if ($_SESSION['access_level'] == 100) { switch ($id) { case "view": echo '<h2>Podgląd użytkowników</h2>'; print_users_view(); break; case "edituser": echo '<h2>Edycja użytkowników</h2>'; print_editusers_view(); break; case "editsave": update_user(); header("Location: ./index.php?kat=users&id=view"); break; case "newpass": update_userpass(); header("Location: ./index.php?kat=users&id=view"); break; case "add": echo '<h2>Nowy użytkownik</h2>'; print_users_add(); break; case "addusersave": add_user(); header("Location: ./index.php?kat=users&id=view"); break; case "deluser": del_user(); header("Location: ./index.php?kat=users&id=view"); break; }
<?php include "./db_conn.php"; $input = file_get_contents("php://input"); $input = json_decode($input, true); if (strlen($input[2]) < 6) { die("minleng err"); } if (strlen($input[3]) < 6) { die("minleng err"); } sleep(1); $input[2] = myhash($input[2]); $input[3] = myhash($input[3]); if (update_userpass($input)) { die("success"); } else { die("authenticate failed.."); } function myhash($v) { global $salt; return md5($salt . $v); } function get_userdata($userid) { $userid = mysql_real_escape_string($userid); $result = mysql_query("select * from users where userid = '{$userid}'"); $row = mysql_fetch_row($result); return $row; }
$id = $userpass['id']; $username = $userpass['username']; $password = $userpass['password']; //$active = $ym_info['active']; include 'userpass_admin_view.php'; } else { $message = 'There was a retrival error to members database.'; include 'userpass_admin_view.php'; } break; case 'Update Member': $id = $_POST['id']; $username = $_POST['username']; $password = $_POST['password']; // $active = $_POST['active']; $result = update_userpass($id, $username, $password); if ($result) { $message = 'Update Member Successful'; include 'userpass_admin_view.php'; } else { $message = 'There was an update error.'; include 'usernpass_admin_view.php'; } break; case 'Add Member': $username = $_POST['username']; $password = $_POST['password']; $result = add_member($username, $password); if ($result) { $message = '<br/><br/>Add Member Successful'; include 'userpass_admin_view.php';