<?php
session_start();
$user_ID=$_SESSION[user_ID];
if (!$user_ID || $user_ID=='0')
{
header('location: index.php');
die('Login failed');
}
require("util.php");
$sql = new MySQL_class;
$sql->Create("generator");
$esql = new MySQL_class;
$esql->Create("generator");
if ($_GET[user]) { $_SESSION[var_user] = $_GET[user]; }
$user=$_SESSION[var_user];
?>
<html>
<head>
<link href="list.css" type="text/css" rel=stylesheet>
<meta content="text/css" http-equiv="Content-Style-Type">
<title>Screen generator Scherm: User</title>
</head>
<script type="text/javascript" src="handlers.js" language="JavaScript">
alert ("no code");
</script>
<body>
<?php
include 'menu.php';
include 'makemenu.php';
makeMenu(1, 0, '');
?>
<div id="content">
<table class=ruler><tr><td>User</td></tr></table>
<?php
$sql->QueryItem("SELECT user.username as F497, user.password as F498, user.special as F499, user.type as F500 FROM `user`
WHERE `user`.`user` = '$user'
ORDER BY `user`.`username` ASC LIMIT 1");
$username = $sql->data['F497'];
$password = $sql->data['F498'];
$special = $sql->data['F499'];
$type = $sql->data['F500'];
echo ('<table class=record>');
echo ("<tr><th>Username</th>
<td>$username</td>");
echo ("</tr>");
echo ("<tr><th>Password</th>
<td>$password</td>");
echo ("</tr>");
echo ("<tr><th>Special</th>
<td>$special</td>");
echo ("</tr>");
echo ("<tr><th>Type</th>
<td>$type</td>");
echo ("</tr>");
echo ('</table>');
?>
<p><input type=button value="Edit User" onClick="javascript: window.open('edituser.php?user=<?php echo $user; ?>','','width=500,height=300,location=no,menubar=no,scrollbars=yes,status=no,resizable=yes'); return false;">
<br><br><br><table class=ruler><tr><td>Rights</td></tr></table>
<?php
$lastorder=$_SESSION[last_69];
$lastfilter69=$_SESSION[filter69];
$_SESSION[last_69]='';
if ($_GET[filter69]) { $filter69 =$_GET[filter69]; } else { $filter69=$_POST[filter69];}
if ($_GET[page69]) { $page=$_GET[page69]; } else { $page=$_POST[page69]; }
if ($filter69!=$lastfilter69) {
$_SESSION[filter69]=$filter69;
$page=0;
}
if ($filter69!='')
{
$qfilter69 = quote('%'.$filter69.'%');
$query = ("
FROM `user_rights`
LEFT JOIN `user` AS T502 ON user_rights.right=T502.user
WHERE (username LIKE $qfilter69
) AND `user_rights`.`user`='$user'
");
}
else
{
$query = ("
FROM `user_rights`
LEFT JOIN `user` AS T502 ON user_rights.right=T502.user
WHERE 1 AND `user_rights`.`user`='$user'
");
}
$lastrec=-1;
$sql->QueryItem("SELECT COUNT(*) AS records$query");
$records=$sql->data[records];
if ($lastorder=='') {$fromrec=20*$page;} else {
$sql->QueryItem("SELECT COUNT(*) AS fromrec$query AND `user_rights`.`right` < $lastorder");
$fromrec=$sql->data[fromrec]-10;
if($fromrec<0) {$fromrec=0; }
$lastrec=$sql->data[fromrec]-$fromrec;
}
$sql->Query("SELECT user_rights.user as F501, $query
ORDER BY `user_rights`.`right` ASC
LIMIT $fromrec, 20");
if (($part_rights['30/nofilter']==0)) {
echo "<form action=\"\" method=get name=Filter>";
echo "<p class=filter>";
echo "Records: $records ";
$maxpage=(int) (($records+19)/20);
if ($maxpage>1) {
echo "Page: ";
echo "<select name=\"page69\" OnChange=\"Filter.target=''; Filter.action = ''; Filter.submit();\">\n";
for ($i = 0; $i < $maxpage; $i++)
{
$nr=$i+1;
if ($i==$page) {$sel=" selected";} else {$sel="";}
echo "<option value=$i$sel>$nr van $maxpage</option>\n";
}
echo "</select>\n";
}
echo "<input type=text name=\"filter69\" size=25 value=\"$filter69\">";
echo "<input type=submit value=\"Search\">";
echo "<input type=button value=\"Add Rights\" onClick=\"javascript: window.open('addrights.php?user=$user','','width=400,height=400,location=no,menubar=no,scrollbars=yes,status=no,resizable=yes'); return false;\">";
echo "</p>";
echo "</form>";
}
?>
<table class=list>
<tr>
<th width=210px>Right</th>
</tr>
<?php
for ($i = 0; $i < $sql->rows; $i++)
{
$sql->Fetch($i);
$right_lup = "username";
if ($lastrec==$i) {$color="style=\"background-color: #aaaaff;\"";} else {$color="";}
echo ("
<tr $color onMouseOver=\"ChangeColor(this)\" onMouseOut=\"ChangeColorBack(this)\" onClick=\"window.open('editrights.php?user=$user','wijzigen','width=400,height=400,location=no,menubar=no,scrollbars=yes,status=no,resizable=yes')\">
<td>$right_lup</td>
</tr>");
}
?>
</table>
</div></body>
</html>