1
0
mirror of https://github.com/e107inc/e107.git synced 2025-01-17 20:58:30 +01:00
php-e107/e107_admin/updateadmin.php

127 lines
3.6 KiB
PHP
Raw Normal View History

2006-12-02 04:36:16 +00:00
<?php
/*
2008-12-15 21:53:17 +00:00
* e107 website system
*
2009-11-18 01:06:08 +00:00
* Copyright (C) 2008-2009 e107 Inc (e107.org)
2008-12-15 21:53:17 +00:00
* Released under the terms and conditions of the
* GNU General Public License (http://www.gnu.org/licenses/gpl.txt)
*
* Administration Area - Update Admin
*
*
2006-12-02 04:36:16 +00:00
*/
2008-12-15 21:53:17 +00:00
require_once(__DIR__.'/../class2.php');
2009-08-28 16:11:02 +00:00
2012-12-15 18:06:55 -08:00
// include_lan(e_LANGUAGEDIR.e_LANGUAGE.'/admin/lan_'.e_PAGE);
e107::lan('core','updateadmin',true);
2009-08-28 16:11:02 +00:00
2006-12-02 04:36:16 +00:00
$e_sub_cat = 'admin_pass';
2008-12-15 21:53:17 +00:00
require_once(e_ADMIN.'auth.php');
// require_once(e_HANDLER.'user_handler.php'); //use e107::getUserSession() instead.
require_once(e_HANDLER.'validator_class.php');
$userMethods = e107::getUserSession();
$mes = e107::getMessage();
2012-11-26 14:41:32 -08:00
$frm = e107::getForm();
if (isset($_POST['update_settings']))
{
if ($_POST['ac'] == md5(ADMINPWCHANGE))
{
$userData = array();
$userData['data'] = array();
if ($_POST['a_password'] != '' && $_POST['a_password2'] != '' && ($_POST['a_password'] == $_POST['a_password2']))
{
$userData['data']['user_password'] = $sql->escape($userMethods->HashPassword($_POST['a_password'], $currentUser['user_loginname']), FALSE);
unset($_POST['a_password']);
unset($_POST['a_password2']);
2017-01-12 18:57:02 -08:00
if (vartrue($pref['allowEmailLogin']))
{
2017-01-12 18:57:02 -08:00
$new_pass = e107::getParser()->filter($_POST['a_password']);
$user_prefs = e107::getArrayStorage()->unserialize($currentUser['user_prefs']);
2017-01-12 18:57:02 -08:00
$user_prefs['email_password'] = $userMethods->HashPassword($new_pass, USEREMAIL);
$userData['data']['user_prefs'] = e107::getArrayStorage()->serialize($user_prefs);
}
$userData['data']['user_pwchange'] = time();
$userData['WHERE'] = 'user_id='.USERID;
validatorClass::addFieldTypes($userMethods->userVettingInfo,$userData, $userMethods->otherFieldTypes);
$check = $sql->update('user',$userData);
2008-12-15 21:53:17 +00:00
if ($check)
{
2021-02-01 18:18:30 -08:00
e107::getLog()->add('ADMINPW_01', '');
$userMethods->makeUserCookie(array('user_id' => USERID,'user_password' => $userData['data']['user_password']), FALSE); // Can't handle autologin ATM
$mes->addSuccess(UDALAN_3." ".ADMINNAME);
2015-02-15 16:07:27 -08:00
e107::getEvent()->trigger('adpword'); //@deprecated
$eventData = array('user_id'=> USERID, 'user_pwchange'=> $userData['data']['user_pwchange']);
e107::getEvent()->trigger('admin_password_update',$eventData );
$ns->tablerender(UDALAN_2, $mes->render());
2008-12-15 21:53:17 +00:00
}
else
{
$mes->addError(UDALAN_1.' '.LAN_UPDATED_FAILED);
$ns->tablerender(LAN_UPDATED_FAILED, $mes->render());
2006-12-02 04:36:16 +00:00
}
2008-12-15 21:53:17 +00:00
}
else
{
$mes->addError(UDALAN_1.' '.LAN_UPDATED_FAILED);
$ns->tablerender(LAN_UPDATED_FAILED, $mes->render());
2006-12-02 04:36:16 +00:00
}
}
2008-12-15 21:53:17 +00:00
}
else
{
$text = "
<form method='post' action='".e_SELF."'>
<fieldset id='core-updateadmin'>
<legend class='e-hideme'>".UDALAN_8." ".ADMINNAME."</legend>
2012-11-26 14:41:32 -08:00
<table class='table adminform'>
2012-05-13 05:50:32 +00:00
<colgroup>
2008-12-15 21:53:17 +00:00
<col class='col-label' />
<col class='col-control' />
</colgroup>
<tbody>
<tr>
2012-11-26 14:41:32 -08:00
<td>".UDALAN_4.":</td>
<td>
2008-12-15 21:53:17 +00:00
".ADMINNAME."
</td>
</tr>
<tr>
<td>".LAN_PASSWORD.":</td>
2012-12-15 18:06:55 -08:00
<td>".$frm->password('a_password','',20,'generate=1&strength=1')."
2008-12-15 21:53:17 +00:00
</td>
</tr>
<tr>
2012-11-26 14:41:32 -08:00
<td>".UDALAN_6.":</td>
<td>
2017-11-17 19:19:35 -08:00
<input class='tbox form-control input-text' type='password' name='a_password2' size='60' value='' maxlength='20' />
2008-12-15 21:53:17 +00:00
</td>
</tr>
</tbody>
</table>
<div class='buttons-bar center'>
<input type='hidden' name='ac' value='".md5(defset('ADMINPWCHANGE'))."' />".
2012-11-26 14:41:32 -08:00
$frm->admin_button('update_settings','no-value','update',UDALAN_7)."
2008-12-15 21:53:17 +00:00
</div>
</fieldset>
2006-12-02 04:36:16 +00:00
</form>
2008-12-15 21:53:17 +00:00
";
2006-12-02 04:36:16 +00:00
$ns->tablerender(UDALAN_8." ".ADMINNAME, $text);
}
2010-07-23 23:21:48 +00:00
require_once(e_ADMIN.'footer.php');
2006-12-02 04:36:16 +00:00