index.php 5.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183
  1. <?php
  2. // Init
  3. error_reporting(NULL);
  4. ob_start();
  5. session_start();
  6. $TAB = 'USER';
  7. include($_SERVER['DOCUMENT_ROOT']."/inc/main.php");
  8. // Check user argument
  9. if (empty($_GET['user'])) {
  10. header("Location: /list/user/");
  11. exit;
  12. }
  13. // Edit as someone else?
  14. if (($_SESSION['user'] == 'admin') && (!empty($_GET['user']))) {
  15. $user = $_GET['user'];
  16. } else {
  17. $user = $_SESSION['user'];
  18. }
  19. $v_username = $user;
  20. // List user
  21. v_exec('v-list-user', [$v_username, 'json'], true, $output);
  22. $data = json_decode($output, true);
  23. // Parse user
  24. $v_password = '';
  25. $v_email = $data[$v_username]['CONTACT'];
  26. $v_package = $data[$v_username]['PACKAGE'];
  27. $v_language = $data[$v_username]['LANGUAGE'];
  28. $v_fname = $data[$v_username]['FNAME'];
  29. $v_lname = $data[$v_username]['LNAME'];
  30. $v_shell = $data[$v_username]['SHELL'];
  31. $v_ns = $data[$v_username]['NS'];
  32. $nameservers = explode(', ', $v_ns);
  33. $v_ns1 = $nameservers[0];
  34. $v_ns2 = $nameservers[1];
  35. $v_ns3 = $nameservers[2];
  36. $v_ns4 = $nameservers[3];
  37. $v_ns5 = $nameservers[4];
  38. $v_ns6 = $nameservers[5];
  39. $v_ns7 = $nameservers[6];
  40. $v_ns8 = $nameservers[7];
  41. $v_suspended = $data[$v_username]['SUSPENDED'];
  42. if ( $v_suspended == 'yes' ) {
  43. $v_status = 'suspended';
  44. } else {
  45. $v_status = 'active';
  46. }
  47. $v_time = $data[$v_username]['TIME'];
  48. $v_date = $data[$v_username]['DATE'];
  49. // List packages
  50. v_exec('v-list-user-packages', ['json'], false, $output);
  51. $packages = json_decode($output, true);
  52. // List languages
  53. v_exec('v-list-sys-languages', ['json'], false, $output);
  54. $languages = json_decode($output, true);
  55. // List shells
  56. v_exec('v-list-sys-shells', ['json'], false, $output);
  57. $shells = json_decode($output, true);
  58. // Are you admin?
  59. // Check POST request
  60. if (!empty($_POST['save'])) {
  61. // Check token
  62. if ((!isset($_POST['token'])) || ($_SESSION['token'] != $_POST['token'])) {
  63. header('location: /login/');
  64. exit;
  65. }
  66. // Change password
  67. if ((!empty($_POST['v_password'])) && (empty($_SESSION['error_msg']))) {
  68. $v_password = tempnam("/tmp","vst");
  69. $fp = fopen($v_password, "w");
  70. fwrite($fp, $_POST['v_password']."\n");
  71. fclose($fp);
  72. v_exec('v-change-user-password', [$v_username, $v_password]);
  73. unlink($v_password);
  74. $v_password = $_POST['v_password'];
  75. }
  76. // Change package (admin only)
  77. if (($v_package != $_POST['v_package']) && ($_SESSION['user'] == 'admin') && (empty($_SESSION['error_msg']))) {
  78. $v_package = $_POST['v_package'];
  79. v_exec('v-change-user-package', [$v_username, $v_package]);
  80. }
  81. // Change language
  82. if (($v_language != $_POST['v_language']) && (empty($_SESSION['error_msg']))) {
  83. $v_language = $_POST['v_language'];
