summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rwxr-xr-xadmin/admin.php89
-rwxr-xr-xadmin/change-password/change-password.php60
-rwxr-xr-xadmin/change-password/index.php28
-rwxr-xr-xadmin/change-status/change-status.php68
-rwxr-xr-xadmin/change-status/index.php28
-rwxr-xr-xadmin/index.php8
-rwxr-xr-xadmin/remove-user/index.php28
-rwxr-xr-xadmin/remove-user/remove-user.php63
-rwxr-xr-xhtml/account.html1
-rwxr-xr-xhtml/admin-link.html19
-rwxr-xr-xhtml/admin.html52
-rwxr-xr-xhtml/change-password.html35
-rwxr-xr-xhtml/change-status.html36
-rwxr-xr-xhtml/remove-user.html27
-rwxr-xr-xphp/header.php6
-rwxr-xr-xphp/replace.php6
-rw-r--r--php/user.php12
17 files changed, 420 insertions, 146 deletions
diff --git a/admin/admin.php b/admin/admin.php
deleted file mode 100755
index eb85ccb..0000000
--- a/admin/admin.php
+++ /dev/null
@@ -1,89 +0,0 @@
-<?php
-/*
- * GNUfault.org - GNUfault's website
- * Copyright (C) 2026 Connor Thomson
- *
- * This program is free software: you can redistribute it and/or modify
- * it under the terms of the GNU Affero General Public License as published by
- * the Free Software Foundation, either version 3 of the License, or
- * (at your option) any later version.
- *
- * This program is distributed in the hope that it will be useful,
- * but WITHOUT ANY WARRANTY; without even the implied warranty of
- * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
- * GNU Affero General Public License for more details.
- *
- * You should have received a copy of the GNU Affero General Public License
- * along with this program. If not, see <https://www.gnu.org/licenses/>.
- */
-
-define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/');
-
-require_once ROOT . '/php/user.php';
-
-if (!is_admin()) {
- http_response_code(403);
-
- echo "Forbidden";
- exit;
-}
-
-if ($_SERVER["REQUEST_METHOD"] != "POST") {
- header("Location: /admin/");
- exit;
-}
-
-$action = isset($_POST['action']) ? $_POST['action'] : '';
-$username = isset($_POST['username']) ? $_POST['username'] : '';
-
-try {
- if (!find_user($username)) {
- echo "User not found.";
- exit;
- }
-
- if ($action == 'password') {
- $password = $_POST['password'];
- $confirmpassword = $_POST['confirmpassword'];
-
- if ($confirmpassword != $password) {
- echo "Passwords do not match!";
- exit;
- }
-
- $sql = "UPDATE users SET password = :password WHERE username = :username";
-
- query($sql, [
- 'password' => password_hash($password, PASSWORD_DEFAULT),
- 'username' => $username
- ]);
- } elseif ($action == 'status') {
- $status = isset($_POST['status']) ? $_POST['status'] : '';
-
- if (!in_array($status, USER_STATUSES, true)) {
- echo "That is not a status!";
- exit;
- }
-
- $sql = "UPDATE users SET status = :status WHERE username = :username";
-
- query($sql, [
- 'status' => $status,
- 'username' => $username
- ]);
- } elseif ($action == 'remove') {
- $sql = "DELETE FROM users WHERE username = :username";
-
- query($sql, ['username' => $username]);
- } else {
- echo "That is not something I can do.";
- exit;
- }
-} catch (\PDOException $e) {
- echo "Error: " . $e->getMessage();
- exit;
-}
-
-header("Location: /admin/");
-
-?>
diff --git a/admin/change-password/change-password.php b/admin/change-password/change-password.php
new file mode 100755
index 0000000..a5c98be
--- /dev/null
+++ b/admin/change-password/change-password.php
@@ -0,0 +1,60 @@
+<?php
+/*
+ * GNUfault.org - GNUfault's website
+ * Copyright (C) 2026 Connor Thomson
+ *
+ * This program is free software: you can redistribute it and/or modify
+ * it under the terms of the GNU Affero General Public License as published by
+ * the Free Software Foundation, either version 3 of the License, or
+ * (at your option) any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * GNU Affero General Public License for more details.
+ *
+ * You should have received a copy of the GNU Affero General Public License
+ * along with this program. If not, see <https://www.gnu.org/licenses/>.
