2 /***************************************************************************
5 * begin : Saturday, Feb 13, 2001
6 * copyright : (C) 2001 The phpBB Group
7 * email : support@phpbb.com
9 * $Id: admin_ug_auth.php,v 1.13.2.5 2004/03/25 15:57:20 acydburn Exp $
12 ***************************************************************************/
14 /***************************************************************************
16 * This program is free software; you can redistribute it and/or modify
17 * it under the terms of the GNU General Public License as published by
18 * the Free Software Foundation; either version 2 of the License, or
19 * (at your option) any later version.
21 ***************************************************************************/
23 define('IN_PHPBB', 1);
25 if( !empty($setmodules) )
27 $filename = basename(__FILE__);
28 $module['Users']['Permissions'] = $filename . "?mode=user";
29 $module['Groups']['Permissions'] = $filename . "?mode=group";
35 // Load default header
37 $no_page_header = TRUE;
39 $phpbb_root_path = "./../";
40 require($phpbb_root_path . 'extension.inc');
41 require('./pagestart.' . $phpEx);
43 $params = array('mode' => 'mode', 'user_id' => POST_USERS_URL, 'group_id' => POST_GROUPS_URL, 'adv' => 'adv');
45 while( list($var, $param) = @each($params) )
47 if ( !empty($HTTP_POST_VARS[$param]) || !empty($HTTP_GET_VARS[$param]) )
49 $$var = ( !empty($HTTP_POST_VARS[$param]) ) ? $HTTP_POST_VARS[$param] : $HTTP_GET_VARS[$param];
57 $user_id = intval($user_id);
58 $group_id = intval($group_id);
60 $mode = htmlspecialchars($mode);
63 // Start program - define vars
65 $forum_auth_fields = array('auth_view', 'auth_read', 'auth_post', 'auth_reply', 'auth_edit', 'auth_delete', 'auth_sticky', 'auth_announce', 'auth_vote', 'auth_pollcreate');
67 $auth_field_match = array(
68 'auth_view' => AUTH_VIEW,
69 'auth_read' => AUTH_READ,
70 'auth_post' => AUTH_POST,
71 'auth_reply' => AUTH_REPLY,
72 'auth_edit' => AUTH_EDIT,
73 'auth_delete' => AUTH_DELETE,
74 'auth_sticky' => AUTH_STICKY,
75 'auth_announce' => AUTH_ANNOUNCE,
76 'auth_vote' => AUTH_VOTE,
77 'auth_pollcreate' => AUTH_POLLCREATE);
80 'auth_view' => $lang['View'],
81 'auth_read' => $lang['Read'],
82 'auth_post' => $lang['Post'],
83 'auth_reply' => $lang['Reply'],
84 'auth_edit' => $lang['Edit'],
85 'auth_delete' => $lang['Delete'],
86 'auth_sticky' => $lang['Sticky'],
87 'auth_announce' => $lang['Announce'],
88 'auth_vote' => $lang['Vote'],
89 'auth_pollcreate' => $lang['Pollcreate']);
94 function check_auth($type, $key, $u_access, $is_admin)
98 if( count($u_access) )
100 for($j = 0; $j < count($u_access); $j++)
106 $result = $u_access[$j][$key];
109 $result = $result || $u_access[$j]['auth_mod'];
112 $result = $result || $is_admin;
116 $auth_user = $auth_user || $result;
121 $auth_user = $is_admin;
130 if ( isset($HTTP_POST_VARS['submit']) && ( ( $mode == 'user' && $user_id ) || ( $mode == 'group' && $group_id ) ) )
133 if ( $mode == 'user' )
136 // Get group_id for this user_id
138 $sql = "SELECT g.group_id, u.user_level
139 FROM " . USER_GROUP_TABLE . " ug, " . USERS_TABLE . " u, " . GROUPS_TABLE . " g
140 WHERE u.user_id = $user_id
141 AND ug.user_id = u.user_id
142 AND g.group_id = ug.group_id
143 AND g.group_single_user = " . TRUE;
144 if ( !($result = $db->sql_query($sql)) )
