From 070a27baa8f93c3bf191459b88d24d7430a78899 Mon Sep 17 00:00:00 2001 From: Connor Thomson Date: Sun, 20 Sep 2026 21:23:09 -0700 Subject: Some fixes and updates --- admin/admin.php | 89 --------------------------------------------------------- 1 file changed, 89 deletions(-) delete mode 100755 admin/admin.php (limited to 'admin/admin.php') diff --git a/admin/admin.php b/admin/admin.php deleted file mode 100755 index eb85ccb..0000000 --- a/admin/admin.php +++ /dev/null @@ -1,89 +0,0 @@ -. - */ - -define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/'); - -require_once ROOT . '/php/user.php'; - -if (!is_admin()) { - http_response_code(403); - - echo "Forbidden"; - exit; -} - -if ($_SERVER["REQUEST_METHOD"] != "POST") { - header("Location: /admin/"); - exit; -} - -$action = isset($_POST['action']) ? $_POST['action'] : ''; -$username = isset($_POST['username']) ? $_POST['username'] : ''; - -try { - if (!find_user($username)) { - echo "User not found."; - exit; - } - - if ($action == 'password') { - $password = $_POST['password']; - $confirmpassword = $_POST['confirmpassword']; - - if ($confirmpassword != $password) { - echo "Passwords do not match!"; - exit; - } - - $sql = "UPDATE users SET password = :password WHERE username = :username"; - - query($sql, [ - 'password' => password_hash($password, PASSWORD_DEFAULT), - 'username' => $username - ]); - } elseif ($action == 'status') { - $status = isset($_POST['status']) ? $_POST['status'] : ''; - - if (!in_array($status, USER_STATUSES, true)) { - echo "That is not a status!"; - exit; - } - - $sql = "UPDATE users SET status = :status WHERE username = :username"; - - query($sql, [ - 'status' => $status, - 'username' => $username - ]); - } elseif ($action == 'remove') { - $sql = "DELETE FROM users WHERE username = :username"; - - query($sql, ['username' => $username]); - } else { - echo "That is not something I can do."; - exit; - } -} catch (\PDOException $e) { - echo "Error: " . $e->getMessage(); - exit; -} - -header("Location: /admin/"); - -?> -- cgit v1.2.3