session_start();
if (!session_is_registered("LLC"))
{
// if session check fails, invoke error handler
header("Location: /error.php?e=1");
exit();
}
$user = $_SESSION['UNAME'];
if (!(session_is_registered("SUPER") || session_is_registered("ADMIN")))
{
header("Location: /error.php?e=3");
exit();
}
$type = $_POST['submit'];
$user = $_POST['user'];
$user1 = $_POST['user1'];
$status = $_POST['status'];
if ($status == '2'){$status='0';}
$group = $_POST['group'];
include(dirname(__FILE__)."/llc/includes/dbconfig.php");
$connection = mysql_connect($db_host, $db_user, $db_pass) or die ("Unable to connect!");
mysql_select_db($db_name);
if ($type == 'Update')
{
$query = "UPDATE userlist SET UserName='$user', Status='$status', GroupID='$group' WHERE UserName='$user1'";
$result = mysql_query($query, $connection) or die ("Error in query: $query. " . mysql_error());
header("Location: /llc/login/admin.php");
exit();
}
if ($type == 'Delete')
{
$query = "DELETE FROM userlist WHERE UserName='$user1'";
$result = mysql_query($query, $connection) or die ("Error in query: $query. " . mysql_error());
header("Location: /llc/login/admin.php");
exit();
}
if ($type == 'View')
{
$query = "SELECT FirstName, LastName, Title, Extension, Email, Status, GroupID from userlist WHERE username = '$user'";
$result = mysql_query($query, $connection) or die ("Error in query: $query. " . mysql_error());
if (mysql_num_rows($result) == 1)
{
$row = mysql_fetch_row($result);
$fname = $row[0];
$lname = $row[1];
$title = $row[2];
$ext = $row[3];
$email = $row[4];
$status = $row[5];
if ($status=='1'){$status='Enabled';}else {$status='Disabled';}
$group = $row[6];
if ($group=='U'){$group='User';}
else if ($group=='A'){$group='Administrator';}
else if ($group=='S'){$group='Supervisor';}
else if ($group=='C'){$group='CFS';}
}
}
?>
Language Learning Center -- Confirmation of Computer Service Request
|
|
Admin -- Add User |
|
User Information
|
|
|
|