<?php
session_start();
if (($_SESSION['groupid'] > 1) or (!isset($_SESSION['groupid']))) {
echo "Your Do not have the rights to view this page";
include_once 'page.php';
exit;
}
include 'includes/config.php';
include 'includes/db_inc.php';
include_once('includes/printheader.php');
prheader($_SESSION['groupid']);
if(!isset($_POST['todo']))
{
echo '<table width="100%" border="0" cellspacing="0" cellpadding="0">
<tr>
<td width="25%"> </td>
<td><p>What would you like to do?</p>
<form name="todo" method="post" action="admin.php?do=modify">
<p>
<input name="todo" type="radio" value="view">View Users
</p>
<p>
<input name="todo" type="radio" value="import">Import Users
</p>
<p>
<input name="todo" type="radio" value="delete">Delete Users
</p>
<p>
<input type="submit" name="Submit" value="Submit">
</p>
</form></td>
<td width="25%"> </td>
</tr>
</table>
';
} elseif($_POST['todo'] == view) {
db_select($db_table);
echo '<table width="100%" border="0" cellspacing="0" cellpadding="0">
<tr>
<td width="25%"> </td>
<td>';
$results = mysql_query("SELECT * FROM rsc ORDER BY username ASC ") or die('<font color="red"><br>'.mysql_error().'</font>');
echo '<table border="1"><div align="center">';
echo '<tr><td>ID #</td><td>Group ID#</td><td>Username</td><td>Password</td>
<td>Frist Name</td><td>Last Name</td><td>Email</td>';
while($rowarray = mysql_fetch_array($results) or die(mysql_error())) {
echo '<tr>';
echo '<td>';
echo $rowarray['id'];
echo '</td>';
echo '<td>';
echo $rowarray['group_id'];
echo '</td>';
echo '<td>';
echo $rowarray['username'];
echo '</td>';
echo '<td>';
echo $rowarray['password'];
echo '</td>';
echo '<td>';
echo $rowarray['first_name'];
echo '</td>';
echo '<td>';
echo $rowarray['last_name'];
echo '</td>';
echo '<td>';
echo $rowarray['email'];
echo '</td>';
echo '</tr>';
}
echo '</table></td>
<td width="25%"> </td>
</tr>
</table>';
echo "hello"; // This will not echo ????
} elseif($_POST['todo'] == import) {
echo '<div align="center"><font color="blue"> All Fields are Required</font>
<form name="UserInput" method="post" action="admin.php?do=import">
<table width="300" border="1" cellpadding="0" cellspacing="0" bordercolor="#CCCCCC">
<tr>
<td colspan="2" align="right" valign="top" nowrap><div align="left">User name And Password Input:</div></td>
</tr>
<tr>
<td align="right" valign="top" nowrap>Group</td>
<td><select name="group_id">
<option value="1">Administrator</option>
<option value="2">Managers</option>
<option value="3">User</option>
</select></td>
</tr>
<tr>
<td width="78" align="right" valign="top" nowrap><div align="right">User Name:</div></td>
<td width="528"><input name="username" type="text" id="username"></td>
</tr>
<tr>
<td width="78" align="right" valign="top" nowrap><div align="right">Password:</div></td>
<td><input name="password" type="text" id="password"></td>
</tr>
<tr>
<td align="right" valign="top" nowrap>First Name </td>
<td><input name="fname" type="text" id="fname"></td>
</tr>
<tr>
<td align="right" valign="top" nowrap>Last Name </td>
<td><input name="lname" type="text" id="lname"></td>
</tr>
<tr>
<td align="right" valign="top" nowrap>Email</td>
<td><input name="email" type="text" id="email"></td>
</tr>
<tr>
<td width="78" align="right" valign="top" nowrap><div align="right">Which Site:</div></td>
<td>Edifi Sales (Working on both) </td>
</tr>
<tr>
<td align="right" valign="top" nowrap><input type="submit" name="Submit" value="Submit"></td>
<td><input type="reset" name="Submit2" value="Reset"></td>
</tr>
</table>
</form>
</div>';
} elseif($_POST['todo'] == delete) {
db_select($db_table);
echo '<table width="100%" border="0" cellspacing="0" cellpadding="0">
<tr>
<td width="45%"> </td>
<td>';
$result = mysql_query('SELECT * FROM rsc ORDER BY username ASC') or die('<font color="red"><br>'.mysql_error().'</font>');
echo ' <form action="admin.php?do=delete" method="POST"> ';
while ($row = mysql_fetch_assoc($result))
{
echo '<input type="radio" name="del[]" value="' . $row['username'] . '"> ' . $row['username'] . '<br>';
}
echo ' <br>
<input type="submit" name="submit" value="submit">
</form></td>
<td width="25%"> </td>
</tr>
</table>';
}
///////////////////////////////////////////////////////////////////////////////////
function import($group_id,$username,$password,$fname,$lname,$email) {
global $db_table;
db_select($db_table);
$sql = "INSERT INTO rsc (group_id,username, password, first_name , last_name, email) VALUES ('$group_id','$username', '$password', '$fname', '$lname', '$email')";
mysql_query($sql) or die('<font color="red"><br>'.mysql_error().'</font>');
}
///////////////////////////////////////////////////////////////////////////////////
switch ($_GET['do']) {
case 'delete':
if (isset($_POST['del']))
{
db_select($db_table);
$result = mysql_query("DELETE FROM rsc WHERE username = '".(implode(',',$_POST['del'])."'"));
}
break;
case 'import':
import($_POST['group_id'],$_POST['username'],$_POST['password'],$_POST['fname'],$_POST['lname'],$_POST['email']);
break;
default:
break;
}
include_once 'footer.php';
?>