2 /************************************************************************
3 * MXChange v0.2.1 Start: 04/11/2004 *
4 * ================ Last change: 10/29/2004 *
6 * -------------------------------------------------------------------- *
7 * File : ext-admins.php *
8 * -------------------------------------------------------------------- *
9 * Short description : Administrator management *
10 * -------------------------------------------------------------------- *
11 * Kurzbeschreibung : Admin-Accountsverwaltung *
12 * -------------------------------------------------------------------- *
14 * -------------------------------------------------------------------- *
15 * Copyright (c) 2003 - 2008 by Roland Haeder *
16 * For more information visit: http://www.mxchange.org *
18 * This program is free software; you can redistribute it and/or modify *
19 * it under the terms of the GNU General Public License as published by *
20 * the Free Software Foundation; either version 2 of the License, or *
21 * (at your option) any later version. *
23 * This program is distributed in the hope that it will be useful, *
24 * but WITHOUT ANY WARRANTY; without even the implied warranty of *
25 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the *
26 * GNU General Public License for more details. *
28 * You should have received a copy of the GNU General Public License *
29 * along with this program; if not, write to the Free Software *
30 * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, *
32 ************************************************************************/
34 // Some security stuff...
35 if (!defined('__SECURITY')) {
36 $INC = substr(dirname(__FILE__), 0, strpos(dirname(__FILE__), "/inc") + 4) . "/security.php";
40 // Version of this extension
41 $EXT_VERSION = "0.7.0";
43 // Auto-set extension version
44 if (empty($EXT_VER)) $EXT_VER = $EXT_VERSION;
46 // Version history array (add more with , "0.1" and so on)
47 $EXT_VER_HISTORY = array("0.0", "0.1", "0.2", "0.3", "0.3.1", "0.4.0", "0.4.1", "0.4.2", "0.4.3", "0.4.4", "0.4.5", "0.4.6", "0.4.7", "0.4.8", "0.4.9", "0.5.0", "0.5.1", "0.5.2", "0.5.3", "0.5.4", "0.5.5", "0.5.6", "0.5.7", "0.5.8", "0.5.9", "0.6.0", "0.6.1", "0.6.2", "0.6.3", "0.6.4", "0.6.5", "0.6.6", "0.6.7", "0.6.8", "0.6.9", "0.7.0");
49 switch ($EXT_LOAD_MODE)
51 case "register": // Do stuff when installtion is running (modules.php?module=admin&action=login is called)
52 // SQL commands to run
53 $SQLs[] = "DELETE LOW_PRIORITY FROM "._MYSQL_PREFIX."_admin_menu WHERE action='admins' LIMIT 1";
54 $SQLs[] = "INSERT INTO "._MYSQL_PREFIX."_admin_menu (action, what, title, descr, sort) VALUES ('admins', NULL, 'Admin-Management','Administratoren anlegen, löschen oder Passwort/E-Mail Adresse ändern.','1')";
55 $SQLs[] = "INSERT INTO "._MYSQL_PREFIX."_admin_menu (action, what, title, descr, sort) VALUES ('admins','admins_add','Admin hinzufügen','Neuen Admin-Account anlegen','0')";
56 $SQLs[] = "INSERT INTO "._MYSQL_PREFIX."_admin_menu (action, what, title, descr, sort) VALUES ('admins','admins_edit','Admin-Account ändern','Bestehende Admin-Accounts bearbeiten: E-Mail-Adresse, Passwort und/oder Login-Name ändern.','1')";
59 case "remove": // Do stuff when removing extension
60 // SQL commands to run
61 $SQLs[] = "DELETE LOW_PRIORITY FROM "._MYSQL_PREFIX."_admin_menu WHERE action='admins' LIMIT 5";
62 $SQLs[] = "DROP TABLE "._MYSQL_PREFIX."_admins_acls";
63 $SQLs[] = "ALTER TABLE "._MYSQL_PREFIX."_admins DROP default_acl";
66 case "activate": // Do stuff when admin activates this extension
67 // SQL commands to run
71 case "deactivate": // Do stuff when admin deactivates this extension
72 // SQL commands to run
76 case "update": // Update an extension
79 case "0.2": // SQL queries for v0.2
80 $SQLs[] = "INSERT INTO "._MYSQL_PREFIX."_admin_menu (action, what, title, descr, sort) VALUES ('admins','admins_contact','Admin kontaktieren','Kontaktiert einen Admin per Mail oder Nachricht (nur wenn messaging-Erweiterung installiert ist).','2')";
82 // Update notes (these will be set as task text!)
