diff options
| author | Connor Thomson <blumatrikz@gmail.com> | 2026-09-20 21:23:09 -0700 |
|---|---|---|
| committer | Connor Thomson <blumatrikz@gmail.com> | 2026-09-20 21:23:09 -0700 |
| commit | 070a27baa8f93c3bf191459b88d24d7430a78899 (patch) | |
| tree | 8c96b12d16e1d219ef410ad0e45b2d886368bc5e | |
| parent | 83cd353b01660f34d6fd894d15a27fb1b3aeab4c (diff) | |
Some fixes and updates
| -rwxr-xr-x | admin/admin.php | 89 | ||||
| -rwxr-xr-x | admin/change-password/change-password.php | 60 | ||||
| -rwxr-xr-x | admin/change-password/index.php | 28 | ||||
| -rwxr-xr-x | admin/change-status/change-status.php | 68 | ||||
| -rwxr-xr-x | admin/change-status/index.php | 28 | ||||
| -rwxr-xr-x | admin/index.php | 8 | ||||
| -rwxr-xr-x | admin/remove-user/index.php | 28 | ||||
| -rwxr-xr-x | admin/remove-user/remove-user.php | 63 | ||||
| -rwxr-xr-x | html/account.html | 1 | ||||
| -rwxr-xr-x | html/admin-link.html | 19 | ||||
| -rwxr-xr-x | html/admin.html | 52 | ||||
| -rwxr-xr-x | html/change-password.html | 35 | ||||
| -rwxr-xr-x | html/change-status.html | 36 | ||||
| -rwxr-xr-x | html/remove-user.html | 27 | ||||
| -rwxr-xr-x | php/header.php | 6 | ||||
| -rwxr-xr-x | php/replace.php | 6 | ||||
| -rw-r--r-- | php/user.php | 12 |
17 files changed, 420 insertions, 146 deletions
diff --git a/admin/admin.php b/admin/admin.php deleted file mode 100755 index eb85ccb..0000000 --- a/admin/admin.php +++ /dev/null @@ -1,89 +0,0 @@ -<?php -/* - * GNUfault.org - GNUfault's website - * Copyright (C) 2026 Connor Thomson - * - * This program is free software: you can redistribute it and/or modify - * it under the terms of the GNU Affero General Public License as published by - * the Free Software Foundation, either version 3 of the License, or - * (at your option) any later version. - * - * This program is distributed in the hope that it will be useful, - * but WITHOUT ANY WARRANTY; without even the implied warranty of - * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the - * GNU Affero General Public License for more details. - * - * You should have received a copy of the GNU Affero General Public License - * along with this program. If not, see <https://www.gnu.org/licenses/>. - */ - -define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/'); - -require_once ROOT . '/php/user.php'; - -if (!is_admin()) { - http_response_code(403); - - echo "Forbidden"; - exit; -} - -if ($_SERVER["REQUEST_METHOD"] != "POST") { - header("Location: /admin/"); - exit; -} - -$action = isset($_POST['action']) ? $_POST['action'] : ''; -$username = isset($_POST['username']) ? $_POST['username'] : ''; - -try { - if (!find_user($username)) { - echo "User not found."; - exit; - } - - if ($action == 'password') { - $password = $_POST['password']; - $confirmpassword = $_POST['confirmpassword']; - - if ($confirmpassword != $password) { - echo "Passwords do not match!"; - exit; - } - - $sql = "UPDATE users SET password = :password WHERE username = :username"; - - query($sql, [ - 'password' => password_hash($password, PASSWORD_DEFAULT), - 'username' => $username - ]); - } elseif ($action == 'status') { - $status = isset($_POST['status']) ? $_POST['status'] : ''; - - if (!in_array($status, USER_STATUSES, true)) { - echo "That is not a status!"; - exit; - } - - $sql = "UPDATE users SET status = :status WHERE username = :username"; - - query($sql, [ - 'status' => $status, - 'username' => $username - ]); - } elseif ($action == 'remove') { - $sql = "DELETE FROM users WHERE username = :username"; - - query($sql, ['username' => $username]); - } else { - echo "That is not something I can do."; - exit; - } -} catch (\PDOException $e) { - echo "Error: " . $e->getMessage(); - exit; -} - -header("Location: /admin/"); - -?