+ */
+
+define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/');
+
+require_once ROOT . '/php/user.php';
+
+require_admin();
+
+if ($_SERVER["REQUEST_METHOD"] != "POST") {
+ header("Location: /admin/change-password/");
+ exit;
+}
+
+$username = isset($_POST['username']) ? $_POST['username'] : '';
+
+$password = isset($_POST['password']) ? $_POST['password'] : '';
+$confirmpassword = isset($_POST['confirmpassword']) ? $_POST['confirmpassword'] : '';
+
+if ($confirmpassword != $password) {
+ echo "Passwords do not match!";
+ exit;
+}
+
+try {
+ if (!find_user($username)) {
+ echo "User not found.";
+ exit;
+ }
+
+ $sql = "UPDATE users SET password = :password WHERE username = :username";
+
+ query($sql, [
+ 'password' => password_hash($password, PASSWORD_DEFAULT),
+ 'username' => $username
+ ]);
+} catch (\PDOException $e) {
+ echo "Error: " . $e->getMessage();
+ exit;
+}
+
+header("Location: /admin/");
+
+?>
diff --git a/admin/change-password/index.php b/admin/change-password/index.php
new file mode 100755
index 0000000..fedab8a
--- /dev/null
+++ b/admin/change-password/index.php
@@ -0,0 +1,28 @@
+<?php
+/*
+ * GNUfault.org - GNUfault's website
+ * Copyright (C) 2026 Connor Thomson
+ *
+ * This program is free software: you can redistribute it and/or modify
+ * it under the terms of the GNU Affero General Public License as published by
+ * the Free Software Foundation, either version 3 of the License, or
+ * (at your option) any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * GNU Affero General Public License for more details.
+ *
+ * You should have received a copy of the GNU Affero General Public License
+ * along with this program. If not, see <https://www.gnu.org/licenses/>.
+ */
+
+define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/');
+
+require_once ROOT . '/php/user.php';
+
+require_admin();
+
+render_content(ROOT . '/html/change-password.html');
+
+?>
diff --git a/admin/change-status/change-status.php b/admin/change-status/change-status.php
new file mode 100755
index 0000000..cbf7f6e
--- /dev/null
+++ b/admin/change-status/change-status.php
@@ -0,0 +1,68 @@
+<?php
+/*
+ * GNUfault.org - GNUfault's website
+ * Copyright (C) 2026 Connor Thomson
+ *
+ * This program is free software: you can redistribute it and/or modify
+ * it under the terms of the GNU Affero General Public License as published by
+ * the Free Software Foundation, either version 3 of the License, or
+ * (at your option) any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * GNU Affero General Public License for more details.
+ *
+ * You should have received a copy of the GNU Affero General Public License
+ * along with this program. If not, see <https://www.gnu.org/licenses/>.
+ */
+
+define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/');
+
+require_once ROOT . '/php/user.php';
+
+require_admin();
+
+if ($_SERVER["REQUEST_METHOD"] != "POST") {
+ header("Location: /admin/change-status/");
+ exit;
+}
+
+$username = isset($_POST['username']) ? $_POST['username'] : '';
+
+$status = isset($_POST['status']) ? $_POST['status'] : '';
+
+if (!in_array($status, USER_STATUSES, true)) {
+ echo "That is not a status!";
+ exit;
+}
+
+try {
+ $user = find_user($username);
+
+ if (!$user) {
+ echo "User not found.";
+ exit;
+ }
+
+ $me = current_user();
+
+ if ($me !== null && (int)$user['id'] === (int)$me['id']) {
+ echo "You cannot change your own status!";
+ exit;
+ }
+
+ $sql = "UPDATE users SET status = :status WHERE username = :username";
+
+ query($sql, [
+ 'status' => $status,
+ 'username' => $username
+ ]);
+} catch (\PDOException $e) {
+ echo "Error: " . $e->getMessage();
+ exit;
+}
+
+header("Location: /admin/");
+
+?>
diff --git a/admin/change-status/index.php b/admin/change-status/index.php
new file mode 100755
index 0000000..4eddee3
--- /dev/null
+++ b/admin/change-status/index.php
@@ -0,0 +1,28 @@
+<?php
+/*
+ * GNUfault.org - GNUfault's website
+ * Copyright (C) 2026 Connor Thomson
+ *
+ * This program is free software: you can redistribute it and/or modify
+ * it under the terms of the GNU Affero General Public License as published by
+ * the Free Software Foundation, either version 3 of the License, or
+ * (at your option) any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * GNU Affero General Public License for more details.