  84. v_exec('v-change-user-language', [$v_username, $v_language]);
  85. if (empty($_SESSION['error_msg'])) {
  86. if ((empty($_GET['user'])) || ($_GET['user'] == $_SESSION['user'])) {
  87. $_SESSION['language'] = $_POST['v_language'];
  88. }
  89. }
  90. }
  91. // Change shell (admin only)
  92. if ($_SESSION['user'] == 'admin') {
  93. if (($v_shell != $_POST['v_shell']) && (empty($_SESSION['error_msg']))) {
  94. $v_shell = $_POST['v_shell'];
  95. v_exec('v-change-user-shell', [$v_username, $v_shell]);
  96. }
  97. }
  98. // Change contact email
  99. if (($v_email != $_POST['v_email']) && (empty($_SESSION['error_msg']))) {
  100. if (!filter_var($_POST['v_email'], FILTER_VALIDATE_EMAIL)) {
  101. $_SESSION['error_msg'] = __('Please enter valid email address.');
  102. } else {
  103. $v_email = $_POST['v_email'];
  104. v_exec('v-change-user-contact', [$v_username, $v_email]);
  105. }
  106. }
  107. // Change full name
  108. if ((($v_fname != $_POST['v_fname']) || ($v_lname != $_POST['v_lname'])) && (empty($_SESSION['error_msg']))) {
  109. $v_fname = $_POST['v_fname'];
  110. $v_lname = $_POST['v_lname'];
  111. v_exec('v-change-user-name', [$v_username, $v_fname, $v_lname]);
  112. }
  113. // Change NameServers
  114. if ((($v_ns1 != $_POST['v_ns1']) || ($v_ns2 != $_POST['v_ns2']) || ($v_ns3 != $_POST['v_ns3']) || ($v_ns4 != $_POST['v_ns4']) || ($v_ns5 != $_POST['v_ns5'])
  115. || ($v_ns6 != $_POST['v_ns6']) || ($v_ns7 != $_POST['v_ns7']) || ($v_ns8 != $_POST['v_ns8'])) && (empty($_SESSION['error_msg']))) {
  116. $v_ns1 = $_POST['v_ns1'];
  117. $v_ns2 = $_POST['v_ns2'];
  118. $v_ns3 = $_POST['v_ns3'];
  119. $v_ns4 = $_POST['v_ns4'];
  120. $v_ns5 = $_POST['v_ns5'];
  121. $v_ns6 = $_POST['v_ns6'];
  122. $v_ns7 = $_POST['v_ns7'];
  123. $v_ns8 = $_POST['v_ns8'];
  124. $ns_args = [$v_username, $v_ns1, $v_ns2];
  125. if (!empty($_POST['v_ns3'])) $ns_args[] = $v_ns3;
  126. if (!empty($_POST['v_ns4'])) $ns_args[] = $v_ns4;
  127. if (!empty($_POST['v_ns5'])) $ns_args[] = $v_ns5;
  128. if (!empty($_POST['v_ns6'])) $ns_args[] = $v_ns6;
  129. if (!empty($_POST['v_ns7'])) $ns_args[] = $v_ns7;
  130. if (!empty($_POST['v_ns8'])) $ns_args[] = $v_ns8;
  131. v_exec('v-change-user-ns', $ns_args);
  132. }
  133. // Set success message
  134. if (empty($_SESSION['error_msg'])) {
  135. $_SESSION['ok_msg'] = __('Changes has been saved.');
  136. }
  137. }
  138. // Header
  139. include($_SERVER['DOCUMENT_ROOT'].'/templates/header.html');
  140. // Panel
  141. if (!empty($_SESSION['look'])) {
  142. top_panel($user,$TAB);
  143. } else {
  144. top_panel($_SESSION['user'],$TAB);
  145. }
  146. // Display body
  147. if ($_SESSION['user'] == 'admin') {
  148. include($_SERVER['DOCUMENT_ROOT'].'/templates/admin/edit_user.html');
  149. } else {
  150. include($_SERVER['DOCUMENT_ROOT'].'/templates/user/edit_user.html');
  151. }
  152. // Flush session messages
  153. unset($_SESSION['error_msg']);
  154. unset($_SESSION['ok_msg']);
  155. // Footer
  156. include($_SERVER['DOCUMENT_ROOT'].'/templates/footer.html');