> diff --git a/admin/change-password/change-password.php b/admin/change-password/change-password.php new file mode 100755 index 0000000..a5c98be --- /dev/null +++ b/admin/change-password/change-password.php @@ -0,0 +1,60 @@ +<?php +/* + * GNUfault.org - GNUfault's website + * Copyright (C) 2026 Connor Thomson + * + * This program is free software: you can redistribute it and/or modify + * it under the terms of the GNU Affero General Public License as published by + * the Free Software Foundation, either version 3 of the License, or + * (at your option) any later version. + * + * This program is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU Affero General Public License for more details. + * + * You should have received a copy of the GNU Affero General Public License + * along with this program. If not, see <https://www.gnu.org/licenses/>. + */ + +define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/'); + +require_once ROOT . '/php/user.php'; + +require_admin(); + +if ($_SERVER["REQUEST_METHOD"] != "POST") { + header("Location: /admin/change-password/"); + exit; +} + +$username = isset($_POST['username']) ? $_POST['username'] : ''; + +$password = isset($_POST['password']) ? $_POST['password'] : ''; +$confirmpassword = isset($_POST['confirmpassword']) ? $_POST['confirmpassword'] : ''; + +if ($confirmpassword != $password) { + echo "Passwords do not match!"; + exit; +} + +try { + if (!find_user($username)) { + echo "User not found."; + exit; + } + + $sql = "UPDATE users SET password = :password WHERE username = :username"; + + query($sql, [ + 'password' => password_hash($password, PASSWORD_DEFAULT), + 'username' => $username + ]); +} catch (\PDOException $e) { + echo "Error: " . $e->getMessage(); + exit; +} + +header("Location: /admin/"); + +?> diff --git a/admin/change-password/index.php b/admin/change-password/index.php new file mode 100755 index 0000000..fedab8a --- /dev/null +++ b/admin/change-password/index.php @@ -0,0 +1,28 @@ +<?php +/* + * GNUfault.org - GNUfault's website + * Copyright (C) 2026 Connor Thomson + * + * This program is free software: you can redistribute it and/or modify + * it under the terms of the GNU Affero General Public License as published by + * the Free Software Foundation, either version 3 of the License, or + * (at your option) any later version. + * + * This program is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU Affero General Public License for more details. + * + * You should have received a copy of the GNU Affero General Public License + * along with this program. If not, see <https://www.gnu.org/licenses/>. + */ + +define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/'); + +require_once ROOT . '/php/user.php'; + +require_admin(); + +render_content(ROOT . '/html/change-password.html'); + +?> diff --git a/admin/change-status/change-status.php b/admin/change-status/change-status.php new file mode 100755 index 0000000..cbf7f6e --- /dev/null +++ b/admin/change-status/change-status.php @@ -0,0 +1,68 @@ +<?php +/* + * GNUfault.org - GNUfault's website + * Copyright (C) 2026 Connor Thomson + * + * This program is free software: you can redistribute it and/or modify + * it under the terms of the GNU Affero General Public License as published by + * the Free Software Foundation, either version 3 of the License, or + * (at your option) any later version. + * + * This program is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU Affero General Public License for more details. + * + * You should have received a copy of the GNU Affero General Public License + * along with this program. If not, see <https://www.gnu.org/licenses/>. + */ + +define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/'); + +require_once ROOT . '/php/user.php'; + +require_admin(); + +if ($_SERVER["REQUEST_METHOD"] != "POST") { + header("Location: /admin/change-status/"); + exit; +} + +$username = isset($_POST['username']) ? $_POST['username'] : ''; + +$status = isset($_POST['status']) ? $_POST['status'] : ''; + +if (!in_array($status, USER_STATUSES, true)) { + echo "That is not a status!"; + exit; +} + +try { + $user = find_user($username); + + if (!$user) { + echo "User not found."; + exit; + } + + $me = current_user(); + + if ($me !== null && (int)$user['id'] === (int)$me['id']) { + echo "You cannot change your own status!"; + exit; + } + + $sql = "UPDATE users SET status = :status WHERE username = :username"; + + query($sql, [ + 'status' => $status, + 'username' => $username + ]); +} catch (\PDOException $e) { + echo "Error: " . $e->getMessage(); + exit; +} + +header("Location: /admin/"); + +?