocked remote objects
   if ($REMOTE_OBJECTS && !$safe_mode)
-    $OUTPUT->add_script(sprintf("%s.set_env('blockedobjects', true);", $JS_OBJECT_NAME));
+    $OUTPUT->set_env('blockedobjects', true);
 
-  $out .= "\n</div>";
-  return $out;
+  return html::div($attrib, $out);
   }
 
 
+/**
+ * Convert all relative URLs according to a <base> in HTML
+ */
+function rcmail_resolve_base($body)
+{
+  // check for <base href=...>
+  if (preg_match('!(<base.*href=["\']?)([hftps]{3,5}://[a-z0-9/.%-]+)!i', $body, $regs)) {
+    $replacer = new rcube_base_replacer($regs[2]);
+
+    // replace all relative paths
+    $body = preg_replace_callback('/(src|background|href)=(["\']?)([\.\/]+[^"\'\s]+)(\2|\s|>)/Ui', array($replacer, 'callback'), $body);
+    $body = preg_replace_callback('/(url\s*\()(["\']?)([\.\/]+[^"\'\)\s]+)(\2)\)/Ui', array($replacer, 'callback'), $body);
+  }
+
+  return $body;
+}
 
-// modify a HTML message that it can be displayed inside a HTML page
-function rcmail_mod_html_body($body, $container_id)
+/**
+ * modify a HTML message that it can be displayed inside a HTML page
+ */
+function rcmail_html4inline($body, $container_id)
   {
-  // remove any null-byte characters before parsing
-  $body = preg_replace('/\x00/', '', $body);
-  
   $last_style_pos = 0;
   $body_lc = strtolower($body);
   
   // find STYLE tags
   while (($pos = strpos($body_lc, '<style', $last_style_pos)) && ($pos2 = strpos($body_lc, '</style>', $pos)))
     {
-    $pos2 += 8;
-    $body_pre = substr($body, 0, $pos);
-    $styles = substr($body, $pos, $pos2-$pos);
-    $body_post = substr($body, $pos2, strlen($body)-$pos2);
-    
-    // replace all css definitions with #container [def]
-    $styles = rcmail_mod_css_styles($styles, $container_id);
-    
-    $body = $body_pre . $styles . $body_post;
-    $last_style_pos = $pos2;
-    }
-
+    $pos = strpos($body_lc, '>', $pos)+1;
 
-  // remove SCRIPT tags
-  foreach (array('script', 'applet', 'object', 'embed', 'iframe') as $tag)
-    {
-    while (($pos = strpos($body_lc, '<'.$tag)) && ($pos2 = strpos($body_lc, '</'.$tag.'>', $pos)))
-      {
-      $pos2 += 8;
-      $body = substr($body, 0, $pos) . substr($body, $pos2, strlen($body)-$pos2);
-      $body_lc = strtolower($body);
-      }
-    }
+    // replace all css definitions with #container [def]
+    $styles = rcmail_mod_css_styles(substr($body, $pos, $pos2-$pos), $container_id);
 
-  // replace event handlers on any object
-  while ($body != $prev_body)
-    {
-    $prev_body = $body;
-    $body = preg_replace('/(<[^!][^>]*\s)(on[^=>]+)=([^>]+>)/im', '$1__removed=$3', $body);
-    $body = preg_replace('/(<[^!][^>]*\shref=["\']?)(javascript:)([^>]*?>)/im', '$1null:$3', $body);
+    $body = substr($body, 0, $pos) . $styles . substr($body, $pos2);
+    $body_lc = strtolower($body);
+    $last_style_pos = $pos2;
     }
 
