2 /************************************************************************
3 * MXChange v0.2.1 Start: 06/30/2004 *
4 * ================ Last change: 07/02/2004 *
6 * -------------------------------------------------------------------- *
7 * File: what-config_admins.php *
8 * -------------------------------------------------------------------- *
9 * Short description : Configure admin ACLs *
10 * -------------------------------------------------------------------- *
11 * Kurzbeschreibung : Admin-ACLs einstellen *
12 * -------------------------------------------------------------------- *
14 * -------------------------------------------------------------------- *
15 * Copyright (c) 2003 - 2008 by Roland Haeder *
16 * For more information visit: http://www.mxchange.org *
18 * This program is free software; you can redistribute it and/or modify *
19 * it under the terms of the GNU General Public License as published by *
20 * the Free Software Foundation; either version 2 of the License, or *
21 * (at your option) any later version. *
23 * This program is distributed in the hope that it will be useful, *
24 * but WITHOUT ANY WARRANTY; without even the implied warranty of *
25 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the *
26 * GNU General Public License for more details. *
28 * You should have received a copy of the GNU General Public License *
29 * along with this program; if not, write to the Free Software *
30 * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, *
32 ************************************************************************/
34 // Some security stuff...
35 if ((!defined('__SECURITY')) || (!IS_ADMIN())) {
36 $INC = substr(dirname(__FILE__), 0, strpos(dirname(__FILE__), "/inc") + 4) . "/security.php";
40 // Add description as navigation point
41 ADD_DESCR("admin", __FILE__);
44 if (REQUEST_ISSET_POST(('sel'))) $SEL = SELECTION_COUNT(REQUEST_POST('sel'));
46 if ((REQUEST_ISSET_POST(('edit'))) && ($SEL > 0)) {
49 foreach (REQUEST_POST('sel') as $id => $sel) {
50 // Load data for the ID
51 $result = SQL_QUERY_ESC("SELECT admin_id, action_menu, what_menu, access_mode FROM `{!_MYSQL_PREFIX!}_admins_acls` WHERE id=%s LIMIT 1",
52 array(bigintval($id)), __FILE__, __LINE__);
53 list($aid, $act, $wht, $mode) = SQL_FETCHROW($result);
54 SQL_FREERESULT($result);
56 // Prepare data for the row template
60 'admins_selection' => ADD_OPTION_LINES("admins", "id", "login", $aid, "default_acl"),
61 'action_selection' => ADMIN_MENU_SELECTION("action", $act, $id),
62 'what_selection' => ADMIN_MENU_SELECTION("what", $wht, $id),
63 'mode_options' => ADD_OPTION_LINES(
65 array("allow", "deny"),
66 array(constant('ADMINS_ALLOW_MODE'), constant('ADMINS_DENY_MODE')),
72 $OUT .= LOAD_TEMPLATE("admin_config_admins_edit_row", true, $content);
75 define('__ACL_ROWS', $OUT);
78 LOAD_TEMPLATE("admin_config_admins_edit");
79 } elseif ((REQUEST_ISSET_POST(('change'))) && ($SEL > 0)) {
81 foreach (REQUEST_POST('sel') as $id => $sel) {
86 SQL_QUERY_ESC("UPDATE `{!_MYSQL_PREFIX!}_admins_acls` SET admin_id=%s, action_menu='%s', what_menu='%s', access_mode='%s' WHERE id=%s LIMIT 1",
88 REQUEST_POST('admin', $id),
89 REQUEST_POST('action_menu', $id),
90 REQUEST_POST('what_menu', $id),
91 REQUEST_POST('mode', $id),
93 ),__FILE__, __LINE__);
96 // Update cache when installed
97 if (EXT_IS_ACTIVE("cache")) {
98 if ($GLOBALS['cache_instance']->loadCacheFile("admins_acls")) $GLOBALS['cache_instance']->destroyCacheFile();
101 CACHE_PURGE_ADMIN_MENU(REQUEST_POST('admin', $id));
105 LOAD_TEMPLATE("admin_settings_saved", false, getMessage('ADMIN_ADMINS_ENTRIES_CHANGED'));
106 } elseif ((REQUEST_ISSET_POST(('del'))) && ($SEL > 0)) {
109 foreach (REQUEST_POST('sel') as $id => $sel) {
110 // Load data for the ID
111 $result = SQL_QUERY_ESC("SELECT admin_id, action_menu, what_menu, access_mode FROM `{!_MYSQL_PREFIX!}_admins_acls` WHERE id=%s LIMIT 1",
112 array(bigintval($id)), __FILE__, __LINE__);
113 list($admin, $act, $wht, $mode) = SQL_FETCHROW($result);
114 SQL_FREERESULT($result);
117 if (empty($act)) $act = "---";
118 if (empty($wht)) $wht = "---";
121 $mode = constant('ADMINS_'.strtoupper($mode).'_MODE');
124 $admin = GENERATE_AID_LINK($admin);
126 // Prepare data for the row template
136 // Load row template and switch colors
137 $OUT .= LOAD_TEMPLATE("admin_config_admins_del_row", true, $content);
140 define('__ACL_ROWS', $OUT);
142 // Load main template
143 LOAD_TEMPLATE("admin_config_admins_del");
144 } elseif ((REQUEST_ISSET_POST(('remove'))) && ($SEL > 0)) {
146 foreach (REQUEST_POST('sel') as $id => $sel) {
147 SQL_QUERY_ESC("DELETE LOW_PRIORITY FROM `{!_MYSQL_PREFIX!}_admins_acls` WHERE id=%s LIMIT 1",
148 array(bigintval($id)),__FILE__, __LINE__);
151 // Update cache when installed
152 if (EXT_IS_ACTIVE("cache")) {
153 if ($GLOBALS['cache_instance']->loadCacheFile("admins_acls")) $GLOBALS['cache_instance']->destroyCacheFile();
155 // @TODO This causes the whole (!) menu cache being rebuild
156 CACHE_PURGE_ADMIN_MENU();
160 LOAD_TEMPLATE("admin_settings_saved", false, getMessage('ADMIN_ADMINS_ENTRIES_DELETED'));
161 } elseif (REQUEST_ISSET_POST(('add'))) {
162 // Check if everything is fine...
