// Check if there was a submission
foreach($_POST as $key => $val) {
- if (!S::has_xsrf_token()) {
- $page->kill("L'opération de modification de l'utilisateur a échouée, merci de réessayer.");
- }
+ S::assert_xsrf_token();
+
switch ($key) {
case "add_fwd":
$email = trim(Env::v('email'));
case "u_edit":
require_once('secure_hash.inc.php');
$pass_encrypted = Env::v('newpass_clair') != "********" ? hash_encrypt(Env::v('newpass_clair')) : Env::v('passw');
- $naiss = Env::v('naissanceN');
- $deces = Env::v('decesN');
- $perms = Env::v('permsN');
- $prenm = Env::v('prenomN');
- $nom = Env::v('nomN');
- $promo = Env::i('promoN');
- $sexe = Env::v('sexeN');
- $comm = trim(Env::v('commentN'));
- $watch = Env::v('watchN');
- $flags = '';
+ $naiss = Env::v('naissanceN');
+ $deces = Env::v('decesN');
+ $perms = Env::v('permsN');
+ $prenm = Env::v('prenomN');
+ $nom = Env::v('nomN');
+ $nomusage = Env::v('nomusageN');
+ $promo = Env::i('promoN');
+ $sexe = Env::v('sexeN');
+ $comm = trim(Env::v('commentN'));
+ $watch = Env::v('watchN');
+ $flags = '';
if ($sexe) {
$flags = 'femme';
}
break;
}
- $watch = 'SELECT naissance, deces, password, perms,
+ $watch = 'SELECT naissance, deces, password, perms, nom_usage,
prenom, nom, flags, promo, comment
FROM auth_user_md5
WHERE user_id = ' . $mr['user_id'];
perms = '$perms',
prenom = '".addslashes($prenm)."',
nom = '".addslashes($nom)."',
+ nom_usage = '".addslashes($nomusage)."',
flags = '$flags',
promo = $promo,
comment = '".addslashes($comm)."'
$new_fields = $res->fetchOneAssoc();
$mailer = new PlMailer("admin/useredit.mail.tpl");
- $mailer->assign("user", S::v('forlife'));
+ $mailer->assign("admin", S::v('forlife'));
+ $mailer->assign("user", $mr['forlife']);
$mailer->assign('old', $old_fields);
$mailer->assign('new', $new_fields);
$mailer->send();
// on examine l'op a effectuer
switch ($op) {
case 'mail':
- if (S::has_xsrf_token()) {
- send_warning_homonyme($prenom, $nom, $forlife, $loginbis);
- switch_bestalias($target, $loginbis);
- } else {
- $page->assign('op', 'list');
- $page->trig("L'envoi du mail d'homonymie a échoué, merci de réessayer.");
- }
+ S::assert_xsrf_token();
+
+ send_warning_homonyme($prenom, $nom, $forlife, $loginbis);
+ switch_bestalias($target, $loginbis);
$op = 'list';
break;
case 'correct':
- if (S::has_xsrf_token()) {
- switch_bestalias($target, $loginbis);
- XDB::execute("UPDATE aliases SET type='homonyme',expire=NOW() WHERE alias={?}", $loginbis);
- XDB::execute("REPLACE INTO homonymes (homonyme_id,user_id) VALUES({?},{?})", $target, $target);
- send_robot_homonyme($prenom, $nom, $forlife, $loginbis);
- } else {
- $page->assign('op', 'list');
- $page->trig("La correction de l'homonymie a échouée, merci de réessayer.");
- }
+ S::assert_xsrf_token();
+
+ switch_bestalias($target, $loginbis);
+ XDB::execute("UPDATE aliases SET type='homonyme',expire=NOW() WHERE alias={?}", $loginbis);
+ XDB::execute("REPLACE INTO homonymes (homonyme_id,user_id) VALUES({?},{?})", $target, $target);
+ send_robot_homonyme($prenom, $nom, $forlife, $loginbis);
$op = 'list';
break;
}
$page->assign('promo',$promo);
- if ($validate && S::has_xsrf_token()) {
+ if ($validate) {
+ S::assert_xsrf_token();
+
$new_deces = array();
$res = XDB::iterRow("SELECT user_id,matricule,nom,prenom,deces FROM auth_user_md5 WHERE promo = {?}", $promo);
while (list($uid,$mat,$nom,$prenom,$deces) = $res->next()) {
}
}