-  // resolve <base href>
-  $base_reg = '/(<base.*href=["\']?)([hftps]{3,5}:\/{2}[^"\'\s]+)([^<]*>)/i';
-  if (preg_match($base_reg, $body, $regs))
-    {
-    $base_url = $regs[2];
-    $body = preg_replace('/(src|background|href)=(["\']?)([\.\/]+[^"\'\s]+)(\2|\s|>)/Uie', "'\\1=\"'.make_absolute_url('\\3', '$base_url').'\"'", $body);
-    $body = preg_replace('/(url\s*\()(["\']?)([\.\/]+[^"\'\)\s]+)(\2)\)/Uie', "'\\1\''.make_absolute_url('\\3', '$base_url').'\')'", $body);
-    $body = preg_replace($base_reg, '', $body);
-    }
-    
   // modify HTML links to open a new window if clicked
-  $body = preg_replace('/<a\s+([^>]+)>/Uie', "rcmail_alter_html_link('\\1');", $body);
+  $GLOBALS['rcmail_html_container_id'] = $container_id;
+  $body = preg_replace_callback('/<(a|link)\s+([^>]+)>/Ui', 'rcmail_alter_html_link', $body);
+  unset($GLOBALS['rcmail_html_container_id']);
 
   // add comments arround html and other tags
-  $out = preg_replace(array('/(<\/?html[^>]*>)/i',
-                            '/(<\/?head[^>]*>)/i',
-                            '/(<title[^>]*>.*<\/title>)/Ui',
-                            '/(<\/?meta[^>]*>)/i'),
-                      '<!--\\1-->',
-                      $body);
-                      
-  $out = preg_replace(array('/(<body[^>]*>)/i',
-                            '/(<\/body>)/i'),
-                      array('<div class="rcmBody">',
-                            '</div>'),
-                      $out);
-  
+  $out = preg_replace(array(
+      '/(<!DOCTYPE[^>]*>)/i',
+      '/(<\?xml[^>]*>)/i',
+      '/(<\/?html[^>]*>)/i',
+      '/(<\/?head[^>]*>)/i',
+      '/(<title[^>]*>.*<\/title>)/Ui',
+      '/(<\/?meta[^>]*>)/i'),
+    '<!--\\1-->',
+    $body);
+
+  $out = preg_replace(
+    array('/<body([^>]*)>/i', '/<\/body>/i'),
+    array('<div class="rcmBody"\\1>', '</div>'),
+    $out);
+
+  // quote <? of php and xml files that are specified as text/html
+  $out = preg_replace(array('/<\?/', '/\?>/'), array('&lt;?', '?&gt;'), $out);
+
   return $out;
   }
 
 
-// parse link attributes and set correct target
-function rcmail_alter_html_link($in)
-  {
-  $attrib = parse_attrib_string($in);
-
-  if (stristr((string)$attrib['href'], 'mailto:'))
-    $attrib['onclick'] = sprintf("return %s.command('compose','%s',this)",
-                                 $GLOBALS['JS_OBJECT_NAME'],
-                                 preg_replace("/'+/i","",substr($attrib['href'], 7)));
-  else if (!empty($attrib['href']) && $attrib['href']{0}!='#')
-    $attrib['target'] = '_blank';
+/**
+ * parse link attributes and set correct target
+ */
+function rcmail_alter_html_link($matches)
+{
+  global $EMAIL_ADDRESS_PATTERN;
   
-  return '<a' . create_attrib_string($attrib, array('href', 'name', 'target', 'onclick', 'id', 'class', 'style', 'title')) . '>';
-  }
-
+  $tag = $matches[1];
+  $attrib = parse_attrib_string($matches[2]);
+  $end = '>';
 
