summaryrefslogtreecommitdiff
path: root/admin/admin.php
diff options
context:
space:
mode:
Diffstat (limited to 'admin/admin.php')
-rwxr-xr-xadmin/admin.php89
1 files changed, 0 insertions, 89 deletions
diff --git a/admin/admin.php b/admin/admin.php
deleted file mode 100755
index eb85ccb..0000000
--- a/admin/admin.php
+++ /dev/null
@@ -1,89 +0,0 @@
-<?php
-/*
- * GNUfault.org - GNUfault's website
- * Copyright (C) 2026 Connor Thomson
- *
- * This program is free software: you can redistribute it and/or modify
- * it under the terms of the GNU Affero General Public License as published by
- * the Free Software Foundation, either version 3 of the License, or
- * (at your option) any later version.
- *
- * This program is distributed in the hope that it will be useful,
- * but WITHOUT ANY WARRANTY; without even the implied warranty of
- * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
- * GNU Affero General Public License for more details.
- *
- * You should have received a copy of the GNU Affero General Public License
- * along with this program. If not, see <https://www.gnu.org/licenses/>.
- */
-
-define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/');
-
-require_once ROOT . '/php/user.php';
-
-if (!is_admin()) {
- http_response_code(403);
-
- echo "Forbidden";
- exit;
-}
-
-if ($_SERVER["REQUEST_METHOD"] != "POST") {
- header("Location: /admin/");
- exit;
-}
-
-$action = isset($_POST['action']) ? $_POST['action'] : '';
-$username = isset($_POST['username']) ? $_POST['username'] : '';
-
-try {
- if (!find_user($username)) {
- echo "User not found.";
- exit;
- }
-
- if ($action == 'password') {
- $password = $_POST['password'];
- $confirmpassword = $_POST['confirmpassword'];
-
- if ($confirmpassword != $password) {
- echo "Passwords do not match!";
- exit;
- }
-
- $sql = "UPDATE users SET password = :password WHERE username = :username";
-
- query($sql, [
- 'password' => password_hash($password, PASSWORD_DEFAULT),
- 'username' => $username
- ]);
- } elseif ($action == 'status') {
- $status = isset($_POST['status']) ? $_POST['status'] : '';
-
- if (!in_array($status, USER_STATUSES, true)) {
- echo "That is not a status!";
- exit;
- }
-
- $sql = "UPDATE users SET status = :status WHERE username = :username";
-
- query($sql, [
- 'status' => $status,
- 'username' => $username
- ]);
- } elseif ($action == 'remove') {
- $sql = "DELETE FROM users WHERE username = :username";
-
- query($sql, ['username' => $username]);
- } else {
- echo "That is not something I can do.";
- exit;
- }
-} catch (\PDOException $e) {
- echo "Error: " . $e->getMessage();
- exit;
-}
-
-header("Location: /admin/");
-
-?>