Просмотр файла admin/user.php

Размер файла: 3.77Kb
<? $dir=''; include("../head.php");if(!isset($me) or @$me['admin']!=2)exit("Нету доступа");

if(!isset($_GET['id'])){
$num = 25;@$page = $_GET['page'];
$result00 = mysql_query("SELECT COUNT(*) FROM `sh_user`");
$temp = mysql_fetch_array($result00);
$posts = $temp[0];
$total = (($posts - 1) / $num) + 1;
$total =  intval($total);
$page = intval($page);
if(empty($page)or $page < 0) $page = 1;
if($page > $total) $page = $total;
$start = $page * $num - $num;

$users_q=mysql_query("SELECT * FROM `sh_user` ORDER BY `post` DESC LIMIT $start,$num");
while($user=mysql_fetch_array($users_q))
{echo "<a href='user.php?id=$user[id]'>$user[echologin]</a> ($user[login]) [$user[post]]<br/>";}
$url_for_pstr="user.php?page=";
if($page - 5 > 0) $page5left = ' <a href='.$url_for_pstr.($page - 5) .'>'. ($page - 5) .'</a> | ';
if($page - 4 > 0) $page4left = ' <a href='.$url_for_pstr.($page - 4) .'>'. ($page - 4) .'</a> | ';
if($page - 3 > 0) $page3left = ' <a href='.$url_for_pstr.($page - 3) .'>'. ($page - 3) .'</a> | ';
if($page - 2 > 0) $page2left = ' <a href='.$url_for_pstr.($page - 2) .'>'. ($page - 2) .'</a> | ';
if($page - 1 > 0) $page1left = ' <a href='.$url_for_pstr.($page - 1) .'>'. ($page - 1) .'</a> | ';
if($page + 5 <= $total) $page5right = ' | <a href='.$url_for_pstr.($page + 5) .'>'. ($page + 5) .'</a>';
if($page + 4 <= $total) $page4right = ' | <a href='.$url_for_pstr.($page + 4) .'>'. ($page + 4) .'</a>';
if($page + 3 <= $total) $page3right = ' | <a href='.$url_for_pstr.($page + 3) .'>'. ($page + 3) .'</a>';
if($page + 2 <= $total) $page2right = ' | <a href='.$url_for_pstr.($page + 2) .'>'. ($page + 2) .'</a>';
if($page + 1 <= $total) $page1right = ' | <a href='.$url_for_pstr.($page + 1) .'>'. ($page + 1) .'</a>';
if($page - 1 > 0) $nazad = '<a href='.$url_for_pstr.($page - 1) .'>Назад</a>';
if($page + 1 <= $total) $vpered = '<a href='.$url_for_pstr.($page + 1) .'>Далее</a>';
if ($total > 1)
{error_Reporting(E_ALL & ~E_NOTICE);
echo $pervpage.$page5left.$page4left.$page3left.$page2left.$page1left.'<b>'.$page.'</b>'.$page1right.$page2right.$page3right.$page4right.$page5right.$nextpage.'<br>'.$nazad.' '.$vpered;}
}


else {$id=$_GET['id']; if(!$user=@mysql_fetch_array(mysql_query("SELECT * FROM `sh_user` WHERE `id`='$id'")))die("Не найдено");
if(!isset($_POST['sub']))echo "<form action='user.php?id=$id' method='post'>
Отображаемый логин<br/><input type='text' name='echologin' value='$user[echologin]'><br/>
E-Mail<br/><input type='text' name='email' value='$user[email]'><br/>
ICQ<br/><input type='text' name='icq' value='$user[icq]'><br/>
Сообщений<br/><input type='text' name='post' value='$user[post]'><br/>
Крато о себе:<br/><textarea name='osebe' cols='20' rows='4'>$user[osebe]</textarea><br/>
Права доступа:<small><font color='green'>2=админ</font>|<font color='red'>0=пользователь</font></small><br/><input type='text' name='admin' value='$user[admin]'><br/>
<input type='submit' name='sub' value='Редактировать'></form>";

else
{$echologin=mysql_real_escape_string(trim(htmlspecialchars($_POST['echologin'])));$email=mysql_real_escape_string(trim(htmlspecialchars($_POST['email'])));
$icq=mysql_real_escape_string(trim(htmlspecialchars($_POST['icq'])));$osebe=mysql_real_escape_string(trim(htmlspecialchars($_POST['osebe'])));
$post=mysql_real_escape_string(trim(htmlspecialchars($_POST['post'])));$admin=mysql_real_escape_string(trim(htmlspecialchars($_POST['admin'])));
if(mysql_query("UPDATE `sh_user` SET `echologin`='$echologin', `email`='$email', `icq`='$icq', `osebe`='$osebe', `post`='$post', `admin`='$admin' WHERE `id`='$id'"))echo "Отредактировано";
else echo "Ошибка".mysql_error();

}
}

include("../foot.php"); ?>