-// replace all css definitions with #container [def]
-function rcmail_mod_css_styles($source, $container_id)
-  {
-  $a_css_values = array();
-  $last_pos = 0;
-  
-  // cut out all contents between { and }
-  while (($pos = strpos($source, '{', $last_pos)) && ($pos2 = strpos($source, '}', $pos)))
-    {
-    $key = sizeof($a_css_values);
-    $a_css_values[$key] = substr($source, $pos+1, $pos2-($pos+1));
-    $source = substr($source, 0, $pos+1) . "<<str_replacement[$key]>>" . substr($source, $pos2, strlen($source)-$pos2);
-    $last_pos = $pos+2;
-    }
-  
-  $styles = preg_replace('/(^\s*|,\s*)([a-z0-9\._][a-z0-9\.\-_]*)/im', "\\1#$container_id \\2", $source);
-  $styles = preg_replace('/<<str_replacement\[([0-9]+)\]>>/e', "\$a_css_values[\\1]", $styles);
-  
-  // replace body definition because we also stripped off the <body> tag
-  $styles = preg_replace("/$container_id\s+body/i", "$container_id div.rcmBody", $styles);
-  
-  return $styles;
+  if ($tag == 'link' && preg_match('/^https?:\/\//i', $attrib['href'])) {
+    $attrib['href'] = "./bin/modcss.php?u=" . urlencode($attrib['href']) . "&amp;c=" . urlencode($GLOBALS['rcmail_html_container_id']);
+    $end = ' />';
   }
-
-
-
-// return first text part of a message
-function rcmail_first_text_part($message_parts)
-  {
-  if (!is_array($message_parts))
-    return FALSE;
-    
-  $html_part = NULL;
-      
-  // check all message parts
-  foreach ($message_parts as $pid => $part)
-    {
-    $mimetype = strtolower($part->ctype_primary.'/'.$part->ctype_secondary);
-    if ($mimetype=='text/plain')
-      {
-      $body = rcube_imap::mime_decode($part->body, $part->headers['content-transfer-encoding']);
-      $body = rcube_imap::charset_decode($body, $part->ctype_parameters);
-      return $body;
-      }
-    else if ($mimetype=='text/html')
-      {
-      $html_part = rcube_imap::mime_decode($part->body, $part->headers['content-transfer-encoding']);
-      $html_part = rcube_imap::charset_decode($html_part, $part->ctype_parameters);
-      }
-    }
-    
-
-  // convert HTML to plain text
-  if ($html_part)
-    {    
-    // remove special chars encoding
-    $trans = array_flip(get_html_translation_table(HTML_ENTITIES));
-    $html_part = strtr($html_part, $trans);
-
-    // create instance of html2text class
-    $txt = new html2text($html_part);
-    return $txt->get_text();
-    }
-
-  return FALSE;
+  else if (preg_match("/^mailto:$EMAIL_ADDRESS_PATTERN/i", $attrib['href'], $mailto)) {
+    $attrib['href'] = $mailto[0];
+    $attrib['onclick'] = sprintf(
+      "return %s.command('compose','%s',this)",
+      JS_OBJECT_NAME,
+      JQ($mailto[1]));
+  }
+  else if (!empty($attrib['href']) && $attrib['href'][0] != '#') {
+    $attrib['target'] = '_blank';
   }
 
+  return "<$tag" . html::attrib_string($attrib, array('href','name','target','onclick','id','class','style','title','rel','type','media')) . $end;
+}
 
-// get source code of a specific message and cache it
-function rcmail_message_source($uid)
-  {
-  global $IMAP, $DB, $CONFIG;
-
-  // get message ID if uid is given
-  $cache_key = $IMAP->mailbox.'.msg';
-  $cached = $IMAP->get_cached_message($cache_key, $uid, FALSE);
-  
-  // message is cached in database
-  if ($cached && !empty($cached->body))
-    return $cached->body;
-
-  if (!$cached)
-    $headers = $IMAP->get_headers($uid);
-  else
-    $headers = &$cached;
-
-  // create unique identifier based on message_id
-  if (!empty($headers->messageID))
-    $message_id = md5($headers->messageID);
-  else
-    $message_id = md5($headers->uid.'@'.$_SESSION['imap_host']);
-  
-  $temp_dir = $CONFIG['temp_dir'].(!eregi('\/$', $CONFIG['temp_dir']) ? '/' : '');
-  $cache_dir = $temp_dir.$_SESSION['client_id'];
-  $cache_path = $cache_dir.'/'.$message_id;
-
-  // message is cached in temp dir
-  if ($CONFIG['enable_caching'] && is_dir($cache_dir) && is_file($cache_path))
-    {
-    if ($fp = fopen($cache_path, 'r'))
-      {
-      $msg_source = fread($fp, filesize($cache_path));
-      fclose($fp);
-      return $msg_source;
-      }
-    }
-
-
-  // get message from server
-  $msg_source = $IMAP->get_raw_body($uid);
-  
-  // return message source without caching
-  if (!$CONFIG['enable_caching'])
-    return $msg_source;
-
-
-  // let's cache the message body within the database
-  if ($cached && ($CONFIG['db_max_length'] -300) > $headers->size)
-    {
-    $DB->query("UPDATE ".get_table_name('messages')."
-                SET    body=?
-                WHERE  user_id=?
-                AND    cache_key=?
-                AND    uid=?",
-               $msg_source,
-               $_SESSION['user_id'],
-               $cache_key,
-               $uid);
-
-    return $msg_source;
-    }
-
-
-  // create dir for caching
-  if (!is_dir($cache_dir))
-    $dir = mkdir($cache_dir);
-  else
-    $dir = true;
-
-  // attempt to write a file with the message body    
-  if ($dir && ($fp = fopen($cache_path, 'w')))
-    {
-    fwrite($fp, $msg_source);
-    fclose($fp);
-    }
-  else
-    {
-    raise_error(array('code' => 403, 'type' => 'php', 'line' => __LINE__, 'file' => __FILE__, 
-                      'message' => "Failed to write to temp dir"), TRUE, FALSE);
-    }
-
-  return $msg_source;
-  }
 
