admin_manage.php 8.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286
  1. <?php
  2. defined('IN_PHPCMS') or exit('No permission resources.');
  3. pc_base::load_app_class('admin','admin',0);
  4. pc_base::load_app_func('admin');
  5. class admin_manage extends admin {
  6. private $db,$role_db;
  7. function __construct() {
  8. parent::__construct();
  9. $this->db = pc_base::load_model('admin_model');
  10. $this->role_db = pc_base::load_model('admin_role_model');
  11. $this->op = pc_base::load_app_class('admin_op');
  12. }
  13. /**
  14. * 管理员管理列表
  15. */
  16. public function init() {
  17. $userid = $_SESSION['userid'];
  18. $admin_username = param::get_cookie('admin_username');
  19. $page = $_GET['page'] ? intval($_GET['page']) : '1';
  20. $infos = $this->db->listinfo('', '', $page, 20);
  21. $pages = $this->db->pages;
  22. $roles = getcache('role','commons');
  23. include $this->admin_tpl('admin_list');
  24. }
  25. /**
  26. * 添加管理员
  27. */
  28. public function add() {
  29. if(isset($_POST['dosubmit'])) {
  30. if($this->check_admin_manage_code()==false){
  31. showmessage("error auth code");
  32. }
  33. $info = array();
  34. if(!$this->op->checkname($_POST['info']['username'])){
  35. showmessage(L('admin_already_exists'));
  36. }
  37. $info = checkuserinfo($_POST['info']);
  38. if(!checkpasswd($info['password'])){
  39. showmessage(L('pwd_incorrect'));
  40. }
  41. $passwordinfo = password($info['password']);
  42. $info['password'] = $passwordinfo['password'];
  43. $info['encrypt'] = $passwordinfo['encrypt'];
  44. $admin_fields = array('username', 'email', 'password', 'encrypt','roleid','realname');
  45. foreach ($info as $k=>$value) {
  46. if (!in_array($k, $admin_fields)){
  47. unset($info[$k]);
  48. }
  49. }
  50. $this->db->insert($info);
  51. if($this->db->insert_id()){
  52. showmessage(L('operation_success'),'?m=admin&c=admin_manage');
  53. }
  54. } else {
  55. $roles = $this->role_db->select(array('disabled'=>'0'));
  56. $admin_manage_code = $this->get_admin_manage_code();
  57. include $this->admin_tpl('admin_add');
  58. }
  59. }
  60. /**
  61. * 修改管理员
  62. */
  63. public function edit() {
  64. if(isset($_POST['dosubmit'])) {
  65. if($this->check_admin_manage_code()==false){
  66. showmessage("error auth code");
  67. }
  68. $memberinfo = $info = array();
  69. $info = checkuserinfo($_POST['info']);
  70. if(isset($info['password']) && !empty($info['password']))
  71. {
  72. $this->op->edit_password($info['userid'], $info['password']);
  73. }
  74. $userid = $info['userid'];
  75. $admin_fields = array('username', 'email', 'roleid','realname');
  76. foreach ($info as $k=>$value) {
  77. if (!in_array($k, $admin_fields)){
  78. unset($info[$k]);
  79. }
  80. }
  81. $this->db->update($info,array('userid'=>$userid));
  82. showmessage(L('operation_success'),'','','edit');
  83. } else {
  84. $info = $this->db->get_one(array('userid'=>$_GET['userid']));
  85. extract($info);
  86. $roles = $this->role_db->select(array('disabled'=>'0'));
  87. $show_header = true;
  88. $admin_manage_code = $this->get_admin_manage_code();
  89. include $this->admin_tpl('admin_edit');
  90. }
  91. }
  92. /**
  93. * 删除管理员
  94. */
  95. public function delete() {
  96. $userid = intval($_GET['userid']);
  97. if($userid == '1') showmessage(L('this_object_not_del'), HTTP_REFERER);