> diff --git a/admin/change-status/index.php b/admin/change-status/index.php new file mode 100755 index 0000000..4eddee3 --- /dev/null +++ b/admin/change-status/index.php @@ -0,0 +1,28 @@ +<?php +/* + * GNUfault.org - GNUfault's website + * Copyright (C) 2026 Connor Thomson + * + * This program is free software: you can redistribute it and/or modify + * it under the terms of the GNU Affero General Public License as published by + * the Free Software Foundation, either version 3 of the License, or + * (at your option) any later version. + * + * This program is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU Affero General Public License for more details. + * + * You should have received a copy of the GNU Affero General Public License + * along with this program. If not, see <https://www.gnu.org/licenses/>. + */ + +define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/'); + +require_once ROOT . '/php/user.php'; + +require_admin(); + +render_content(ROOT . '/html/change-status.html'); + +?> diff --git a/admin/index.php b/admin/index.php index 29c8873..13f1659 100755 --- a/admin/index.php +++ b/admin/index.php @@ -19,15 +19,9 @@ define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/'); -require_once ROOT . '/php/render.php'; require_once ROOT . '/php/user.php'; -if (!is_admin()) { - http_response_code(403); - - render_content(ROOT . '/html/forbidden.html'); - exit; -} +require_admin(); render_content(ROOT . '/html/admin.html'); diff --git a/admin/remove-user/index.php b/admin/remove-user/index.php new file mode 100755 index 0000000..cd186a5 --- /dev/null +++ b/admin/remove-user/index.php @@ -0,0 +1,28 @@ +<?php +/* + * GNUfault.org - GNUfault's website + * Copyright (C) 2026 Connor Thomson + * + * This program is free software: you can redistribute it and/or modify + * it under the terms of the GNU Affero General Public License as published by + * the Free Software Foundation, either version 3 of the License, or + * (at your option) any later version. + * + * This program is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU Affero General Public License for more details. + * + * You should have received a copy of the GNU Affero General Public License + * along with this program. If not, see <https://www.gnu.org/licenses/>. + */ + +define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/'); + +require_once ROOT . '/php/user.php'; + +require_admin(); + +render_content(ROOT . '/html/remove-user.html'); + +?> diff --git a/admin/remove-user/remove-user.php b/admin/remove-user/remove-user.php new file mode 100755 index 0000000..81849c2 --- /dev/null +++ b/admin/remove-user/remove-user.php @@ -0,0 +1,63 @@ +<?php +/* + * GNUfault.org - GNUfault's website + * Copyright (C) 2026 Connor Thomson + * + * This program is free software: you can redistribute it and/or modify + * it under the terms of the GNU Affero General Public License as published by + * the Free Software Foundation, either version 3 of the License, or + * (at your option) any later version. + * + * This program is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU Affero General Public License for more details. + * + * You should have received a copy of the GNU Affero General Public License + * along with this program. If not, see <https://www.gnu.org/licenses/>. + */ + +define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/'); + +require_once ROOT . '/php/user.php'; + +require_admin(); + +if ($_SERVER["REQUEST_METHOD"] != "POST") { + header("Location: /admin/remove-user/"); + exit; +} + +$username = isset($_POST['username']) ? $_POST['username'] : ''; + +try { + $user = find_user($username); + + if (!$user) { + echo "User not found."; + exit; + } + + $me = current_user(); + + if ($me !== null && (int)$user['id'] === (int)$me['id']) { + echo "You cannot remove yourself!"; + exit; + } + + if ($user['status'] === 'admin') { + echo "You cannot remove an admin, lower their status first!"; + exit; + } + + $sql = "DELETE FROM users WHERE username = :username"; + + query($sql, ['username' => $username]); +} catch (\PDOException $e) { + echo "Error: " . $e->getMessage(); + exit; +} + +header("Location: /admin/"); + +?> diff --git a/html/account.html b/html/account.html index 4c5b97d..7d3d1c8 100755 --- a/html/account.html +++ b/html/account.html @@ -21,6 +21,7 @@ <label class="username" for="account">{{username}}</label> <div class="menu"> <a href="/profile/?username={{profile}}">Profile</a> + {{admin}} <a href="/signout/">Sign-out</a> </div> </div> diff --git a/html/admin-link.html b/html/admin-link.html new file mode 100755 index 0000000..b91dcf2 --- /dev/null +++ b/html/admin-link.html @@ -0,0 +1,19 @@ +<!