+/**
+ * decode address string and re-format it as HTML links
+ */
+function rcmail_address_string($input, $max=null, $linked=false, $addicon=null)
+{
+  global $IMAP, $PRINT_MODE, $CONFIG, $OUTPUT, $EMAIL_ADDRESS_PATTERN;
 
-// decode address string and re-format it as HTML links
-function rcmail_address_string($input, $max=NULL, $addicon=NULL)
-  {
-  global $IMAP, $PRINT_MODE, $CONFIG, $OUTPUT, $JS_OBJECT_NAME, $EMAIL_ADDRESS_PATTERN;
-  
   $a_parts = $IMAP->decode_address_list($input);
 
   if (!sizeof($a_parts))
@@ -1388,82 +1160,125 @@ function rcmail_address_string($input, $max=NULL, $addicon=NULL)
   $j = 0;
   $out = '';
 
-  foreach ($a_parts as $part)
-    {
+  foreach ($a_parts as $part) {
     $j++;
-    if ($PRINT_MODE)
-      $out .= sprintf('%s &lt;%s&gt;', rep_specialchars_output($part['name']), $part['mailto']);
-    else if (preg_match($EMAIL_ADDRESS_PATTERN, $part['mailto']))
-      {
-      $out .= sprintf('<a href="mailto:%s" onclick="return %s.command(\'compose\',\'%s\',this)" class="rcmContactAddress" title="%s">%s</a>',
-                      $part['mailto'],
-                      $JS_OBJECT_NAME,
-                      $part['mailto'],
-                      $part['mailto'],
-                      rep_specialchars_output($part['name']));
-                      
-      if ($addicon)
-        $out .= sprintf('&nbsp;<a href="#add" onclick="return %s.command(\'add-contact\',\'%s\',this)" title="%s"><img src="%s%s" alt="add" border="0" /></a>',
-                        $JS_OBJECT_NAME,
-                        urlencode($part['string']),
-                        rcube_label('addtoaddressbook'),
-                        $CONFIG['skin_path'],
-                        $addicon);
+    if ($PRINT_MODE) {
+      $out .= sprintf('%s &lt;%s&gt;', Q($part['name']), $part['mailto']);
+    }
+    else if (preg_match("/$EMAIL_ADDRESS_PATTERN/i", $part['mailto'])) {
+      if ($linked) {
+        $out .= html::a(array(
+            'href' => 'mailto:'.$part['mailto'],
+            'onclick' => sprintf("return %s.command('compose','%s',this)", JS_OBJECT_NAME, JQ($part['mailto'])),
+            'title' => $part['mailto'],
+            'class' => "rcmContactAddress",
+          ),
+        Q($part['name']));
       }
-    else
-      {
+      else {
+        $out .= html::span(array('title' => $part['mailto'], 'class' => "rcmContactAddress"), Q($part['name']));
+      }
+
+      if ($addicon) {
+        $out .= '&nbsp;' . html::a(array(
+            'href' => "#add",
+            'onclick' => sprintf("return %s.command('add-contact','%s',this)", JS_OBJECT_NAME, urlencode($part['string'])),
+            'title' => rcube_label('addtoaddressbook'),
+          ),
+          html::img(array(
+            'src' => $CONFIG['skin_path'] . $addicon,
+            'alt' => "Add contact",
+          )));
+      }
+    }
+    else {
       if ($part['name'])
-        $out .= rep_specialchars_output($part['name']);
+        $out .= Q($part['name']);
       if ($part['mailto'])
-        $out .= (strlen($out) ? ' ' : '') . sprintf('&lt;%s&gt;', $part['mailto']);
-      }
+        $out .= (strlen($out) ? ' ' : '') . sprintf('&lt;%s&gt;', Q($part['mailto']));
+    }
       