146 message_die(GENERAL_ERROR, 'Could not select info from user/user_group table', '', __LINE__, __FILE__, $sql);
149 $row = $db->sql_fetchrow($result);
151 $group_id = $row['group_id'];
152 $user_level = $row['user_level'];
154 $db->sql_freeresult($result);
158 // Carry out requests
160 if ( $mode == 'user' && $HTTP_POST_VARS['userlevel'] == 'admin' && $user_level != ADMIN )
163 // Make user an admin (if already user)
165 if ( $userdata['user_id'] != $user_id )
167 $sql = "UPDATE " . USERS_TABLE . "
168 SET user_level = " . ADMIN . "
169 WHERE user_id = $user_id";
170 if ( !($result = $db->sql_query($sql)) )
172 message_die(GENERAL_ERROR, 'Could not update user level', '', __LINE__, __FILE__, $sql);
175 $sql = "DELETE FROM " . AUTH_ACCESS_TABLE . "
176 WHERE group_id = $group_id
178 if ( !($result = $db->sql_query($sql)) )
180 message_die(GENERAL_ERROR, "Couldn't delete auth access info", "", __LINE__, __FILE__, $sql);
184 // Delete any entries in auth_access, they are not required if user is becoming an
187 $sql = "UPDATE " . AUTH_ACCESS_TABLE . "
188 SET auth_view = 0, auth_read = 0, auth_post = 0, auth_reply = 0, auth_edit = 0, auth_delete = 0, auth_sticky = 0, auth_announce = 0
189 WHERE group_id = $group_id";
190 if ( !($result = $db->sql_query($sql)) )
192 message_die(GENERAL_ERROR, "Couldn't update auth access", "", __LINE__, __FILE__, $sql);
196 $message = $lang['Auth_updated'] . '<br /><br />' . sprintf($lang['Click_return_userauth'], '<a href="' . append_sid("admin_ug_auth.$phpEx?mode=$mode") . '">', '</a>') . '<br /><br />' . sprintf($lang['Click_return_admin_index'], '<a href="' . append_sid("index.$phpEx?pane=right") . '">', '</a>');
197 message_die(GENERAL_MESSAGE, $message);
201 if ( $mode == 'user' && $HTTP_POST_VARS['userlevel'] == 'user' && $user_level == ADMIN )
204 // Make admin a user (if already admin) ... ignore if you're trying
205 // to change yourself from an admin to user!
207 if ( $userdata['user_id'] != $user_id )
209 $sql = "UPDATE " . AUTH_ACCESS_TABLE . "
210 SET auth_view = 0, auth_read = 0, auth_post = 0, auth_reply = 0, auth_edit = 0, auth_delete = 0, auth_sticky = 0, auth_announce = 0
211 WHERE group_id = $group_id";
212 if ( !($result = $db->sql_query($sql)) )
214 message_die(GENERAL_ERROR, 'Could not update auth access', '', __LINE__, __FILE__, $sql);
218 // Update users level, reset to USER
220 $sql = "UPDATE " . USERS_TABLE . "
221 SET user_level = " . USER . "
222 WHERE user_id = $user_id";
223 if ( !($result = $db->sql_query($sql)) )
225 message_die(GENERAL_ERROR, 'Could not update user level', '', __LINE__, __FILE__, $sql);
229 $message = $lang['Auth_updated'] . '<br /><br />' . sprintf($lang['Click_return_userauth'], '<a href="' . append_sid("admin_ug_auth.$phpEx?mode=$mode") . '">', '</a>') . '<br /><br />' . sprintf($lang['Click_return_admin_index'], '<a href="' . append_sid("index.$phpEx?pane=right") . '">', '</a>');
234 $change_mod_list = ( isset($HTTP_POST_VARS['moderator']) ) ? $HTTP_POST_VARS['moderator'] : false;
238 $change_acl_list = ( isset($HTTP_POST_VARS['private']) ) ? $HTTP_POST_VARS['private'] : false;
242 $change_acl_list = array();
243 for($j = 0; $j < count($forum_auth_fields); $j++)
245 $auth_field = $forum_auth_fields[$j];
247 while( list($forum_id, $value) = @each($HTTP_POST_VARS['private_' . $auth_field]) )
