Repository navigation
Expand file tree
/
Copy pathserversubusersprocess.php
More file actions
67 lines (55 loc) · 2.23 KB
/
Copy pathserversubusersprocess.php
File metadata and controls
67 lines (55 loc) · 2.23 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
<?php
$return = true;
require __DIR__ . '/configuration.php';
require __DIR__ . '/include.php';
requireSameOrigin('index.php');
require __DIR__ . '/includes/access.php';
$clientId = (int) ($_SESSION['clientid'] ?? 0);
if (!$clientId) {
header('Location: login.php');
exit;
}
$task = sanitizeInput($_POST['task'] ?? ($_GET['task'] ?? ''));
$serverid = (int) ($_POST['serverid'] ?? ($_GET['serverid'] ?? 0));
if (!clientOwnsServer($clientId, $serverid)) {
header('Location: serversummary.php?id=' . $serverid);
exit;
}
function su_flash(string $a, string $b, int $serverid): void
{
$_SESSION['msg1'] = $a;
$_SESSION['msg2'] = $b;
header('Location: serversubusers.php?id=' . $serverid);
exit;
}
if ($task === 'add') {
$email = strtolower(trim(sanitizeInput($_POST['email'] ?? '')));
if ($email === '' || filter_var($email, FILTER_VALIDATE_EMAIL) === false) {
su_flash('Invalid email', 'Enter the account email of the person you want to share with.', $serverid);
}
if (dbCount("SELECT `subid` FROM `subuser` WHERE `serverid` = '" . $serverid . "' AND `subemail` = '" . dbEscape($email) . "'") > 0) {
su_flash('Already shared', 'That email is already on this server.', $serverid);
}
$c = dbRow("SELECT `clientid`, `email` FROM `client` WHERE `email` = '" . dbEscape($email) . "' LIMIT 1", true);
$subclientid = (is_array($c) && isset($c['clientid'])) ? (int) $c['clientid'] : 0;
if ($subclientid === $clientId) {
su_flash('That is you', 'You already own this server.', $serverid);
}
dbExec(
"INSERT INTO `subuser` SET `serverid` = '" . $serverid . "', `ownerid` = '" . $clientId . "', " .
"`subclientid` = '" . $subclientid . "', `subemail` = '" . dbEscape($email) . "', `created` = NOW()"
);
su_flash(
'Shared',
$subclientid > 0
? $email . ' can now see this server (view, console, power) in their account.'
: 'No account with that email yet — access starts as soon as they sign up.',
$serverid
);
}
if ($task === 'remove') {
$subid = (int) ($_POST['subid'] ?? ($_GET['subid'] ?? 0));
dbExec("DELETE FROM `subuser` WHERE `subid` = '" . $subid . "' AND `serverid` = '" . $serverid . "'");
su_flash('Access removed', 'They can no longer see this server.', $serverid);
}
header('Location: serversubusers.php?id=' . $serverid);