-- + GNUfault.org - GNUfault's website + Copyright (C) 2026 Connor Thomson + + This program is free software: you can redistribute it and/or modify + it under the terms of the GNU Affero General Public License as published by + the Free Software Foundation, either version 3 of the License, or + (at your option) any later version. + + This program is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + GNU Affero General Public License for more details. + + You should have received a copy of the GNU Affero General Public License + along with this program. If not, see <https://www.gnu.org/licenses/>. +--> + +<a href="/admin/">Admin</a> diff --git a/html/admin.html b/html/admin.html index 8ae34e2..078c23f 100755 --- a/html/admin.html +++ b/html/admin.html @@ -18,52 +18,6 @@ <h2>Admin Panel</h2> <hr> - -<h3>Change user's password</h3> -<form class="login" action="admin.php" method="POST"> - <input type="hidden" name="action" value="password"> - <div class="group"> - <label for="password-username">Username:</label> - <input class="input" type="text" id="password-username" name="username" required> - </div> - <div class="group"> - <label for="password">New password:</label> - <input class="input" type="password" id="password" name="password" required> - </div> - <div class="group"> - <label for="confirmpassword">Confirm new password:</label> - <input class="input" type="password" id="confirmpassword" name="confirmpassword" required> - </div> - <button class="button" type="submit">Send</button> -</form> -<br> - -<h3>Change user's status</h3> -<form class="login" action="admin.php" method="POST"> - <input type="hidden" name="action" value="status"> - <div class="group"> - <label for="status-username">Username:</label> - <input class="input" type="text" id="status-username" name="username" required> - </div> - <div class="group"> - <label for="status">Status:</label> - <select class="input" id="status" name="status"> - <option value="none">none</option> - <option value="member">member</option> - <option value="mod">mod</option> - <option value="admin">admin</option> - </select> - </div> - <button class="button" type="submit">Send</button> -</form> -<br> - -<h3>Remove user</h3> -<form class="login" action="admin.php" method="POST"> - <input type="hidden" name="action" value="remove"> - <div class="group"> - <label for="remove-username">Username:</label> - <input class="input" type="text" id="remove-username" name="username" required> - </div> - <button class="button" type="submit">Send</button> -</form> +<a href="/admin/change-password/">Change user's password</a><br> +<a href="/admin/change-status/">Change user's status</a><br> +<a href="/admin/remove-user/">Remove user</a> diff --git a/html/change-password.html b/html/change-password.html new file mode 100755 index 0000000..fd98dce --- /dev/null +++ b/html/change-password.html @@ -0,0 +1,35 @@ +<!-- + GNUfault.org - GNUfault's website + Copyright (C) 2026 Connor Thomson + + This program is free software: you can redistribute it and/or modify + it under the terms of the GNU Affero General Public License as published by + the Free Software Foundation, either version 3 of the License, or + (at your option) any later version. + + This program is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + GNU Affero General Public License for more details. + + You should have received a copy of the GNU Affero General Public License + along with this program. If not, see <https://www.gnu.org/licenses/>. +--> + +<h2>Change user's password</h2> +<hr> +<form class="login" action="change-password.php" method="POST"> + <div class="group"> + <label for="username">Username:</label> + <input class="input" type="text" id="username" name="username" required> + </div> + <div class="group"> + <label for="password">New password:</label> + <input class="input" type="password" id="password" name="password" required> + </div> + <div class="group"> + <label for="confirmpassword">Confirm new password:</label> + <input class="input" type="password" id="confirmpassword" name="confirmpassword" required> + </div> + <button class="button" type="submit">Send</button> +</form> diff --git a/html/change-status.html b/html/change-status.html new file mode 100755 index 0000000..4b6e8b2 --- /dev/null +++ b/html/change-status.html @@ -0,0 +1,36 @@ +<!