index.php 791 B

12345678910111213141516171819202122232425262728293031
  1. <?php
  2. $TAB = 'SEARCH';
  3. $_SESSION['back'] = $_SERVER['REQUEST_URI'];
  4. // Main include
  5. include($_SERVER['DOCUMENT_ROOT']."/inc/main.php");
  6. // Check token
  7. verify_csrf($_GET);
  8. // Data
  9. $q = escapeshellarg($_GET['q']);
  10. $u = escapeshellarg($_GET['u']);
  11. if (($_SESSION['userContext'] === 'admin') && (!isset($_SESSION['look']))) {
  12. if (!empty($_GET['u'])) {
  13. $user = $u;
  14. exec(HESTIA_CMD . "v-search-user-object " .$user. " " .$q. " json", $output, $return_var);
  15. } else {
  16. exec(HESTIA_CMD . "v-search-object " .$q. " json", $output, $return_var);
  17. }
  18. } else {
  19. exec(HESTIA_CMD . "v-search-user-object " .$user. " " .$q. " json", $output, $return_var);
  20. }
  21. $data = json_decode(implode('', $output), true);
  22. // Render page
  23. render_page($user, $TAB, 'list_search');