  98. $this->db->delete(array('userid'=>$userid));
  99. showmessage(L('admin_cancel_succ'));
  100. }
  101. /**
  102. * 更新管理员状态
  103. */
  104. public function lock(){
  105. $userid = intval($_GET['userid']);
  106. $disabled = intval($_GET['disabled']);
  107. $this->db->update(array('disabled'=>$disabled),array('userid'=>$userid));
  108. showmessage(L('operation_success'),'?m=admin&c=admin_manage');
  109. }
  110. /**
  111. * 管理员自助修改密码
  112. */
  113. public function public_edit_pwd() {
  114. $userid = $_SESSION['userid'];
  115. if(isset($_POST['dosubmit'])) {
  116. $r = $this->db->get_one(array('userid'=>$userid),'password,encrypt');
  117. if ( password($_POST['old_password'],$r['encrypt']) !== $r['password'] ) showmessage(L('old_password_wrong'),HTTP_REFERER);
  118. if(isset($_POST['new_password']) && !empty($_POST['new_password'])) {
  119. $this->op->edit_password($userid, $_POST['new_password']);
  120. }
  121. showmessage(L('password_edit_succ_logout'),'?m=admin&c=index&a=public_logout');
  122. } else {
  123. $info = $this->db->get_one(array('userid'=>$userid));
  124. extract($info);
  125. include $this->admin_tpl('admin_edit_pwd');
  126. }
  127. }
  128. /*
  129. * 编辑用户信息
  130. */
  131. public function public_edit_info() {
  132. $userid = $_SESSION['userid'];
  133. if(isset($_POST['dosubmit'])) {
  134. $admin_fields = array('email','realname','lang');
  135. $info = array();
  136. $info = $_POST['info'];
  137. if(trim($info['lang'])=='') $info['lang'] = 'zh-cn';
  138. foreach ($info as $k=>$value) {
  139. if (!in_array($k, $admin_fields)){
  140. unset($info[$k]);
  141. }
  142. }
  143. $this->db->update($info,array('userid'=>$userid));
  144. param::set_cookie('sys_lang', $info['lang'],SYS_TIME+86400*30);
  145. showmessage(L('operation_success'),HTTP_REFERER);
  146. } else {
  147. $info = $this->db->get_one(array('userid'=>$userid));
  148. extract($info);
  149. $lang_dirs = glob(PC_PATH.'languages/*');
  150. $dir_array = array();
  151. foreach($lang_dirs as $dirs) {
  152. $dir_array[] = str_replace(PC_PATH.'languages/','',$dirs);
  153. }
  154. include $this->admin_tpl('admin_edit_info');
  155. }
  156. }
  157. /**
  158. * 异步检测用户名
  159. */
  160. function public_checkname_ajx() {
  161. $username = isset($_GET['username']) && trim($_GET['username']) ? trim($_GET['username']) : exit(0);
  162. if ($this->db->get_one(array('username'=>$username),'userid')){
  163. exit('0');
  164. }
  165. exit('1');
  166. }
  167. /**
  168. * 异步检测密码
  169. */
  170. function public_password_ajx() {
  171. $userid = $_SESSION['userid'];
  172. $r = array();
  173. $r = $this->db->get_one(array('userid'=>$userid),'password,encrypt');
  174. if ( password($_GET['old_password'],$r['encrypt']) == $r['password'] ) {
  175. exit('1');
  176. }
  177. exit('0');
  178. }
  179. /**
  180. * 异步检测emial合法性
  181. */
  182. function public_email_ajx() {
  183. $email = $_GET['email'];
  184. $userid = $_SESSION['userid'];
  185. $check = $this->db->get_one(array('email'=>$email),'userid');
  186. if ($check && $check['userid']!=$userid){
  187. exit('0');
  188. }else{
  189. exit('1');
  190. }
  191. }
  192. //电子口令卡
  193. function card() {
  194. if (pc_base::load_config('system', 'safe_card') != 1) {
