-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathadmin.php
More file actions
261 lines (235 loc) · 10.8 KB
/
Copy pathadmin.php
File metadata and controls
261 lines (235 loc) · 10.8 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
<?php
// public/admin.php
session_start();
/**
* admin.php:
* Provides an interface for the "admin" user (userid=0) to manage other users:
* - List all users
* - Delete a user
* - Reset a user's password
*/
// 3) Include config & helpers
require __DIR__ . '/app/config.php'; // loads $userData
require __DIR__ . '/app/helpers.php'; // if needed for any function
// 1) Check if logged in
if (!$isLoggedIn) {
header("Location: login.php");
exit;
}
// 2) Check if current user is admin (userid=0)
if ($_SESSION['userid'] !== '0') {
// Not admin => no permission
exit("<p>Access Denied. You are not the administrator.</p>");
}
// If we want to do operations on $userData, note that $userData is loaded in config.php
// from /app/users.json
$feedbackMsg = '';
// 4) Handle Admin Actions
if (isset($_POST['action'])) {
$action = $_POST['action'];
$username = trim($_POST['username'] ?? '');
// Make sure user is in $userData
if (!isset($userData[$username]) && $username !== '') {
$feedbackMsg = "User '$username' not found.";
} else {
switch ($action) {
case 'delete':
// Protect from self-delete (admin can't remove themselves)
if ($username === $_SESSION['username']) {
$feedbackMsg = "You cannot delete your own admin account.";
} else {
// Remove from userData
unset($userData[$username]);
// Save changes
saveData($userData, $userDataFile);
// Also optionally remove that user's data file
$userID = $_POST['userid'] ?? '';
if ($userID !== '') {
$userJsonFile = __DIR__ . '/app/users/' . $userID . '.json';
if (file_exists($userJsonFile)) {
unlink($userJsonFile);
}
}
$feedbackMsg = "User '$username' deleted.";
}
break;
case 'reset':
// We'll reset to a random password or a default
$newPass = generateRandomPassword(8); // e.g. 8 chars
$hashed = password_hash($newPass, PASSWORD_DEFAULT);
$userData[$username]['password'] = $hashed;
saveData($userData, $userDataFile);
$feedbackMsg = "Password for user '$username' reset to: <strong>$newPass</strong>";
break;
case 'edit_module_id':
// Assuming you have a function to edit module ID
$moduleID = $_POST['moduleID'] ?? '';
$newName = $_POST['newName'] ?? '';
if ($moduleID !== '' && $newName !== '') {
// Check if the module ID exists in the globalModuleIDs
if (!in_array($moduleID, $globalModuleIDs)) {
$feedbackMsg = "Module ID '$moduleID' not found.";
break;
}
// Check if the new name is valid
if (in_array($newName, $globalModuleIDs)) {
$feedbackMsg = "New name '$newName' already exists.";
break;
}
// iterate through all user files and adjust the module ID
foreach ($userData as $username => $user) {
$userJsonFile = __DIR__ . '/app/users/' . $user['userid'] . '.json';
if (file_exists($userJsonFile)) {
$temp_data = json_decode(file_get_contents($userJsonFile), true);
$didChange = false;
foreach ($temp_data['modules'] as $moduleIndex => $module) {
if (isset($module['id']) && $module['id'] == $moduleID) {
// Update the module ID
$temp_data['modules'][$moduleIndex]['id'] = $newName;
$didChange = true;
}
}
if ($didChange) {
saveData($temp_data, $userJsonFile);
}
}
}
// change in the globalModuleIDs array
$globalModuleIDs = array_map(function($module) use ($moduleID, $newName) {
return $module === $moduleID ? $newName : $module;
}, $globalModuleIDs);
// Save the updated globalModuleIDs
saveData($globalModuleIDs, $globalModuleIDFile);
$feedbackMsg = "Module ID '$moduleID' updated to '$newName'.";
} else {
$feedbackMsg = "Invalid module ID or new name.";
}
break;
}
}
}
/**
* 5) Helper function to generate random password
*/
function generateRandomPassword($length = 8)
{
$chars = 'abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789';
$pwd = '';
for ($i = 0; $i < $length; $i++) {
$pwd .= $chars[random_int(0, strlen($chars) - 1)];
}
return $pwd;
}
// 6) HTML Output
?>
<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8" />
<title>Admin - Manage Users</title>
<link rel="stylesheet" href="css/style.css" />
</head>
<body>
<div class="container">
<h1>Admin User Management</h1>
<p><a href="index.php">Back to Modules</a></p>
<?php if ($feedbackMsg): ?>
<div style="padding:10px; margin:10px 0; background:#eef;">
<?php echo $feedbackMsg; ?>
</div>
<?php endif; ?>
<h2>Existing Users</h2>
<?php if (empty($userData)): ?>
<p>No users found.</p>
<?php else: ?>
<table border="1" cellpadding="5" cellspacing="0">
<thead>
<tr>
<th>Username</th>
<th>User ID</th>
<th>Actions</th>
</tr>
</thead>
<tbody>
<?php foreach ($userData as $uname => $info): ?>
<tr>
<td><?php echo htmlspecialchars($uname); ?></td>
<td><?php echo htmlspecialchars($info['userid'] ?? ''); ?></td>
<td>
<!-- Delete Form -->
<?php if ($uname !== $_SESSION['username']): // Don't show delete for admin ?>
<form method="post" style="display:inline;" onsubmit="return confirm('Delete this user?');">
<input type="hidden" name="action" value="delete">
<input type="hidden" name="username" value="<?php echo htmlspecialchars($uname); ?>">
<input type="hidden" name="userid"
value="<?php echo htmlspecialchars($info['userid'] ?? ''); ?>">
<button type="submit">Delete</button>
</form>
<?php endif; ?>
<!-- Reset Password Form -->
<form method="post" style="display:inline;"
onsubmit="return confirm('Reset password for this user?');">
<input type="hidden" name="action" value="reset">
<input type="hidden" name="username" value="<?php echo htmlspecialchars($uname); ?>">
<button type="submit">Reset Password</button>
</form>
</td>
</tr>
<?php endforeach; ?>
</tbody>
</table>
<?php endif; ?>
<h2>Module ID's</h2>
<table border="1" cellpadding="5" cellspacing="0">
<thead>
<tr>
<th>Module</th>
<th>Actions</th>
</tr>
</thead>
<tbody>
<?php
// Assuming you have a function to get module data
// $globalModuleIDs
foreach ($globalModuleIDs as $moduleID):
?>
<tr>
<td><?php echo htmlspecialchars($moduleID); ?></td>
<td>
<?php $uuid = uniqid('btn_'); ?>
<button id="<?php echo $uuid; ?>">Edit</button>
<script>
document.getElementById('<?php echo $uuid; ?>').addEventListener('click', function() {
// Your edit logic here
var newName = prompt('Edit Module ID:', '<?php echo htmlspecialchars($moduleID); ?>');
if (newName) {
// redirect post data
var form = document.createElement('form');
form.method = 'POST';
var input = document.createElement('input');
input.type = 'hidden';
input.name = 'action';
input.value = 'edit_module_id';
form.appendChild(input);
input = document.createElement('input');
input.type = 'hidden';
input.name = 'moduleID';
input.value = '<?php echo htmlspecialchars($moduleID); ?>';
form.appendChild(input);
input = document.createElement('input');
input.type = 'hidden';
input.name = 'newName';
input.value = newName;
form.appendChild(input);
document.body.appendChild(form);
form.submit();
}
});
</script>
</td>
</tr>
<?php endforeach; ?>
</tbody>
</div>
</body>
</html>