249 $change_acl_list[$forum_id][$auth_field] = $value;
255 FROM " . FORUMS_TABLE . " f
256 ORDER BY forum_order";
257 if ( !($result = $db->sql_query($sql)) )
259 message_die(GENERAL_ERROR, "Couldn't obtain forum information", "", __LINE__, __FILE__, $sql);
262 $forum_access = array();
263 while( $row = $db->sql_fetchrow($result) )
265 $forum_access[] = $row;
267 $db->sql_freeresult($result);
269 $sql = ( $mode == 'user' ) ? "SELECT aa.* FROM " . AUTH_ACCESS_TABLE . " aa, " . USER_GROUP_TABLE . " ug, " . GROUPS_TABLE. " g WHERE ug.user_id = $user_id AND g.group_id = ug.group_id AND aa.group_id = ug.group_id AND g.group_single_user = " . TRUE : "SELECT * FROM " . AUTH_ACCESS_TABLE . " WHERE group_id = $group_id";
270 if ( !($result = $db->sql_query($sql)) )
272 message_die(GENERAL_ERROR, "Couldn't obtain user/group permissions", "", __LINE__, __FILE__, $sql);
275 $auth_access = array();
276 while( $row = $db->sql_fetchrow($result) )
278 $auth_access[$row['forum_id']] = $row;
280 $db->sql_freeresult($result);
282 $forum_auth_action = array();
283 $update_acl_status = array();
284 $update_mod_status = array();
286 for($i = 0; $i < count($forum_access); $i++)
288 $forum_id = $forum_access[$i]['forum_id'];
291 ( isset($auth_access[$forum_id]['auth_mod']) && $change_mod_list[$forum_id]['auth_mod'] != $auth_access[$forum_id]['auth_mod'] ) ||
292 ( !isset($auth_access[$forum_id]['auth_mod']) && !empty($change_mod_list[$forum_id]['auth_mod']) )
295 $update_mod_status[$forum_id] = $change_mod_list[$forum_id]['auth_mod'];
297 if ( !$update_mod_status[$forum_id] )
299 $forum_auth_action[$forum_id] = 'delete';
301 else if ( !isset($auth_access[$forum_id]['auth_mod']) )
303 $forum_auth_action[$forum_id] = 'insert';
307 $forum_auth_action[$forum_id] = 'update';
311 for($j = 0; $j < count($forum_auth_fields); $j++)
313 $auth_field = $forum_auth_fields[$j];
315 if( $forum_access[$i][$auth_field] == AUTH_ACL && isset($change_acl_list[$forum_id][$auth_field]) )
317 if ( ( empty($auth_access[$forum_id]['auth_mod']) &&
318 ( isset($auth_access[$forum_id][$auth_field]) && $change_acl_list[$forum_id][$auth_field] != $auth_access[$forum_id][$auth_field] ) ||
319 ( !isset($auth_access[$forum_id][$auth_field]) && !empty($change_acl_list[$forum_id][$auth_field]) ) ) ||
320 !empty($update_mod_status[$forum_id])
323 $update_acl_status[$forum_id][$auth_field] = ( !empty($update_mod_status[$forum_id]) ) ? 0 : $change_acl_list[$forum_id][$auth_field];
325 if ( isset($auth_access[$forum_id][$auth_field]) && empty($update_acl_status[$forum_id][$auth_field]) && $forum_auth_action[$forum_id] != 'insert' && $forum_auth_action[$forum_id] != 'update' )
327 $forum_auth_action[$forum_id] = 'delete';
329 else if ( !isset($auth_access[$forum_id][$auth_field]) && !( $forum_auth_action[$forum_id] == 'delete' && empty($update_acl_status[$forum_id][$auth_field]) ) )
331 $forum_auth_action[$forum_id] = 'insert';
333 else if ( isset($auth_access[$forum_id][$auth_field]) && !empty($update_acl_status[$forum_id][$auth_field]) )
335 $forum_auth_action[$forum_id] = 'update';
338 else if ( ( empty($auth_access[$forum_id]['auth_mod']) &&
339 ( isset($auth_access[$forum_id][$auth_field]) && $change_acl_list[$forum_id][$auth_field] == $auth_access[$forum_id][$auth_field] ) ) && $forum_auth_action[$forum_id] == 'delete' )