+ *
+ * You should have received a copy of the GNU Affero General Public License
+ * along with this program. If not, see <https://www.gnu.org/licenses/>.
+ */
+
+define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/');
+
+require_once ROOT . '/php/user.php';
+
+require_admin();
+
+render_content(ROOT . '/html/change-status.html');
+
+?>
diff --git a/admin/index.php b/admin/index.php
index 29c8873..13f1659 100755
--- a/admin/index.php
+++ b/admin/index.php
@@ -19,15 +19,9 @@
define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/');
-require_once ROOT . '/php/render.php';
require_once ROOT . '/php/user.php';
-if (!is_admin()) {
- http_response_code(403);
-
- render_content(ROOT . '/html/forbidden.html');
- exit;
-}
+require_admin();
render_content(ROOT . '/html/admin.html');
diff --git a/admin/remove-user/index.php b/admin/remove-user/index.php
new file mode 100755
index 0000000..cd186a5
--- /dev/null
+++ b/admin/remove-user/index.php
@@ -0,0 +1,28 @@
+<?php
+/*
+ * GNUfault.org - GNUfault's website
+ * Copyright (C) 2026 Connor Thomson
+ *
+ * This program is free software: you can redistribute it and/or modify
+ * it under the terms of the GNU Affero General Public License as published by
+ * the Free Software Foundation, either version 3 of the License, or
+ * (at your option) any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * GNU Affero General Public License for more details.
+ *
+ * You should have received a copy of the GNU Affero General Public License
+ * along with this program. If not, see <https://www.gnu.org/licenses/>.
+ */
+
+define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/');
+
+require_once ROOT . '/php/user.php';
+
+require_admin();
+
+render_content(ROOT . '/html/remove-user.html');
+
+?>
diff --git a/admin/remove-user/remove-user.php b/admin/remove-user/remove-user.php
new file mode 100755
index 0000000..81849c2
--- /dev/null
+++ b/admin/remove-user/remove-user.php
@@ -0,0 +1,63 @@
+<?php
+/*
+ * GNUfault.org - GNUfault's website
+ * Copyright (C) 2026 Connor Thomson
+ *
+ * This program is free software: you can redistribute it and/or modify
+ * it under the terms of the GNU Affero General Public License as published by
+ * the Free Software Foundation, either version 3 of the License, or
+ * (at your option) any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * GNU Affero General Public License for more details.
+ *
+ * You should have received a copy of the GNU Affero General Public License
+ * along with this program. If not, see <https://www.gnu.org/licenses/>.
+ */
+
+define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/');
+
+require_once ROOT . '/php/user.php';
+
+require_admin();
+
+if ($_SERVER["REQUEST_METHOD"] != "POST") {
+ header("Location: /admin/remove-user/");
+ exit;
+}
+
+$username = isset($_POST['username']) ? $_POST['username'] : '';
+
+try {
+ $user = find_user($username);
+
+ if (!$user) {
+ echo "User not found.";
+ exit;
+ }
+
+ $me = current_user();
+
+ if ($me !== null && (int)$user['id'] === (int)$me['id']) {
+ echo "You cannot remove yourself!";
+ exit;
+ }
+
+ if ($user['status'] === 'admin') {
+ echo "You cannot remove an admin, lower their status first!";
+ exit;
+ }
+
+ $sql = "DELETE FROM users WHERE username = :username";
+
+ query($sql, ['username' => $username]);
+} catch (\PDOException $e) {
+ echo "Error: " . $e->getMessage();
+ exit;
+}
+
+header("Location: /admin/");
+
+?>
diff --git a/html/account.html b/html/account.html
index 4c5b97d..7d3d1c8 100755
--- a/html/account.html
+++ b/html/account.html
@@ -21,6 +21,7 @@
<label class="username" for="account">{{username}}</label>
<div class="menu">
<a href="/profile/?username={{profile}}">Profile</a>
+ {{admin}}
<a href="/signout/">Sign-out</a>
</div>
</div>
diff --git a/html/admin-link.html b/html/admin-link.html
new file mode 100755
index 0000000..b91dcf2
--- /dev/null
+++ b/html/admin-link.html
@@ -0,0 +1,19 @@
+<!--
+ GNUfault.org - GNUfault's website
+ Copyright (C) 2026 Connor Thomson
+
+ This program is free software: you can redistribute it and/or modify
+ it under the terms of the GNU Affero General Public License as published by
+ the Free Software Foundation, either version 3 of the License, or
+ (at your option) any later version.
