2023-07-26 22:43:50 +00:00
|
|
|
<?php
|
|
|
|
namespace Misuzu;
|
|
|
|
|
|
|
|
use RuntimeException;
|
|
|
|
|
2023-09-06 20:06:07 +00:00
|
|
|
$authInfo = $msz->getAuthInfo();
|
|
|
|
if(!$authInfo->getPerms('user')->check(Perm::U_WARNINGS_MANAGE))
|
2023-08-31 15:59:53 +00:00
|
|
|
Template::throwError(403);
|
2023-07-26 22:43:50 +00:00
|
|
|
|
2023-09-06 13:50:19 +00:00
|
|
|
$usersCtx = $msz->getUsersContext();
|
|
|
|
$users = $usersCtx->getUsers();
|
|
|
|
$warns = $usersCtx->getWarnings();
|
2023-07-26 22:43:50 +00:00
|
|
|
|
|
|
|
if($_SERVER['REQUEST_METHOD'] === 'GET' && filter_has_var(INPUT_GET, 'delete')) {
|
2023-08-31 15:59:53 +00:00
|
|
|
if(!CSRF::validateRequest())
|
|
|
|
Template::throwError(403);
|
|
|
|
|
|
|
|
try {
|
|
|
|
$warnInfo = $warns->getWarning((string)filter_input(INPUT_GET, 'w'));
|
|
|
|
} catch(RuntimeException $ex) {
|
|
|
|
Template::throwError(404);
|
|
|
|
}
|
|
|
|
|
|
|
|
$warns->deleteWarnings($warnInfo);
|
|
|
|
$msz->createAuditLog('WARN_DELETE', [$warnInfo->getId(), $warnInfo->getUserId()]);
|
|
|
|
url_redirect('manage-users-warnings', ['user' => $warnInfo->getUserId()]);
|
2023-07-26 22:43:50 +00:00
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
try {
|
2023-08-02 22:12:47 +00:00
|
|
|
$userInfo = $users->getUser(filter_input(INPUT_GET, 'u', FILTER_SANITIZE_NUMBER_INT), 'id');
|
2023-07-26 22:43:50 +00:00
|
|
|
} catch(RuntimeException $ex) {
|
2023-08-31 15:59:53 +00:00
|
|
|
Template::throwError(404);
|
2023-07-26 22:43:50 +00:00
|
|
|
}
|
|
|
|
|
2023-09-06 20:06:07 +00:00
|
|
|
$modInfo = $authInfo->getUserInfo();
|
2023-07-26 22:43:50 +00:00
|
|
|
|
|
|
|
while($_SERVER['REQUEST_METHOD'] === 'POST' && CSRF::validateRequest()) {
|
|
|
|
$body = trim((string)filter_input(INPUT_POST, 'uw_body'));
|
|
|
|
Template::set('warn_value_body', $body);
|
|
|
|
|
|
|
|
$warnInfo = $warns->createWarning(
|
|
|
|
$userInfo, $body, modInfo: $modInfo
|
|
|
|
);
|
|
|
|
|
|
|
|
$msz->createAuditLog('WARN_CREATE', [$warnInfo->getId(), $userInfo->getId()]);
|
|
|
|
url_redirect('manage-users-warnings', ['user' => $userInfo->getId()]);
|
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
Template::render('manage.users.warning', [
|
|
|
|
'warn_user' => $userInfo,
|
|
|
|
]);
|