341 $forum_auth_action[$forum_id] = 'update';
348 // Checks complete, make updates to DB
351 while( list($forum_id, $action) = @each($forum_auth_action) )
353 if ( $action == 'delete' )
355 $delete_sql .= ( ( $delete_sql != '' ) ? ', ' : '' ) . $forum_id;
359 if ( $action == 'insert' )
363 while ( list($auth_type, $value) = @each($update_acl_status[$forum_id]) )
365 $sql_field .= ( ( $sql_field != '' ) ? ', ' : '' ) . $auth_type;
366 $sql_value .= ( ( $sql_value != '' ) ? ', ' : '' ) . $value;
368 $sql_field .= ( ( $sql_field != '' ) ? ', ' : '' ) . 'auth_mod';
369 $sql_value .= ( ( $sql_value != '' ) ? ', ' : '' ) . ( ( !isset($update_mod_status[$forum_id]) ) ? 0 : $update_mod_status[$forum_id]);
371 $sql = "INSERT INTO " . AUTH_ACCESS_TABLE . " (forum_id, group_id, $sql_field)
372 VALUES ($forum_id, $group_id, $sql_value)";
377 while ( list($auth_type, $value) = @each($update_acl_status[$forum_id]) )
379 $sql_values .= ( ( $sql_values != '' ) ? ', ' : '' ) . $auth_type . ' = ' . $value;
381 $sql_values .= ( ( $sql_values != '' ) ? ', ' : '' ) . 'auth_mod = ' . ( ( !isset($update_mod_status[$forum_id]) ) ? 0 : $update_mod_status[$forum_id]);
383 $sql = "UPDATE " . AUTH_ACCESS_TABLE . "
385 WHERE group_id = $group_id
386 AND forum_id = $forum_id";
388 if( !($result = $db->sql_query($sql)) )
390 message_die(GENERAL_ERROR, "Couldn't update private forum permissions", "", __LINE__, __FILE__, $sql);
395 if ( $delete_sql != '' )
397 $sql = "DELETE FROM " . AUTH_ACCESS_TABLE . "
398 WHERE group_id = $group_id
399 AND forum_id IN ($delete_sql)";
400 if( !($result = $db->sql_query($sql)) )
402 message_die(GENERAL_ERROR, "Couldn't delete permission entries", "", __LINE__, __FILE__, $sql);
406 $l_auth_return = ( $mode == 'user' ) ? $lang['Click_return_userauth'] : $lang['Click_return_groupauth'];
407 $message = $lang['Auth_updated'] . '<br /><br />' . sprintf($l_auth_return, '<a href="' . append_sid("admin_ug_auth.$phpEx?mode=$mode") . '">', '</a>') . '<br /><br />' . sprintf($lang['Click_return_admin_index'], '<a href="' . append_sid("index.$phpEx?pane=right") . '">', '</a>');
411 // Update user level to mod for appropriate users
413 $sql = "SELECT u.user_id
414 FROM " . AUTH_ACCESS_TABLE . " aa, " . USER_GROUP_TABLE . " ug, " . USERS_TABLE . " u
415 WHERE ug.group_id = aa.group_id
416 AND u.user_id = ug.user_id
417 AND u.user_level NOT IN (" . MOD . ", " . ADMIN . ")
419 HAVING SUM(aa.auth_mod) > 0";
420 if ( !($result = $db->sql_query($sql)) )
422 message_die(GENERAL_ERROR, "Couldn't obtain user/group permissions", "", __LINE__, __FILE__, $sql);
426 while( $row = $db->sql_fetchrow($result) )
428 $set_mod .= ( ( $set_mod != '' ) ? ', ' : '' ) . $row['user_id'];
430 $db->sql_freeresult($result);
433 // Update user level to user for appropriate users
438 $sql = "SELECT u.user_id
439 FROM " . USERS_TABLE . " u, " . USER_GROUP_TABLE . " ug, " . AUTH_ACCESS_TABLE . " aa
440 WHERE ug.user_id = u.user_id
441 AND aa.group_id = ug.group_id
442 AND u.user_level NOT IN (" . USER . ", " . ADMIN . ")
444 HAVING SUM(aa.auth_mod) = 0
447 FROM " . USERS_TABLE . " u
450 FROM " . USER_GROUP_TABLE . " ug, " . AUTH_ACCESS_TABLE . " aa
451 WHERE ug.user_id = u.user_id
452 AND aa.group_id = ug.group_id