     if ($c>$j)
       $out .= ','.($max ? '&nbsp;' : ' ');
         
-    if ($max && $j==$max && $c>$j)
-      {
+    if ($max && $j==$max && $c>$j) {
       $out .= '...';
       break;
-      }        
     }
+  }
     
   return $out;
+}
+
+
+/**
+ * Wrap text to a given number of characters per line
+ * but respect the mail quotation of replies messages (>)
+ *
+ * @param string Text to wrap
+ * @param int The line width
+ * @return string The wrapped text
+ */
+function rcmail_wrap_quoted($text, $max = 76)
+{
+  // Rebuild the message body with a maximum of $max chars, while keeping quoted message.
+  $lines = preg_split('/\r?\n/', trim($text));
+  $out = '';
+
+  foreach ($lines as $line) {
+    if (strlen($line) > $max) {
+      if (preg_match('/^([>\s]+)/', $line, $regs)) {
+        $length = strlen($regs[0]);
+        $prefix = substr($line, 0, $length);
+
+        // Remove '> ' from the line, then wordwrap() the line
+        $line = rc_wordwrap(substr($line, $length), $max - $length);
+
+        // Rebuild the line with '> ' at the beginning of each 'subline'
+        $newline = '';
+        foreach (explode("\n", $line) as $l) {
+          $newline .= $prefix . $l . "\n";
+        }
+
+        // Remove the righest newline char
+        $line = rtrim($newline);
+      }
+      else {
+        $line = rc_wordwrap($line, $max);
+      }
+    }
+
+    // Append the line
+    $out .= $line . "\n";
   }
+  
+  return $out;
+}
 
 
 function rcmail_message_part_controls()
   {
-  global $CONFIG, $IMAP, $MESSAGE;
+  global $MESSAGE;
   
-  if (!is_array($MESSAGE) || !is_array($MESSAGE['parts']) || !($_GET['_uid'] && $_GET['_part']) || !$MESSAGE['parts'][$_GET['_part']])
+  $part = asciiwords(get_input_value('_part', RCUBE_INPUT_GPC));
+  if (!is_object($MESSAGE) || !is_array($MESSAGE->parts) || !($_GET['_uid'] && $_GET['_part']) || !$MESSAGE->mime_parts[$part])
     return '';
     
-  $part = $MESSAGE['parts'][$_GET['_part']];
-  
-  $attrib_str = create_attrib_string($attrib, array('id', 'class', 'style', 'cellspacing', 'cellpadding', 'border', 'summary'));
-  $out = '<table '. $attrib_str . ">\n";
-  
-  $filename = $part->d_parameters['filename'] ? $part->d_parameters['filename'] : $part->ctype_parameters['name'];
-  $filesize = strlen($IMAP->mime_decode($part->body, $part->headers['content-transfer-encoding']));
+  $part = $MESSAGE->mime_parts[$part];
+  $table = new html_table(array('cols' => 3));
   
-  if ($filename)
-    {
-    $out .= sprintf('<tr><td class="title">%s</td><td>%s</td><td>[<a href="./?%s">%s</a>]</tr>'."\n",
-                    rcube_label('filename'),
-                    rep_specialchars_output($filename),
-                    str_replace('_frame=', '_download=', $_SERVER['QUERY_STRING']),
-                    rcube_label('download'));
-    }
-    
-  if ($filesize)
-    $out .= sprintf('<tr><td class="title">%s</td><td>%s</td></tr>'."\n",
-                    rcube_label('filesize'),
-                    show_bytes($filesize));
+  if (!empty($part->filename)) {
+    $table->add('title', Q(rcube_label('filename')));
+    $table->add(null, Q($part->filename));
+    $table->add(null, '[' . html::a('?'.str_replace('_frame=', '_download=', $_SERVER['QUERY_STRING']), Q(rcube_label('download'))) . ']');
+  }
   