  195. showmessage(L('your_website_opened_the_card_no_password'));
  196. }
  197. $userid = isset($_GET['userid']) && intval($_GET['userid']) ? intval($_GET['userid']) : showmessage(L('user_id_cannot_be_empty'));
  198. $data = array();
  199. if ($data = $this->db->get_one(array('userid'=>$userid), '`card`,`username`')) {
  200. $pic_url = '';
  201. if ($data['card']) {
  202. pc_base::load_app_class('card', 'admin', 0);
  203. $pic_url = card::get_pic($data['card']);
  204. }
  205. $show_header = true;
  206. include $this->admin_tpl('admin_card');
  207. } else {
  208. showmessage(L('users_were_not_found'));
  209. }
  210. }
  211. //绑定电子口令卡
  212. function creat_card() {
  213. if (pc_base::load_config('system', 'safe_card') != 1) {
  214. showmessage(L('your_website_opened_the_card_no_password'));
  215. }
  216. $userid = isset($_GET['userid']) && intval($_GET['userid']) ? intval($_GET['userid']) : showmessage(L('user_id_cannot_be_empty'));
  217. $data = $card = '';
  218. if ($data = $this->db->get_one(array('userid'=>$userid), '`card`,`username`')) {
  219. if (empty($data['card'])) {
  220. pc_base::load_app_class('card', 'admin', 0);
  221. $card = card::creat_card();
  222. if ($this->db->update(array('card'=>$card), array('userid'=>$userid))) {
  223. showmessage(L('password_card_application_success'), '?m=admin&c=admin_manage&a=card&userid='.$userid);
  224. } else {
  225. showmessage(L('a_card_with_a_local_database_please_contact_the_system_administrators'));
  226. }
  227. } else {
  228. showmessage(L('please_lift_the_password_card_binding'),HTTP_REFERER);
  229. }
  230. } else {
  231. showmessage(L('users_were_not_found'));
  232. }
  233. }
  234. //解除口令卡绑定
  235. function remove_card() {
  236. if (pc_base::load_config('system', 'safe_card') != 1) {
  237. showmessage(L('your_website_opened_the_card_no_password'));
  238. }
  239. $userid = isset($_GET['userid']) && intval($_GET['userid']) ? intval($_GET['userid']) : showmessage(L('user_id_cannot_be_empty'));
  240. $data = $result = '';
  241. if ($data = $this->db->get_one(array('userid'=>$userid), '`card`,`username`,`userid`')) {
  242. pc_base::load_app_class('card', 'admin', 0);
  243. if ($result = card::remove_card($data['card'])) {
  244. $this->db->update(array('card'=>''), array('userid'=>$userid));
  245. showmessage(L('the_binding_success'), '?m=admin&c=admin_manage&a=card&userid='.$userid);
  246. }
  247. } else {
  248. showmessage(L('users_were_not_found'));
  249. }
  250. }
  251. //添加修改用户 验证串验证
  252. private function check_admin_manage_code(){
  253. $admin_manage_code = $_POST['info']['admin_manage_code'];
  254. $pc_auth_key = md5(pc_base::load_config('system','auth_key').'adminuser');
  255. $admin_manage_code = sys_auth($admin_manage_code, 'DECODE', $pc_auth_key);
  256. if($admin_manage_code==""){
  257. return false;
  258. }
  259. $admin_manage_code = explode("_", $admin_manage_code);
  260. if($admin_manage_code[0]!="adminuser" || $admin_manage_code[1]!=$_POST[pc_hash]){
  261. return false;
  262. }
  263. return true;
  264. }
  265. //添加修改用户 生成验证串
  266. private function get_admin_manage_code(){
  267. $pc_auth_key = md5(pc_base::load_config('system','auth_key').'adminuser');
  268. $code = sys_auth("adminuser_".$_GET[pc_hash]."_".time(), 'ENCODE', $pc_auth_key);
  269. return $code;
  270. }
  271. }
  272. ?>