454 AND u.user_level NOT IN (" . USER . ", " . ADMIN . ")
459 $sql = "SELECT u.user_id
460 FROM " . USERS_TABLE . " u, " . USER_GROUP_TABLE . " ug, " . AUTH_ACCESS_TABLE . " aa
461 WHERE ug.user_id = u.user_id(+)
462 AND aa.group_id = ug.group_id(+)
463 AND u.user_level NOT IN (" . USER . ", " . ADMIN . ")
465 HAVING SUM(aa.auth_mod) = 0";
468 $sql = "SELECT u.user_id
469 FROM ( ( " . USERS_TABLE . " u
470 LEFT JOIN " . USER_GROUP_TABLE . " ug ON ug.user_id = u.user_id )
471 LEFT JOIN " . AUTH_ACCESS_TABLE . " aa ON aa.group_id = ug.group_id )
472 WHERE u.user_level NOT IN (" . USER . ", " . ADMIN . ")
474 HAVING SUM(aa.auth_mod) = 0";
477 if ( !($result = $db->sql_query($sql)) )
479 message_die(GENERAL_ERROR, "Couldn't obtain user/group permissions", "", __LINE__, __FILE__, $sql);
483 while( $row = $db->sql_fetchrow($result) )
485 $unset_mod .= ( ( $unset_mod != '' ) ? ', ' : '' ) . $row['user_id'];
487 $db->sql_freeresult($result);
489 if ( $set_mod != '' )
491 $sql = "UPDATE " . USERS_TABLE . "
492 SET user_level = " . MOD . "
493 WHERE user_id IN ($set_mod)";
494 if( !($result = $db->sql_query($sql)) )
496 message_die(GENERAL_ERROR, "Couldn't update user level", "", __LINE__, __FILE__, $sql);
500 if ( $unset_mod != '' )
502 $sql = "UPDATE " . USERS_TABLE . "
503 SET user_level = " . USER . "
504 WHERE user_id IN ($unset_mod)";
505 if( !($result = $db->sql_query($sql)) )
507 message_die(GENERAL_ERROR, "Couldn't update user level", "", __LINE__, __FILE__, $sql);
511 message_die(GENERAL_MESSAGE, $message);
514 else if ( ( $mode == 'user' && ( isset($HTTP_POST_VARS['username']) || $user_id ) ) || ( $mode == 'group' && $group_id ) )
516 if ( isset($HTTP_POST_VARS['username']) )
518 $this_userdata = get_userdata($HTTP_POST_VARS['username'], true);
519 if ( !is_array($this_userdata) )
521 message_die(GENERAL_MESSAGE, $lang['No_such_user']);
523 $user_id = $this_userdata['user_id'];
530 FROM " . FORUMS_TABLE . " f
531 ORDER BY forum_order";
532 if ( !($result = $db->sql_query($sql)) )
534 message_die(GENERAL_ERROR, "Couldn't obtain forum information", "", __LINE__, __FILE__, $sql);
537 $forum_access = array();
538 while( $row = $db->sql_fetchrow($result) )
540 $forum_access[] = $row;
542 $db->sql_freeresult($result);
546 for($i = 0; $i < count($forum_access); $i++)
548 $forum_id = $forum_access[$i]['forum_id'];
550 $forum_auth_level[$forum_id] = AUTH_ALL;
552 for($j = 0; $j < count($forum_auth_fields); $j++)
554 $forum_access[$i][$forum_auth_fields[$j]] . ' :: ';
555 if ( $forum_access[$i][$forum_auth_fields[$j]] == AUTH_ACL )
557 $forum_auth_level[$forum_id] = AUTH_ACL;
558 $forum_auth_level_fields[$forum_id][] = $forum_auth_fields[$j];
564 $sql = "SELECT u.user_id, u.username, u.user_level, g.group_id, g.group_name, g.group_single_user FROM " . USERS_TABLE . " u, " . GROUPS_TABLE . " g, " . USER_GROUP_TABLE . " ug WHERE ";
565 $sql .= ( $mode == 'user' ) ? "u.user_id = $user_id AND ug.user_id = u.user_id AND g.group_id = ug.group_id" : "g.group_id = $group_id AND ug.group_id = g.group_id AND u.user_id = ug.user_id";
566 if ( !($result = $db->sql_query($sql)) )
568 message_die(GENERAL_ERROR, "Couldn't obtain user/group information", "", __LINE__, __FILE__, $sql);
571 while( $row = $db->sql_fetchrow($result) )
575 $db->sql_freeresult($result);