+
+ This program is distributed in the hope that it will be useful,
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ GNU Affero General Public License for more details.
+
+ You should have received a copy of the GNU Affero General Public License
+ along with this program. If not, see <https://www.gnu.org/licenses/>.
+-->
+
+<a href="/admin/">Admin</a>
diff --git a/html/admin.html b/html/admin.html
index 8ae34e2..078c23f 100755
--- a/html/admin.html
+++ b/html/admin.html
@@ -18,52 +18,6 @@
<h2>Admin Panel</h2>
<hr>
-
-<h3>Change user's password</h3>
-<form class="login" action="admin.php" method="POST">
- <input type="hidden" name="action" value="password">
- <div class="group">
- <label for="password-username">Username:</label>
- <input class="input" type="text" id="password-username" name="username" required>
- </div>
- <div class="group">
- <label for="password">New password:</label>
- <input class="input" type="password" id="password" name="password" required>
- </div>
- <div class="group">
- <label for="confirmpassword">Confirm new password:</label>
- <input class="input" type="password" id="confirmpassword" name="confirmpassword" required>
- </div>
- <button class="button" type="submit">Send</button>
-</form>
-<br>
-
-<h3>Change user's status</h3>
-<form class="login" action="admin.php" method="POST">
- <input type="hidden" name="action" value="status">
- <div class="group">
- <label for="status-username">Username:</label>
- <input class="input" type="text" id="status-username" name="username" required>
- </div>
- <div class="group">
- <label for="status">Status:</label>
- <select class="input" id="status" name="status">
- <option value="none">none</option>
- <option value="member">member</option>
- <option value="mod">mod</option>
- <option value="admin">admin</option>
- </select>
- </div>
- <button class="button" type="submit">Send</button>
-</form>
-<br>
-
-<h3>Remove user</h3>
-<form class="login" action="admin.php" method="POST">
- <input type="hidden" name="action" value="remove">
- <div class="group">
- <label for="remove-username">Username:</label>
- <input class="input" type="text" id="remove-username" name="username" required>
- </div>
- <button class="button" type="submit">Send</button>
-</form>
+<a href="/admin/change-password/">Change user's password</a><br>
+<a href="/admin/change-status/">Change user's status</a><br>
+<a href="/admin/remove-user/">Remove user</a>
diff --git a/html/change-password.html b/html/change-password.html
new file mode 100755
index 0000000..fd98dce
--- /dev/null
+++ b/html/change-password.html
@@ -0,0 +1,35 @@
+<!--
+ GNUfault.org - GNUfault's website
+ Copyright (C) 2026 Connor Thomson
+
+ This program is free software: you can redistribute it and/or modify
+ it under the terms of the GNU Affero General Public License as published by
+ the Free Software Foundation, either version 3 of the License, or
+ (at your option) any later version.
+
+ This program is distributed in the hope that it will be useful,
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ GNU Affero General Public License for more details.
+
+ You should have received a copy of the GNU Affero General Public License
+ along with this program. If not, see <https://www.gnu.org/licenses/>.
+-->
+
+<h2>Change user's password</h2>
+<hr>
+<form class="login" action="change-password.php" method="POST">
+ <div class="group">
+ <label for="username">Username:</label>
+ <input class="input" type="text" id="username" name="username" required>
+ </div>
+ <div class="group">
+ <label for="password">New password:</label>
+ <input class="input" type="password" id="password" name="password" required>
+ </div>
+ <div class="group">
+ <label for="confirmpassword">Confirm new password:</label>
+ <input class="input" type="password" id="confirmpassword" name="confirmpassword" required>
+ </div>
+ <button class="button" type="submit">Send</button>
+</form>
diff --git a/html/change-status.html b/html/change-status.html
new file mode 100755
index 0000000..4b6e8b2
--- /dev/null
+++ b/html/change-status.html
@@ -0,0 +1,36 @@
+<!--
+ GNUfault.org - GNUfault's website
+ Copyright (C) 2026 Connor Thomson
+
+ This program is free software: you can redistribute it and/or modify
+ it under the terms of the GNU Affero General Public License as published by
+ the Free Software Foundation, either version 3 of the License, or
+ (at your option) any later version.