-- + GNUfault.org - GNUfault's website + Copyright (C) 2026 Connor Thomson + + This program is free software: you can redistribute it and/or modify + it under the terms of the GNU Affero General Public License as published by + the Free Software Foundation, either version 3 of the License, or + (at your option) any later version. + + This program is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + GNU Affero General Public License for more details. + + You should have received a copy of the GNU Affero General Public License + along with this program. If not, see <https://www.gnu.org/licenses/>. +--> + +<h2>Change user's status</h2> +<hr> +<form class="login" action="change-status.php" method="POST"> + <div class="group"> + <label for="username">Username:</label> + <input class="input" type="text" id="username" name="username" required> + </div> + <div class="group"> + <label for="status">Status:</label> + <select class="input" id="status" name="status"> + <option value="none">none</option> + <option value="member">member</option> + <option value="mod">mod</option> + <option value="admin">admin</option> + </select> + </div> + <button class="button" type="submit">Send</button> +</form> diff --git a/html/remove-user.html b/html/remove-user.html new file mode 100755 index 0000000..ee2c2eb --- /dev/null +++ b/html/remove-user.html @@ -0,0 +1,27 @@ +<!-- + GNUfault.org - GNUfault's website + Copyright (C) 2026 Connor Thomson + + This program is free software: you can redistribute it and/or modify + it under the terms of the GNU Affero General Public License as published by + the Free Software Foundation, either version 3 of the License, or + (at your option) any later version. + + This program is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + GNU Affero General Public License for more details. + + You should have received a copy of the GNU Affero General Public License + along with this program. If not, see <https://www.gnu.org/licenses/>. +--> + +<h2>Remove user</h2> +<hr> +<form class="login" action="remove-user.php" method="POST"> + <div class="group"> + <label for="username">Username:</label> + <input class="input" type="text" id="username" name="username" required> + </div> + <button class="button" type="submit">Send</button> +</form> diff --git a/php/header.php b/php/header.php index 0fd46df..18a043a 100755 --- a/php/header.php +++ b/php/header.php @@ -19,15 +19,19 @@ require_once ROOT . '/php/replace.php'; require_once ROOT . '/php/session.php'; +require_once ROOT . '/php/user.php'; $username = get_username(); if ($username === null) { $account = import(ROOT . '/html/guest.html'); } else { + $admin = is_admin() ? import(ROOT . '/html/admin-link.html') : ''; + $account = replace(ROOT . '/html/account.html', [ '{{username}}' => htmlspecialchars($username, ENT_QUOTES, 'UTF-8'), - '{{profile}}' => rawurlencode($username) + '{{profile}}' => rawurlencode($username), + '{{admin}}' => $admin ]); } diff --git a/php/replace.php b/php/replace.php index dcc5fb6..0823370 100755 --- a/php/replace.php +++ b/php/replace.php @@ -25,6 +25,12 @@ function replace(string $templatePath, array $replacements = []): string { foreach ($replacements as $placeholder => $replacementValue) { $replacementValue = tidy((string)$replacementValue); + if ($replacementValue === '') { + $pattern = '/^[ \t]*' . preg_quote($placeholder, '/') . '[ \t]*\n?/m'; + + $html = preg_replace($pattern, '', $html); + } + $pattern = '/^([ \t]*)' . preg_quote($placeholder, '/') . '/m'; $html = preg_replace_callback($pattern, function (array $match) use ($replacementValue) { diff --git a/php/user.php b/php/user.php index 8a424e5..9521dc5 100644 --- a/php/user.php +++ b/php/user.php @@ -19,6 +19,7 @@ require_once ROOT . '/php/session.php'; require_once ROOT . '/php/database.php'; +require_once ROOT . '/php/render.php'; const USER_STATUSES = ['none', 'member', 'mod', 'admin']; @@ -46,4 +47,15 @@ function is_admin(): bool { return $user !== null && $user['status'] === 'admin'; } +function require_admin(): void { + if (is_admin()) { + return; + } + + http_response_code(403); + + render_content(ROOT . '/html/forbidden.html'); + exit; +} + ?> |