577 $sql = ( $mode == 'user' ) ? "SELECT aa.*, g.group_single_user FROM " . AUTH_ACCESS_TABLE . " aa, " . USER_GROUP_TABLE . " ug, " . GROUPS_TABLE. " g WHERE ug.user_id = $user_id AND g.group_id = ug.group_id AND aa.group_id = ug.group_id AND g.group_single_user = 1" : "SELECT * FROM " . AUTH_ACCESS_TABLE . " WHERE group_id = $group_id";
578 if ( !($result = $db->sql_query($sql)) )
580 message_die(GENERAL_ERROR, "Couldn't obtain user/group permissions", "", __LINE__, __FILE__, $sql);
583 $auth_access = array();
584 $auth_access_count = array();
585 while( $row = $db->sql_fetchrow($result) )
587 $auth_access[$row['forum_id']][] = $row;
588 $auth_access_count[$row['forum_id']]++;
590 $db->sql_freeresult($result);
592 $is_admin = ( $mode == 'user' ) ? ( ( $ug_info[0]['user_level'] == ADMIN && $ug_info[0]['user_id'] != ANONYMOUS ) ? 1 : 0 ) : 0;
594 for($i = 0; $i < count($forum_access); $i++)
596 $forum_id = $forum_access[$i]['forum_id'];
598 unset($prev_acl_setting);
599 for($j = 0; $j < count($forum_auth_fields); $j++)
601 $key = $forum_auth_fields[$j];
602 $value = $forum_access[$i][$key];
608 $auth_ug[$forum_id][$key] = 1;
612 $auth_ug[$forum_id][$key] = ( !empty($auth_access_count[$forum_id]) ) ? check_auth(AUTH_ACL, $key, $auth_access[$forum_id], $is_admin) : 0;
613 $auth_field_acl[$forum_id][$key] = $auth_ug[$forum_id][$key];
615 if ( isset($prev_acl_setting) )
617 if ( $prev_acl_setting != $auth_ug[$forum_id][$key] && empty($adv) )
623 $prev_acl_setting = $auth_ug[$forum_id][$key];
628 $auth_ug[$forum_id][$key] = ( !empty($auth_access_count[$forum_id]) ) ? check_auth(AUTH_MOD, $key, $auth_access[$forum_id], $is_admin) : 0;
632 $auth_ug[$forum_id][$key] = $is_admin;
636 $auth_ug[$forum_id][$key] = 0;
642 // Is user a moderator?
644 $auth_ug[$forum_id]['auth_mod'] = ( !empty($auth_access_count[$forum_id]) ) ? check_auth(AUTH_MOD, 'auth_mod', $auth_access[$forum_id], 0) : 0;
649 while( list($forum_id, $user_ary) = @each($auth_ug) )
653 if ( $forum_auth_level[$forum_id] == AUTH_ACL )
657 for($j = 0; $j < count($forum_auth_level_fields[$forum_id]); $j++)
659 if ( !$auth_ug[$forum_id][$forum_auth_level_fields[$forum_id][$j]] )
665 $optionlist_acl = '<select name="private[' . $forum_id . ']">';
667 if ( $is_admin || $user_ary['auth_mod'] )
669 $optionlist_acl .= '<option value="1">' . $lang['Allowed_Access'] . '</option>';
673 $optionlist_acl .= '<option value="1" selected="selected">' . $lang['Allowed_Access'] . '</option><option value="0">'. $lang['Disallowed_Access'] . '</option>';
677 $optionlist_acl .= '<option value="1">' . $lang['Allowed_Access'] . '</option><option value="0" selected="selected">' . $lang['Disallowed_Access'] . '</option>';
680 $optionlist_acl .= '</select>';
684 $optionlist_acl = ' ';
689 for($j = 0; $j < count($forum_access); $j++)
691 if ( $forum_access[$j]['forum_id'] == $forum_id )
693 for($k = 0; $k < count($forum_auth_fields); $k++)
695 $field_name = $forum_auth_fields[$k];
697 if( $forum_access[$j][$field_name] == AUTH_ACL )
699 $optionlist_acl_adv[$forum_id][$k] = '<select name="private_' . $field_name . '[' . $forum_id . ']">';
701 if( isset($auth_field_acl[$forum_id][$field_name]) && !($is_admin || $user_ary['auth_mod']) )
703 if( !$auth_field_acl[$forum_id][$field_name] )