-  $out .= "\n</table>";
+  if (!empty($part->size)) {
+    $table->add('title', Q(rcube_label('filesize')));
+    $table->add(null, Q(show_bytes($part->size)));
+  }
   
-  return $out;
+  return $table->show($attrib);
   }
 
 
@@ -1472,57 +1287,231 @@ function rcmail_message_part_frame($attrib)
   {
   global $MESSAGE;
   
-  $part = $MESSAGE['parts'][$_GET['_part']];
+  $part = $MESSAGE->mime_parts[asciiwords(get_input_value('_part', RCUBE_INPUT_GPC))];
   $ctype_primary = strtolower($part->ctype_primary);
 
-  $attrib['src'] = './?'.str_replace('_frame=', ($ctype_primary=='text' ? '_show=' : '_preload='), $_SERVER['QUERY_STRING']);
+  $attrib['src'] = './?' . str_replace('_frame=', ($ctype_primary=='text' ? '_show=' : '_preload='), $_SERVER['QUERY_STRING']);
 
-  $attrib_str = create_attrib_string($attrib, array('id', 'class', 'style', 'src', 'width', 'height'));
-  $out = '<iframe '. $attrib_str . "></ifame>";
-    
-  return $out;
+  return html::iframe($attrib);
   }
 
 
-// create temp dir for attachments
-function rcmail_create_compose_tempdir()
+/**
+ * clear message composing settings
+ */
+function rcmail_compose_cleanup()
   {
-  global $CONFIG;
+  if (!isset($_SESSION['compose']))
+    return;
+
+  rcmail::get_instance()->plugins->exec_hook('cleanup_attachments',array());
   
-  if ($_SESSION['compose']['temp_dir'])
-    return $_SESSION['compose']['temp_dir'];
+  rcube_sess_unset('compose');
+  }
   
-  if (!empty($CONFIG['temp_dir']))
-    $temp_dir = $CONFIG['temp_dir'].(!eregi('\/$', $CONFIG['temp_dir']) ? '/' : '').$_SESSION['compose']['id'];
 
-  // create temp-dir for uploaded attachments
-  if (!empty($CONFIG['temp_dir']) && is_writeable($CONFIG['temp_dir']))
-    {
-    mkdir($temp_dir);
-    $_SESSION['compose']['temp_dir'] = $temp_dir;
-    }
+/**
+ * Send the given message compose object using the configured method
+ */
+function rcmail_deliver_message(&$message, $from, $mailto, &$smtp_error)
+{
+  global $CONFIG, $RCMAIL;
+
+  $msg_body = $message->get();
+  $headers = $message->headers();
 