+
+ This program is distributed in the hope that it will be useful,
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ GNU Affero General Public License for more details.
+
+ You should have received a copy of the GNU Affero General Public License
+ along with this program. If not, see <https://www.gnu.org/licenses/>.
+-->
+
+<h2>Change user's status</h2>
+<hr>
+<form class="login" action="change-status.php" method="POST">
+ <div class="group">
+ <label for="username">Username:</label>
+ <input class="input" type="text" id="username" name="username" required>
+ </div>
+ <div class="group">
+ <label for="status">Status:</label>
+ <select class="input" id="status" name="status">
+ <option value="none">none</option>
+ <option value="member">member</option>
+ <option value="mod">mod</option>
+ <option value="admin">admin</option>
+ </select>
+ </div>
+ <button class="button" type="submit">Send</button>
+</form>
diff --git a/html/remove-user.html b/html/remove-user.html
new file mode 100755
index 0000000..ee2c2eb
--- /dev/null
+++ b/html/remove-user.html
@@ -0,0 +1,27 @@
+<!--
+ GNUfault.org - GNUfault's website
+ Copyright (C) 2026 Connor Thomson
+
+ This program is free software: you can redistribute it and/or modify
+ it under the terms of the GNU Affero General Public License as published by
+ the Free Software Foundation, either version 3 of the License, or
+ (at your option) any later version.
+
+ This program is distributed in the hope that it will be useful,
+ but WITHOUT ANY WARRANTY; without even the implied warranty of
+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ GNU Affero General Public License for more details.
+
+ You should have received a copy of the GNU Affero General Public License
+ along with this program. If not, see <https://www.gnu.org/licenses/>.
+-->
+
+<h2>Remove user</h2>
+<hr>
+<form class="login" action="remove-user.php" method="POST">
+ <div class="group">
+ <label for="username">Username:</label>
+ <input class="input" type="text" id="username" name="username" required>
+ </div>
+ <button class="button" type="submit">Send</button>
+</form>
diff --git a/php/header.php b/php/header.php
index 0fd46df..18a043a 100755
--- a/php/header.php
+++ b/php/header.php
@@ -19,15 +19,19 @@
require_once ROOT . '/php/replace.php';
require_once ROOT . '/php/session.php';
+require_once ROOT . '/php/user.php';
$username = get_username();
if ($username === null) {
$account = import(ROOT . '/html/guest.html');
} else {
+ $admin = is_admin() ? import(ROOT . '/html/admin-link.html') : '';
+
$account = replace(ROOT . '/html/account.html', [
'{{username}}' => htmlspecialchars($username, ENT_QUOTES, 'UTF-8'),
- '{{profile}}' => rawurlencode($username)
+ '{{profile}}' => rawurlencode($username),
+ '{{admin}}' => $admin
]);
}
diff --git a/php/replace.php b/php/replace.php
index dcc5fb6..0823370 100755
--- a/php/replace.php
+++ b/php/replace.php
@@ -25,6 +25,12 @@ function replace(string $templatePath, array $replacements = []): string {
foreach ($replacements as $placeholder => $replacementValue) {
$replacementValue = tidy((string)$replacementValue);
+ if ($replacementValue === '') {
+ $pattern = '/^[ \t]*' . preg_quote($placeholder, '/') . '[ \t]*\n?/m';
+
+ $html = preg_replace($pattern, '', $html);
+ }
+
$pattern = '/^([ \t]*)' . preg_quote($placeholder, '/') . '/m';
$html = preg_replace_callback($pattern, function (array $match) use ($replacementValue) {
diff --git a/php/user.php b/php/user.php
index 8a424e5..9521dc5 100644
--- a/php/user.php
+++ b/php/user.php
@@ -19,6 +19,7 @@
require_once ROOT . '/php/session.php';
require_once ROOT . '/php/database.php';
+require_once ROOT . '/php/render.php';
const USER_STATUSES = ['none', 'member', 'mod', 'admin'];
@@ -46,4 +47,15 @@ function is_admin(): bool {
return $user !== null && $user['status'] === 'admin';
}
+function require_admin(): void {
+ if (is_admin()) {
+ return;
+ }
+
+ http_response_code(403);
+
+ render_content(ROOT . '/html/forbidden.html');
+ exit;
+}
+
?>