705 $optionlist_acl_adv[$forum_id][$k] .= '<option value="1">' . $lang['ON'] . '</option><option value="0" selected="selected">' . $lang['OFF'] . '</option>';
709 $optionlist_acl_adv[$forum_id][$k] .= '<option value="1" selected="selected">' . $lang['ON'] . '</option><option value="0">' . $lang['OFF'] . '</option>';
714 if( $is_admin || $user_ary['auth_mod'] )
716 $optionlist_acl_adv[$forum_id][$k] .= '<option value="1">' . $lang['ON'] . '</option>';
720 $optionlist_acl_adv[$forum_id][$k] .= '<option value="1">' . $lang['ON'] . '</option><option value="0" selected="selected">' . $lang['OFF'] . '</option>';
724 $optionlist_acl_adv[$forum_id][$k] .= '</select>';
732 $optionlist_mod = '<select name="moderator[' . $forum_id . ']">';
733 $optionlist_mod .= ( $user_ary['auth_mod'] ) ? '<option value="1" selected="selected">' . $lang['Is_Moderator'] . '</option><option value="0">' . $lang['Not_Moderator'] . '</option>' : '<option value="1">' . $lang['Is_Moderator'] . '</option><option value="0" selected="selected">' . $lang['Not_Moderator'] . '</option>';
734 $optionlist_mod .= '</select>';
736 $row_class = ( !( $i % 2 ) ) ? 'row2' : 'row1';
737 $row_color = ( !( $i % 2 ) ) ? $theme['td_color1'] : $theme['td_color2'];
739 $template->assign_block_vars('forums', array(
740 'ROW_COLOR' => '#' . $row_color,
741 'ROW_CLASS' => $row_class,
742 'FORUM_NAME' => $forum_access[$i]['forum_name'],
744 'U_FORUM_AUTH' => append_sid("admin_forumauth.$phpEx?f=" . $forum_access[$i]['forum_id']),
746 'S_MOD_SELECT' => $optionlist_mod)
751 $template->assign_block_vars('forums.aclvalues', array(
752 'S_ACL_SELECT' => $optionlist_acl)
757 for($j = 0; $j < count($forum_auth_fields); $j++)
759 $template->assign_block_vars('forums.aclvalues', array(
760 'S_ACL_SELECT' => $optionlist_acl_adv[$forum_id][$j])
769 if ( $mode == 'user' )
771 $t_username = $ug_info[0]['username'];
772 $s_user_type = ( $is_admin ) ? '<select name="userlevel"><option value="admin" selected="selected">' . $lang['Auth_Admin'] . '</option><option value="user">' . $lang['Auth_User'] . '</option></select>' : '<select name="userlevel"><option value="admin">' . $lang['Auth_Admin'] . '</option><option value="user" selected="selected">' . $lang['Auth_User'] . '</option></select>';
776 $t_groupname = $ug_info[0]['group_name'];
781 for($i = 0; $i < count($ug_info); $i++)
783 if( ( $mode == 'user' && !$ug_info[$i]['group_single_user'] ) || $mode == 'group' )
785 $name[] = ( $mode == 'user' ) ? $ug_info[$i]['group_name'] : $ug_info[$i]['username'];
786 $id[] = ( $mode == 'user' ) ? intval($ug_info[$i]['group_id']) : intval($ug_info[$i]['user_id']);
792 $t_usergroup_list = '';
793 for($i = 0; $i < count($ug_info); $i++)
795 $ug = ( $mode == 'user' ) ? 'group&' . POST_GROUPS_URL : 'user&' . POST_USERS_URL;
797 $t_usergroup_list .= ( ( $t_usergroup_list != '' ) ? ', ' : '' ) . '<a href="' . append_sid("admin_ug_auth.$phpEx?mode=$ug=" . $id[$i]) . '">' . $name[$i] . '</a>';
802 $t_usergroup_list = $lang['None'];
805 $s_column_span = 2; // Two columns always present
808 $template->assign_block_vars('acltype', array(
809 'L_UG_ACL_TYPE' => $lang['Simple_Permission'])
815 for($i = 0; $i < count($forum_auth_fields); $i++)
817 $cell_title = $field_names[$forum_auth_fields[$i]];
819 $template->assign_block_vars('acltype', array(
820 'L_UG_ACL_TYPE' => $cell_title)
827 // Dump in the page header ...