-  return $_SESSION['compose']['temp_dir'];
+  // send thru SMTP server using custom SMTP library
+  if ($CONFIG['smtp_server']) {
+    // generate list of recipients
+    $a_recipients = array($mailto);
+  
+    if (strlen($headers['Cc']))
+      $a_recipients[] = $headers['Cc'];
+    if (strlen($headers['Bcc']))
+      $a_recipients[] = $headers['Bcc'];
+  
+    // clean Bcc from header for recipients
+    $send_headers = $headers;
+    unset($send_headers['Bcc']);
+    // here too, it because txtHeaders() below use $message->_headers not only $send_headers
+    unset($message->_headers['Bcc']);
+
+    // send message
+    if (!is_object($RCMAIL->smtp))
+      $RCMAIL->smtp_init(true);
+     
+    $sent = $RCMAIL->smtp->send_mail($from, $a_recipients, ($foo = $message->txtHeaders($send_headers, true)), $msg_body);
+    $smtp_response = $RCMAIL->smtp->get_response();
+    $smtp_error = $RCMAIL->smtp->get_error();
+
+    // log error
+    if (!$sent)
+      raise_error(array('code' => 800, 'type' => 'smtp', 'line' => __LINE__, 'file' => __FILE__,
+                        'message' => "SMTP error: ".join("\n", $smtp_response)), TRUE, FALSE);
+  }
+  // send mail using PHP's mail() function
+  else {
+    // unset some headers because they will be added by the mail() function
+    $headers_enc = $message->headers($headers);
+    $headers_php = $message->_headers;
+    unset($headers_php['To'], $headers_php['Subject']);
+    
+    // reset stored headers and overwrite
+    $message->_headers = array();
+    $header_str = $message->txtHeaders($headers_php);
+    
+    // #1485779
+    if (strtoupper(substr(PHP_OS, 0, 3)) === 'WIN') {
+      if (preg_match_all('/<([^@]+@[^>]+)>/', $headers_enc['To'], $m)) {
+        $headers_enc['To'] = implode(', ', $m[1]);
+        }
+      }
+       
+    if (ini_get('safe_mode'))
+      $sent = mail($headers_enc['To'], $headers_enc['Subject'], $msg_body, $header_str);
+    else
+      $sent = mail($headers_enc['To'], $headers_enc['Subject'], $msg_body, $header_str, "-f$from");
+  }
+  
+  if ($sent) {
+    $RCMAIL->plugins->exec_hook('message_sent', array('headers' => $headers, 'body' => $msg_body));
+    
+    // remove MDN headers after sending
+    unset($headers['Return-Receipt-To'], $headers['Disposition-Notification-To']);
+    
+    if ($CONFIG['smtp_log']) {
+      write_log('sendmail', sprintf("User %s [%s]; Message for %s; %s",
+        $RCMAIL->user->get_username(),
+        $_SERVER['REMOTE_ADDR'],
+        $mailto,
+        !empty($smtp_response) ? join('; ', $smtp_response) : ''));
+    }
   }
+  
+  $message->_headers = array();
+  $message->headers($headers);
+  
+  return $sent;
+}
 
 
-// clear message composing settings
-function rcmail_compose_cleanup()
-  {
-  if (!isset($_SESSION['compose']))
-    return;
-  
-  // remove attachment files from temp dir
-  if (is_array($_SESSION['compose']['attachments']))
-    foreach ($_SESSION['compose']['attachments'] as $attachment)
-      @unlink($attachment['path']);
-
-  // kill temp dir
-  if ($_SESSION['compose']['temp_dir'])
-    @rmdir($_SESSION['compose']['temp_dir']);
+function rcmail_send_mdn($uid, &$smtp_error)
+{
+  global $RCMAIL, $IMAP;
+
+  $message = new rcube_message($uid);
   
