admin.php 6.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244
  1. <?php
  2. require_once ('./header.php');
  3. logged_in_only ();
  4. $delete = set_post_string_var ('delete');
  5. $create = set_post_string_var ('create');
  6. $new_username = set_post_string_var ('new_username');
  7. $new_password = set_post_string_var('new_password');
  8. $new_admin = set_post_bool_var ('new_admin', false);
  9. $existing_user = set_post_string_var ('existing_user');
  10. $noconfirm = set_get_noconfirm ();
  11. $message1 = '';
  12. $message2 = '';
  13. ?>
  14. <h1 id="caption">Admin Page</h1>
  15. <!-- Wrapper starts here. -->
  16. <div style="min-width: <?php echo 230 + $settings['column_width_folder']; ?>px;">
  17. <!-- Menu starts here. -->
  18. <div id="menu">
  19. <h2 class="nav">Bookmarks</h2>
  20. <ul class="nav">
  21. <li><a href="./index.php">My Bookmarks</a></li>
  22. <li><a href="./shared.php">Shared Bookmarks</a></li>
  23. </ul>
  24. <h2 class="nav">Tools</h2>
  25. <ul class="nav">
  26. <?php if (admin_only ()) { ?>
  27. <li><a href="./admin.php">Admin</a></li>
  28. <?php } ?>
  29. <li><a href="./import.php">Import</a></li>
  30. <li><a href="./export.php">Export</a></li>
  31. <li><a href="./sidebar.php">View as Sidebar</a></li>
  32. <li><a href="./settings.php">Settings</a></li>
  33. <li><a href="./index.php?logout=1">Logout</a></li>
  34. </ul>
  35. <!-- Menu ends here. -->
  36. </div>
  37. <!-- Main content starts here. -->
  38. <div id="main">
  39. <?php
  40. if (!admin_only ()) {
  41. message ("You are not an Admin.");
  42. }
  43. if ($create == 'Create') {
  44. if ($new_username == '' || $new_password == '') {
  45. $message1 = 'Username and Password fields must not be empty.';
  46. }
  47. else if (check_username ($new_username)) {
  48. $message1 = 'User already exists.';
  49. }
  50. else {
  51. $query = sprintf ("INSERT INTO user (username, password, admin) VALUES ('%s', md5('%s'), '%d')",
  52. $mysql->escape ($new_username),
  53. $mysql->escape ($new_password),
  54. $mysql->escape ($new_admin));
  55. if ($mysql->query ($query)) {
  56. $message1 = "User $new_username created.";
  57. }
  58. else {
  59. message ($mysql->error);
  60. }
  61. unset ($new_password, $_POST['new_password']);
  62. }
  63. }
  64. ?>
  65. <div style="border: 1px solid #bbb; margin: 10px; padding: 10px;">
  66. <h2 class="caption">Create User</h2>
  67. <form action="<?php echo $_SERVER['SCRIPT_NAME']; ?>" method="POST">
  68. <table>
  69. <tr>
  70. <td>Username:
  71. </td>
  72. <td>
  73. <input type="text" name="new_username">
  74. </td>
  75. </tr>
  76. <tr>
  77. <td>Password:
  78. </td>
  79. <td>
  80. <input type="password" name="new_password">
  81. </td>
  82. </tr>
  83. <tr>
  84. <td>Admin:
  85. </td>
  86. <td>
  87. <input type="checkbox" name="new_admin" value="1">
  88. </td>
  89. </tr>
  90. <tr>
  91. <td>
  92. </td>
  93. <td>
  94. <input type="submit" name="create" value="Create"> <?php echo $message1; ?>
  95. </td>
  96. </tr>
  97. </table>
  98. </form>
  99. </div>
  100. <div style="border: 1px solid #bbb; margin: 10px; padding: 10px;">
  101. <h2 class="caption">Delete User</h2>
  102. <?php
  103. if ($delete == 'Delete') {
  104. if (check_username ($existing_user)) {
  105. if ($noconfirm) {