83 $UPDATE_NOTES = "Fügt den Menüpunkt "Admin kontaktieren" hinzu.";
86 case "0.3": // SQL queries for v0.3
88 $SQLs[] = "INSERT INTO "._MYSQL_PREFIX."_admin_menu (action, what, title, descr, sort) VALUES ('admins','config_admins','ACL einstellen','Richten Sie Zugriffskontrollzeilen für jeden Admin individuell ein, um ihm nur bestimmte Bereiche des Admin-Bereiches zugänglich zu machen oder zu sperren.','4')";
90 // Which is the default setting when you create a new admin login?
91 $SQLs[] = "ALTER TABLE "._MYSQL_PREFIX."_config ADD admins_default_acl ENUM('deny','allow') NOT NULL DEFAULT 'deny'";
93 // Default is deny everything
94 $SQLs[] = "ALTER TABLE "._MYSQL_PREFIX."_admins ADD default_acl ENUM('deny','allow') NOT NULL DEFAULT 'deny'";
96 // But allow current admin everything (THIS SHALL BE YOU!)
97 $SQLs[] = "UPDATE "._MYSQL_PREFIX."_admins SET default_acl='allow' WHERE login='".get_session('admin_login')."' LIMIT 1";
98 $SQLs[] = "DROP TABLE IF EXISTS "._MYSQL_PREFIX."_admins_acls";
99 $SQLs[] = "CREATE TABLE "._MYSQL_PREFIX."_admins_acls (
100 id BIGINT(20) UNSIGNED NOT NULL AUTO_INCREMENT,
101 admin_id BIGINT(20) UNSIGNED NOT NULL DEFAULT '0',
102 action_menu VARCHAR(255) NOT NULL DEFAULT '',
103 what_menu VARCHAR(255) NOT NULL DEFAULT '',
104 access_mode ENUM('deny','allow') NOT NULL DEFAULT 'deny',
109 // Update notes (these will be set as task text!)
110 $UPDATE_NOTES = "Sogn. ACLs werden hinzugefügt: <STRONG>A</STRONG>ccess <STRONG>C</STRONG>ontrol <STRONG>L</STRONG>ines sind zu deutsch Zugriffkontrollzeilen, mit denen Sie einstellen können, was welcher Admin machen darf oder nicht.";
113 case "0.3.1": // SQL queries for v0.3.1
114 $SQLs[] = "ALTER TABLE "._MYSQL_PREFIX."_admins_acls MODIFY id BIGINT(20) UNSIGNED NOT NULL AUTO_INCREMENT";
117 case "0.4.0": // SQL queries for v0.4.0
118 $SQLs[] = "DROP TABLE IF EXISTS "._MYSQL_PREFIX."_admins_mails";
119 $SQLs[] = "CREATE TABLE "._MYSQL_PREFIX."_admins_mails (
120 id BIGINT(20) UNSIGNED NOT NULL AUTO_INCREMENT,
121 admin_id BIGINT(20) UNSIGNED NOT NULL DEFAULT '0',
122 mail_template VARCHAR(255) NOT NULL,
126 $SQLs[] = "INSERT INTO "._MYSQL_PREFIX."_admin_menu (action, what, title, descr, sort) VALUES ('admins','admins_mails','Admin-Mails','Stellen Sie hier ein, welcher Admin welche Mail erhalten soll. Sie können dies (derzeit) jedoch erst, wenn einmal die Mail versendet wurde!','5')";
128 // Update notes (these will be set as task text!)
129 $UPDATE_NOTES = "Kontrollieren Sie, welche Mails welcher Admin oder alle (admin_id=0) bekommen soll oder im UserLog (admin_id=-1) verzeichnet werden soll. Standartmässig wird weiter an alle versendet.";
132 case "0.4.1": // SQL queries for v0.4.1
133 $SQLs[] = "DELETE LOW_PRIORITY FROM "._MYSQL_PREFIX."_admins_mails WHERE mail_template LIKE '% %'";
135 // Update notes (these will be set as task text!)