829 include('./page_header_admin.'.$phpEx);
831 $template->set_filenames(array(
832 "body" => 'admin/auth_ug_body.tpl')
835 $adv_switch = ( empty($adv) ) ? 1 : 0;
836 $u_ug_switch = ( $mode == 'user' ) ? POST_USERS_URL . "=" . $user_id : POST_GROUPS_URL . "=" . $group_id;
837 $switch_mode = append_sid("admin_ug_auth.$phpEx?mode=$mode&" . $u_ug_switch . "&adv=$adv_switch");
838 $switch_mode_text = ( empty($adv) ) ? $lang['Advanced_mode'] : $lang['Simple_mode'];
839 $u_switch_mode = '<a href="' . $switch_mode . '">' . $switch_mode_text . '</a>';
841 $s_hidden_fields = '<input type="hidden" name="mode" value="' . $mode . '" /><input type="hidden" name="adv" value="' . $adv . '" />';
842 $s_hidden_fields .= ( $mode == 'user' ) ? '<input type="hidden" name="' . POST_USERS_URL . '" value="' . $user_id . '" />' : '<input type="hidden" name="' . POST_GROUPS_URL . '" value="' . $group_id . '" />';
844 if ( $mode == 'user' )
846 $template->assign_block_vars('switch_user_auth', array());
848 $template->assign_vars(array(
849 'USERNAME' => $t_username,
850 'USER_LEVEL' => $lang['User_Level'] . " : " . $s_user_type,
851 'USER_GROUP_MEMBERSHIPS' => $lang['Group_memberships'] . ' : ' . $t_usergroup_list)
856 $template->assign_block_vars("switch_group_auth", array());
858 $template->assign_vars(array(
859 'USERNAME' => $t_groupname,
860 'GROUP_MEMBERSHIP' => $lang['Usergroup_members'] . ' : ' . $t_usergroup_list)
864 $template->assign_vars(array(
865 'L_USER_OR_GROUPNAME' => ( $mode == 'user' ) ? $lang['Username'] : $lang['Group_name'],
867 'L_AUTH_TITLE' => ( $mode == 'user' ) ? $lang['Auth_Control_User'] : $lang['Auth_Control_Group'],
868 'L_AUTH_EXPLAIN' => ( $mode == 'user' ) ? $lang['User_auth_explain'] : $lang['Group_auth_explain'],
869 'L_MODERATOR_STATUS' => $lang['Moderator_status'],
870 'L_PERMISSIONS' => $lang['Permissions'],
871 'L_SUBMIT' => $lang['Submit'],
872 'L_RESET' => $lang['Reset'],
873 'L_FORUM' => $lang['Forum'],
875 'U_USER_OR_GROUP' => append_sid("admin_ug_auth.$phpEx"),
876 'U_SWITCH_MODE' => $u_switch_mode,
878 'S_COLUMN_SPAN' => $s_column_span,
879 'S_AUTH_ACTION' => append_sid("admin_ug_auth.$phpEx"),
880 'S_HIDDEN_FIELDS' => $s_hidden_fields)
886 // Select a user/group
888 include('./page_header_admin.'.$phpEx);
890 $template->set_filenames(array(
891 'body' => ( $mode == 'user' ) ? 'admin/user_select_body.tpl' : 'admin/auth_select_body.tpl')
894 if ( $mode == 'user' )
896 $template->assign_vars(array(
897 'L_FIND_USERNAME' => $lang['Find_username'],
899 'U_SEARCH_USER' => append_sid("../search.$phpEx?mode=searchuser"))
904 $sql = "SELECT group_id, group_name
905 FROM " . GROUPS_TABLE . "
906 WHERE group_single_user <> " . TRUE;
907 if ( !($result = $db->sql_query($sql)) )
909 message_die(GENERAL_ERROR, "Couldn't get group list", "", __LINE__, __FILE__, $sql);
912 if ( $row = $db->sql_fetchrow($result) )
914 $select_list = '<select name="' . POST_GROUPS_URL . '">';
917 $select_list .= '<option value="' . $row['group_id'] . '">' . $row['group_name'] . '</option>';
919 while ( $row = $db->sql_fetchrow($result) );
920 $select_list .= '</select>';
923 $template->assign_vars(array(
924 'S_AUTH_SELECT' => $select_list)
928 $s_hidden_fields = '<input type="hidden" name="mode" value="' . $mode . '" />';
930 $l_type = ( $mode == 'user' ) ? 'USER' : 'AUTH';
932 $template->assign_vars(array(
933 'L_' . $l_type . '_TITLE' => ( $mode == 'user' ) ? $lang['Auth_Control_User'] : $lang['Auth_Control_Group'],
934 'L_' . $l_type . '_EXPLAIN' => ( $mode == 'user' ) ? $lang['User_auth_explain'] : $lang['Group_auth_explain'],
935 'L_' . $l_type . '_SELECT' => ( $mode == 'user' ) ? $lang['Select_a_User'] : $lang['Select_a_Group'],
936 'L_LOOK_UP' => ( $mode == 'user' ) ? $lang['Look_up_User'] : $lang['Look_up_Group'],
938 'S_HIDDEN_FIELDS' => $s_hidden_fields,
939 'S_' . $l_type . '_ACTION' => append_sid("admin_ug_auth.$phpEx"))
944 $template->pparse('body');
946 include('./page_footer_admin.'.$phpEx);