$page->assign('new_deces',$new_deces);
- } else if ($validate) {
- $page->trig("La mise à jour des dates de decès à échouée, merci de réessayer.");
}
$res = XDB::iterator('SELECT matricule, nom, prenom, deces FROM auth_user_md5 WHERE promo = {?} ORDER BY nom,prenom', $promo);
}
if(Env::has('uid') && Env::has('type') && Env::has('stamp')) {
+ S::assert_xsrf_token();
+
$req = Validate::get_typed_request(Env::v('uid'), Env::v('type'), Env::v('stamp'));
- if($req && S::has_xsrf_token()) {
- $req->handle_formu();
- } else if ($req) {
- $page->trig("L'opération a échoué, merci de réessayer.");
- }
+ $req->handle_formu();
}
$r = XDB::iterator('SHOW COLUMNS FROM requests_answers');
}
// update wiki perms
- if ($action == 'update' && S::has_xsrf_token()) {
+ if ($action == 'update') {
+ S::assert_xsrf_token();
+
$perms_read = Post::v('read');
$perms_edot = Post::v('edit');
if ($perms_read || $perms_edit) {
wiki_set_perms($wiki_page, $perms0, $perms1);
}
}
- } elseif ($action == 'update') {
- $page->trig("La mise à jour des permissions wiki a échouée, merci de réessayer.");
}
- if ($action == 'delete' && $wikipage != '' && S::has_xsrf_token()) {
+ if ($action == 'delete' && $wikipage != '') {
+ S::assert_xsrf_token();
+
if (wiki_delete_page($wikipage)) {
$page->trig("La page ".$wikipage." a été supprimée.");
} else {
$page->trig("Impossible de supprimer la page ".$wikipage.".");
}
- } elseif ($action == 'delete' && $wikipage != '') {
- $page->trig("La suppression de la page wiki a échouée, merci de réessayer.");
}
- if ($action == 'rename' && $wikipage != '' && $wikipage2 != '' && $wikipage != $wikipage2 && S::has_xsrf_token()) {
+ if ($action == 'rename' && $wikipage != '' && $wikipage2 != '' && $wikipage != $wikipage2) {
+ S::assert_xsrf_token();
+
if ($changedLinks = wiki_rename_page($wikipage, $wikipage2)) {
$s = 'La page <em>'.$wikipage.'</em> a été déplacée en <em>'.$wikipage2.'</em>.';
if (is_numeric($changedLinks)) {
} else {
$page->trig("Impossible de déplacer la page ".$wikipage);
}
- } elseif ($action == 'rename' && $wikipage != '' && $wikipage2 != '' && $wikipage != $wikipage2) {
- $page->trig("Le renommage de la page wiki a échoué, merci de réessayer.");
}
$perms = wiki_perms_options();
switch (Post::v('action')) {
case 'create':
if (trim(Post::v('ipN')) != '') {
- if (!S::has_xsrf_token()) {
- $page->trig("L'ajout d'une IP à surveiller a échoué, merci de réessayer.");
- break;
- }
+ S::assert_xsrf_token();
Xdb::execute('INSERT IGNORE INTO ip_watch (ip, mask, state, detection, last, uid, description)
VALUES ({?}, {?}, {?}, CURDATE(), NOW(), {?}, {?})',
ip_to_uint(trim(Post::v('ipN'))), ip_to_uint(trim(Post::v('maskN'))),
break;
case 'edit':
- if (!S::has_xsrf_token()) {
- $page->trig("L'édition de l'IP a échoué, merci de réessayer.");
- break;
- }
+ S::assert_xsrf_token();
Xdb::execute('UPDATE ip_watch
SET state = {?}, last = NOW(), uid = {?}, description = {?}, mask = {?}
WHERE ip = {?}', Post::v('stateN'), S::i('uid'), Post::v('descriptionN'),
default:
if ($action == 'delete' && !is_null($ip)) {
- if (S::has_xsrf_token()) {
- Xdb::execute('DELETE FROM ip_watch WHERE ip = {?}', ip_to_uint($ip));
- } else {
- $page->trig("La suppression de l'adresse IP a échouée, merci de réessayer.");
- }
+ S::assert_xsrf_token();
+ Xdb::execute('DELETE FROM ip_watch WHERE ip = {?}', ip_to_uint($ip));
}
}
if ($action != 'create' && $action != 'edit') {