163 $mode = GET_ADMIN_DEFAULT_ACL(bigintval(REQUEST_POST('admin_id')));
165 // Default ACL is false
167 if (REQUEST_ISSET_POST(('what_menu'))) {
169 $ACL = ADMINS_CHECK_ACL(GET_ACTION("admin", REQUEST_POST('what_menu')), "");
172 if ($mode != REQUEST_POST('mode') || ($ACL)) {
174 $BOTH = ((REQUEST_ISSET_POST(('action_menu'))) && (REQUEST_ISSET_POST(('what_menu'))));
175 if (((REQUEST_ISSET_POST(('action_menu'))) || (REQUEST_ISSET_POST(('what_menu')))) && (!$BOTH)) {
176 // Main or sub menu selected
177 $result = SQL_QUERY_ESC("SELECT id FROM `{!_MYSQL_PREFIX!}_admins_acls` WHERE admin_id=%s AND action_menu='%s' AND what_menu='%s' LIMIT 1",
178 array(bigintval(REQUEST_POST('admin_id')), REQUEST_POST('action_menu'), REQUEST_POST('what_menu')), __FILE__, __LINE__);
179 if (SQL_NUMROWS($result) == 0) {
180 // Finally add the new ACL
181 SQL_QUERY_ESC("INSERT INTO `{!_MYSQL_PREFIX!}_admins_acls` (admin_id, action_menu, what_menu, access_mode)
182 VALUES ('%s','%s','%s','%s')",
184 bigintval(REQUEST_POST('admin_id')),
185 REQUEST_POST('action_menu'),
186 REQUEST_POST('what_menu'),
188 ), __FILE__, __LINE__);
189 $content = ADMIN_ADMINS_ACL_SAVED;
191 // Update cache when installed
192 if (EXT_IS_ACTIVE("cache")) {
193 if ($GLOBALS['cache_instance']->loadCacheFile("admins_acls")) $GLOBALS['cache_instance']->destroyCacheFile();
196 CACHE_PURGE_ADMIN_MENU(REQUEST_POST('admin_id'), REQUEST_POST('action_menu'), REQUEST_POST('what_menu'));
199 // ACL does already exist!
200 $content = ADMIN_ADMINS_ACL_ALREADY_ADDED;
204 SQL_FREERESULT($result);
206 // No menu selected makes also no sence...
207 $content = ADMIN_ADMINS_SELECT_ACTION_WHAT;
210 // Same mode makes no sence...
211 $content = ADMIN_ADMINS_SAME_MODE_SELECTED;
215 LOAD_TEMPLATE("admin_settings_saved", false, $content);
218 $result_acls = SQL_QUERY("SELECT id, admin_id, action_menu, what_menu, access_mode FROM `{!_MYSQL_PREFIX!}_admins_acls` ORDER BY admin_id, id", __FILE__, __LINE__);
219 if (SQL_NUMROWS($result_acls) > 0)
223 while (list($id, $admin, $act, $wht, $mode) = SQL_FETCHROW($result_acls))
226 if (empty($act)) $act = "---";
227 if (empty($wht)) $wht = "---";
230 $mode = constant('ADMINS_'.strtoupper($mode).'_MODE');
232 // Prepare data for the row template
236 'admin' => GENERATE_AID_LINK($admin),
242 // Load row template and switch colors
243 $OUT .= LOAD_TEMPLATE("admin_config_admins_row", true, $content);
248 SQL_FREERESULT($result);
249 define('__ACL_ROWS', $OUT);
251 // Load main template
252 LOAD_TEMPLATE("admin_config_admins");
255 // Prepare some constants for the template
256 define('_ADMINS_SELECTION', ADD_OPTION_LINES("admins", "id", "login", "", "default_acl"));
257 define('_ACTION_SELECTION', ADMIN_MENU_SELECTION("action"));
258 define('_WHAT_SELECTION' , ADMIN_MENU_SELECTION("what"));
259 define('_MODE_OPTIONS' , ADD_OPTION_LINES("/ARRAY/", array("allow", "deny"), array(ADMINS_ALLOW_MODE, ADMINS_DENY_MODE)));
261 // Load template for adding new ACL
262 LOAD_TEMPLATE("admin_admins_add_acl");