136 $UPDATE_NOTES = "Admins-Mails-Tabelle geleert.";
138 case "0.4.4": // SQL queries for v0.4.4
139 // Update notes (these will be set as task text!)
140 $UPDATE_NOTES = "&admin= in &amp;admin= umgewandelt.";
143 case "0.4.5": // SQL queries for v0.4.5
144 // Update notes (these will be set as task text!)
145 $UPDATE_NOTES = "Vorbereitet auf Cache-System";
148 case "0.4.6": // SQL queries for v0.4.6
149 // Update notes (these will be set as task text!)
150 $UPDATE_NOTES = "Problem mit cache-Erweiterung gefixt. Der Admin-Bereich war permanent gesperrt.";
153 case "0.4.7": // SQL queries for v0.4.7
154 // Update notes (these will be set as task text!)
155 $UPDATE_NOTES = "Es wurde die Zeitmarke der Cache-Datei admins.cache mit berücksichtigt.";
158 case "0.4.8": // SQL queries for v0.4.8
159 // Update notes (these will be set as task text!)
160 $UPDATE_NOTES = "Fehler beseitigt, wenn error_reporting=E_ALL gesetzt ist.";
163 case "0.4.9": // SQL queries for v0.4.9
164 // Update notes (these will be set as task text!)
165 $UPDATE_NOTES = "Fehler beseitigt, wenn error_reporting=E_ALL gesetzt ist.";
168 case "0.5.0": // SQL queries for v0.5.0
169 // Update notes (these will be set as task text!)
170 $UPDATE_NOTES = "Fehler beseitigt, wenn error_reporting=E_ALL gesetzt ist.";
173 case "0.5.1": // SQL queries for v0.5.1
174 // Update notes (these will be set as task text!)
175 $UPDATE_NOTES = "Cache wird endlich gelöscht, wenn Admin entfernt wird.";
178 case "0.5.2": // SQL queries for v0.5.2
179 // Update notes (these will be set as task text!)
180 $UPDATE_NOTES = "Löschen von Admin-Accounts repariert und HTML-Code ausgelagert in Templates.";
183 case "0.5.3": // SQL queries for v0.5.3
184 // Update notes (these will be set as task text!)
185 $UPDATE_NOTES = "Seit <A href=\"#\">Patch 340</A> überflüssige HTML-Tags entfernt.";
188 case "0.5.4": // SQL queries for v0.5.4
189 // Update notes (these will be set as task text!)
190 $UPDATE_NOTES = "IP-Nummer und Browserbezeichnung wird in Admin-Mails eingesetzt.";
193 case "0.5.5": // SQL queries for v0.5.5
194 // Update notes (these will be set as task text!)
195 $UPDATE_NOTES = "Menüpunkt Admin-Mails korregiert: SQL-Anweisung war fehlerhaft; und HTML-Code in Templates ausgelagert.";
198 case "0.5.6": // SQL queries for v0.5.6
199 $SQLs[] = "UPDATE "._MYSQL_PREFIX."_admin_menu SET what='admins_contct' WHERE what='admins_contact' LIMIT 1";
201 // Update notes (these will be set as task text!)
202 $UPDATE_NOTES = "Namenskonflikt zwischen den Erweiterungen <STRONG>admins</STRONG> und (kommender) <STRONG>contact</STRONG>.";
205 case "0.5.7": // SQL queries for v0.5.7
206 // Update notes (these will be set as task text!)
207 $UPDATE_NOTES = "Links wegen <STRONG>what=admins_contct</STRONG> geändert.";
210 case "0.5.8": // SQL queries for v0.5.8
211 $SQLs[] = "UPDATE "._MYSQL_PREFIX."_admin_menu SET what='admins_contct' WHERE what='admins_contact' LIMIT 1";
213 // Update notes (these will be set as task text!)
214 $UPDATE_NOTES = "Ein Punkt in der Versionsnummernliste verhinderte das 0.5.6-Update.";
217 case "0.5.9": // SQL queries for v0.5.9
218 // Update notes (these will be set as task text!)