  106. $query = sprintf ("DELETE FROM user WHERE md5(username)=md5('%s')",
  107. $mysql->escape ($existing_user));
  108. if ($mysql->query ($query)) {
  109. $message2 = "User $existing_user deleted.<br>";
  110. }
  111. else {
  112. message ($mysql->error);
  113. }
  114. $query = sprintf ("DELETE FROM bookmark WHERE md5(user)=md5('%s')",
  115. $mysql->escape ($existing_user));
  116. if (!$mysql->query ($query)) {
  117. message ($mysql->error);
  118. }
  119. $query = sprintf ("DELETE FROM folder WHERE md5(user)=md5('%s')",
  120. $mysql->escape ($existing_user));
  121. if (!$mysql->query ($query)) {
  122. message ($mysql->error);
  123. }
  124. list_users ();
  125. }
  126. else {
  127. ?>
  128. <p>Are you sure you want to delete the user <?php echo $existing_user; ?> and all it's Bookmarks and Folders?</p>
  129. <form action="<?php echo $_SERVER['SCRIPT_NAME'] . "?noconfirm=1"; ?>" method="POST" name="userdelete">
  130. <input type="hidden" name="existing_user" value="<?php echo $existing_user; ?>">
  131. <input type="submit" name="delete" value="Delete">
  132. <input type="button" value=" Cancel " onClick="self.location.href='./admin.php'">
  133. </form>
  134. <?php
  135. }
  136. }
  137. else {
  138. $message2 = 'User does not exist.';
  139. list_users ();
  140. }
  141. }
  142. else {
  143. list_users ();
  144. }
  145. function list_users () {
  146. global $mysql, $message2;;
  147. ?>
  148. <form action="<?php echo $_SERVER['SCRIPT_NAME']; ?>" method="POST">
  149. <div style="height: 200px; width: 300px; overflow:auto;">
  150. <?php
  151. $query = "SELECT username, admin FROM user ORDER BY username";
  152. if ($mysql->query ($query)) {
  153. while ($row = mysqli_fetch_object ($mysql->result)) {
  154. echo '<input type="radio" name="existing_user" value="'.$row->username.'">';
  155. if ($row->admin) {
  156. echo " <b>" . $row->username . "</b><br>\n";
  157. }
  158. else {
  159. echo " " . $row->username . "<br>\n";
  160. }
  161. }
  162. }
  163. else {
  164. message ($mysql->error);
  165. }
  166. ?>
  167. </div>
  168. <input type="submit" name="delete" value="Delete">
  169. <?php echo $message2; ?>
  170. </form>
  171. <?php
  172. }
  173. ?>
  174. </div>
  175. <div style="border: 1px solid #bbb; margin: 10px; padding: 10px;">
  176. <h2 class="caption">Version</h2>
  177. <table>
  178. <tr>
  179. <td>This Version:</td>
  180. <td><?php @readfile (ABSOLUTE_PATH . "VERSION"); ?></td>
  181. </tr>
  182. <tr>
  183. <td><a href="http://www.frech.ch/online-bookmarks/" target="_new">Newest Version available:</a></td>
  184. <td><a href="http://www.frech.ch/online-bookmarks/" target="_new"><?php echo check_version (); ?></a></td>
  185. </tr>
  186. </table>
  187. <?php
  188. function check_version () {
  189. $version = null;
  190. if ($fp = @fsockopen ("www.frech.ch", 80)) {
  191. $get = "GET /online-bookmarks/bookmarks/VERSION HTTP/1.0\r\n\r\n";
  192. $data = null;
  193. fwrite ($fp, $get);
  194. while (!feof ($fp)) {
  195. $data .= fgets ($fp, 128);
  196. }
  197. fclose ($fp);
  198. $pos = strpos($data, "\r\n\r\n") + 4;
  199. $version = substr ($data, $pos, strlen ($data));
  200. }
  201. return $version;
  202. }
  203. ?>
  204. </div>
  205. </div>
  206. <?php
  207. print_footer ();
  208. require_once (ABSOLUTE_PATH . 'footer.php');
  209. ?>