From 1b35cf3f1124b161ebde5e9e3a2c74c8ea2821d0 Mon Sep 17 00:00:00 2001 From: Connor Thomson Date: Sun, 20 Sep 2026 21:01:48 -0700 Subject: Add status and more --- admin/admin.php | 89 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 89 insertions(+) create mode 100755 admin/admin.php (limited to 'admin/admin.php') diff --git a/admin/admin.php b/admin/admin.php new file mode 100755 index 0000000..0a00cf3 --- /dev/null +++ b/admin/admin.php @@ -0,0 +1,89 @@ +. + */ + +define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/'); + +require_once ROOT . '/php/user.php'; + +if (!is_admin()) { + http_response_code(403); + + echo "Forbidden"; + exit; +} + +if ($_SERVER["REQUEST_METHOD"] != "POST") { + header("Location: /admin"); + exit; +} + +$action = isset($_POST['action']) ? $_POST['action'] : ''; +$username = isset($_POST['username']) ? $_POST['username'] : ''; + +try { + if (!find_user($username)) { + echo "User not found."; + exit; + } + + if ($action == 'password') { + $password = $_POST['password']; + $confirmpassword = $_POST['confirmpassword']; + + if ($confirmpassword != $password) { + echo "Passwords do not match!"; + exit; + } + + $sql = "UPDATE users SET password = :password WHERE username = :username"; + + query($sql, [ + 'password' => password_hash($password, PASSWORD_DEFAULT), + 'username' => $username + ]); + } elseif ($action == 'status') { + $status = isset($_POST['status']) ? $_POST['status'] : ''; + + if (!in_array($status, USER_STATUSES, true)) { + echo "That is not a status!"; + exit; + } + + $sql = "UPDATE users SET status = :status WHERE username = :username"; + + query($sql, [ + 'status' => $status, + 'username' => $username + ]); + } elseif ($action == 'remove') { + $sql = "DELETE FROM users WHERE username = :username"; + + query($sql, ['username' => $username]); + } else { + echo "That is not something I can do."; + exit; + } +} catch (\PDOException $e) { + echo "Error: " . $e->getMessage(); + exit; +} + +header("Location: /admin"); + +?> -- cgit v1.2.3