219 $UPDATE_NOTES = "Sicherheitsupdate: SQL-Anweisungen geschützt.";
222 case "0.6.0": // SQL queries for v0.6.0
223 // Update notes (these will be set as task text!)
224 $UPDATE_NOTES = "Link in "ACL Einstellen" zum Admin-Kontaktformular korregiert.";
227 case "0.6.1": // SQL queries for v0.6.1
228 // Update notes (these will be set as task text!)
229 $UPDATE_NOTES = "Speichern von Admin-Accounts klappt wieder.";
232 case "0.6.2": // SQL queries for v0.6.2
233 // Update notes (these will be set as task text!)
234 $UPDATE_NOTES = "Bitte verschieben Sie die admins-Templates (Ordner: ".PATH."/templates/de/emails/) in den neuen Order admins!";
237 case "0.6.3": // SQL queries for v0.6.3
238 // Update notes (these will be set as task text!)
239 $UPDATE_NOTES = "Abspeichern von Einstellungen repariert.";
242 case "0.6.4": // SQL queries for v0.6.4
243 // Update notes (these will be set as task text!)
244 $UPDATE_NOTES = "Problem mit der Rechtevererbung beseitigt: Geben Sie nun ein Hauptmenü frei (Allow), dann kann der Admin auch die Untermenüs erreichen. Zudem können Sie gezielte Untermenüs im freigegeben Hauptmenü dennoch sperren.";
247 case "0.6.5": // SQL queries for v0.6.5
248 // Update notes (these will be set as task text!)
249 $UPDATE_NOTES = "Sicherheitsupdate für die Include-Befehle.";
252 case "0.6.6": // SQL queries for v0.5.6
253 $SQLs[] = "UPDATE "._MYSQL_PREFIX."_admin_menu SET what='admins_contct' WHERE what='admins_contact' LIMIT 1";
255 // Update notes (these will be set as task text!)
256 $UPDATE_NOTES = "Namenskonflikt zwischen den Erweiterungen <STRONG>admins</STRONG> und (kommender) <STRONG>contact</STRONG>.";
259 case "0.6.7": // SQL queries for v0.6.7
260 $SQLs[] = "ALTER TABLE "._MYSQL_PREFIX."_admins ADD la_mode ENUM('global','OLD','NEW') NOT NULL DEFAULT 'global'";
262 // Update notes (these will be set as task text!)
263 $UPDATE_NOTES = "Namenskonflikt zwischen den Erweiterungen <STRONG>admins</STRONG> und (kommender) <STRONG>contact</STRONG>. Beseitigung eines Fehlers <STRONG>HTTP_POSR_VARS</STRONG> beim Ändern von Administratoren.";
266 case "0.6.8": // SQL queries for v0.6.8
267 // Update notes (these will be set as task text!)
268 $UPDATE_NOTES = "<STRONG>set_session()</STRONG> mit @-Zeichen gegen ungewollte Ausgaben abgesichert.";
271 case "0.6.9": // SQL queries for v0.6.9
272 $SQLs[] = "UPDATE "._MYSQL_PREFIX."_admin_menu SET title = 'Admin-Management' WHERE action = 'admins' AND (what='' OR what IS NULL) LIMIT 1";
274 // Update notes (these will be set as task text!)
275 $UPDATE_NOTES = "Verwaltung nach Management umbenannt.";
278 case "0.7.0": // SQL queries for v0.7.0
279 $SQLs[] = "ALTER TABLE "._MYSQL_PREFIX."_admins ADD login_failtures BIGINT(20) UNSIGNED NOT NULL DEFAULT 0";
280 $SQLs[] = "ALTER TABLE "._MYSQL_PREFIX."_admins ADD last_failture TIMESTAMP NOT NULL DEFAULT '0000-00-00 00:00:00'";
282 // Update notes (these will be set as task text!)
283 $UPDATE_NOTES = "Fehlgeschlagene Login-Versuche werden nun mitgezählt und der letzte vermerkt.";
288 default: // Do stuff when extension is loaded
292 // Language file prefix
293 $EXT_LANG_PREFIX = "admins";
295 // Extension is always active?
296 $EXT_ALWAYS_ACTIVE = "N";