-  unset($_SESSION['compose']);
+  if ($message->headers->mdn_to && !$message->headers->mdn_sent &&
+    ($IMAP->check_permflag('MDNSENT') || $IMAP->check_permflag('*')))
+  {
+    $identity = $RCMAIL->user->get_identity();
+    $sender = format_email_recipient($identity['email'], $identity['name']);
+    $recipient = array_shift($IMAP->decode_address_list($message->headers->mdn_to));
+    $mailto = $recipient['mailto'];
+
+    $compose = new rcube_mail_mime($RCMAIL->config->header_delimiter());
+    $compose->setParam(array(
+      'text_encoding' => 'quoted-printable',
+      'html_encoding' => 'quoted-printable',
+      'head_encoding' => 'quoted-printable',
+      'head_charset'  => RCMAIL_CHARSET,
+      'html_charset'  => RCMAIL_CHARSET,
+      'text_charset'  => RCMAIL_CHARSET,
+    ));
+    
+    // compose headers array
+    $headers = array(
+      'Date' => date('r'),
+      'From' => $sender,
+      'To'   => $message->headers->mdn_to,
+      'Subject' => rcube_label('receiptread') . ': ' . $message->subject,
+      'Message-ID' => sprintf('<%s@%s>', md5(uniqid('rcmail'.rand(),true)), $RCMAIL->config->mail_domain($_SESSION['imap_host'])),
+      'X-Sender' => $identity['email'],
+      'Content-Type' => 'multipart/report; report-type=disposition-notification',
+    );
+    
+    if ($agent = $RCMAIL->config->get('useragent'))
+      $headers['User-Agent'] = $agent;
+
+    $body = rcube_label("yourmessage") . "\r\n\r\n" .
+      "\t" . rcube_label("to") . ': ' . rcube_imap::decode_mime_string($message->headers->to, $message->headers->charset) . "\r\n" .
+      "\t" . rcube_label("subject") . ': ' . $message->subject . "\r\n" .
+      "\t" . rcube_label("sent") . ': ' . format_date($message->headers->date, $RCMAIL->config->get('date_long')) . "\r\n" .
+      "\r\n" . rcube_label("receiptnote") . "\r\n";
+    
+    $ua = $RCMAIL->config->get('useragent', "RoundCube Webmail (Version ".RCMAIL_VERSION.")");
+    $report = "Reporting-UA: $ua\r\n";
+    
+    if ($message->headers->to)
+        $report .= "Original-Recipient: {$message->headers->to}\r\n";
+    
+    $report .= "Final-Recipient: rfc822; {$identity['email']}\r\n" .
+               "Original-Message-ID: {$message->headers->messageID}\r\n" .
+               "Disposition: manual-action/MDN-sent-manually; displayed\r\n";
+    
+    $compose->headers($headers);
+    $compose->setTXTBody(rc_wordwrap($body, 75, "\r\n"));
+    $compose->addAttachment($report, 'message/disposition-notification', 'MDNPart2.txt', false, '7bit', 'inline');
+
+    $sent = rcmail_deliver_message($compose, $identity['email'], $mailto, $smtp_error);
+
+    if ($sent)
+    {
+      $IMAP->set_flag($message->uid, 'MDNSENT');
+      return true;
+    }
   }
   
+  return false;
+}
+
+
+function rcmail_search_filter($attrib)
+{
+  global $OUTPUT, $CONFIG;
+
+  if (!strlen($attrib['id']))
+    $attrib['id'] = 'rcmlistfilter';
+
+  $attrib['onchange'] = JS_OBJECT_NAME.'.filter_mailbox(this.value)';
   
+  /*
+    RFC3501 (6.4.4): 'ALL', 'RECENT', 
+    'ANSWERED', 'DELETED', 'FLAGGED', 'SEEN',
+    'UNANSWERED', 'UNDELETED', 'UNFLAGGED', 'UNSEEN',
+    'NEW', // = (RECENT UNSEEN)
+    'OLD' // = NOT RECENT
+  */
+
+  $select_filter = new html_select($attrib);
+  $select_filter->add(rcube_label('all'), 'ALL');
+  $select_filter->add(rcube_label('unread'), 'UNSEEN');
+  $select_filter->add(rcube_label('flagged'), 'FLAGGED');
+  $select_filter->add(rcube_label('unanswered'), 'UNANSWERED');
+  if (!$CONFIG['skip_deleted'])
+    $select_filter->add(rcube_label('deleted'), 'DELETED');
+
+  $out = $select_filter->show($_SESSION['search_filter']);
+
+  $OUTPUT->add_gui_object('search_filter', $attrib['id']);
+
+  return $out;                                                                         
+}
+
+// register UI objects
+$OUTPUT->add_handlers(array(
+  'mailboxlist' => 'rcmail_mailbox_list',
+  'messages' => 'rcmail_message_list',
+  'messagecountdisplay' => 'rcmail_messagecount_display',
+  'quotadisplay' => 'rcmail_quota_display',
+  'mailboxname' => 'rcmail_mailbox_name_display',
+  'messageheaders' => 'rcmail_message_headers',
+  'messagebody' => 'rcmail_message_body',
+  'messagecontentframe' => 'rcmail_messagecontent_frame',
+  'messagepartframe' => 'rcmail_message_part_frame',
+  'messagepartcontrols' => 'rcmail_message_part_controls',
+  'searchfilter' => 'rcmail_search_filter',
+  'searchform' => array($OUTPUT, 'search_form'),
+));
+
 ?>