. */ define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/'); require_once ROOT . '/php/user.php'; if (!is_admin()) { http_response_code(403); echo "Forbidden"; exit; } if ($_SERVER["REQUEST_METHOD"] != "POST") { header("Location: /admin/"); exit; } $action = isset($_POST['action']) ? $_POST['action'] : ''; $username = isset($_POST['username']) ? $_POST['username'] : ''; try { if (!find_user($username)) { echo "User not found."; exit; } if ($action == 'password') { $password = $_POST['password']; $confirmpassword = $_POST['confirmpassword']; if ($confirmpassword != $password) { echo "Passwords do not match!"; exit; } $sql = "UPDATE users SET password = :password WHERE username = :username"; query($sql, [ 'password' => password_hash($password, PASSWORD_DEFAULT), 'username' => $username ]); } elseif ($action == 'status') { $status = isset($_POST['status']) ? $_POST['status'] : ''; if (!in_array($status, USER_STATUSES, true)) { echo "That is not a status!"; exit; } $sql = "UPDATE users SET status = :status WHERE username = :username"; query($sql, [ 'status' => $status, 'username' => $username ]); } elseif ($action == 'remove') { $sql = "DELETE FROM users WHERE username = :username"; query($sql, ['username' => $username]); } else { echo "That is not something I can do."; exit; } } catch (\PDOException $e) { echo "Error: " . $e->getMessage(); exit; } header("Location: /admin/"); ?>