<?php
session_start();
$user_ID=$_SESSION[user_ID];
if (!$user_ID || $user_ID=='0')
{
header('location: index.php');
die('Login failed');
}
require("util.php");
$sql = new MySQL_class;
$sql->Create("generator");
$esql = new MySQL_class;
$esql->Create("generator");
if ($_GET[user]) { $_SESSION[var_user] = $_GET[user]; }
$user=$_SESSION[var_user];
?>
<?php
$sql->QueryItem("SELECT user_rights.right as F502 FROM `user_rights` WHERE user_rights.user='$user'");
$right = htmlspecialchars($sql->data['F502']);
if ($_POST['user_rights']!='') {
$right = htmlspecialchars($_POST['right']);
}
?>
<html>
<head>
<link href="list.css" type="text/css" rel=stylesheet>
<meta content="text/css" http-equiv="Content-Style-Type">
<title>Edit Rights</title>
<script>
function confirmDelete(delUrl) {
if (confirm("Remove Rights?")) {
document.location = delUrl;
}
}
</script>
</head>
<body class="top" onload="document.Edit.<?php
{echo 'right';}
?>.focus();">
<form name="Edit" action="posteditrights.php" method="post">
<input type=hidden name="FOCUS" value="">
<?php echo("<input type=hidden name=\"user_rights\" size=5 value=\"$user_rights\">\n");?>
<table class=enter>
<tr id=title><th colspan=2>Edit Rights</th></tr>
<tr><th>Right</th>
<td>
<?php
echo ("<select name=\"right\" style=\"width: 175px\" OnChange=\"Edit.action=''; Edit.FOCUS.value='502'; Edit.submit();\">");
$sql->Query("SELECT `user`.`username` as F0_1, `user`.user FROM `user` ORDER BY `user`.`username`");
for ($i = 0; $i < $sql->rows; $i++) {
$sql->Fetch($i);
$searchID = $sql->data[user];
$username_0=htmlspecialchars($sql->data[F0_1]);
$searchShow = "$username_0";
echo "<option ";
if ($searchID == $right) {echo "selected ";};
echo "value=\"$searchID\">$searchShow";
echo "</option>\n";
}
echo ("</select>");
?>
</td></tr>
</table>
<p id=buttons>
<input type=submit value=Change>
<?php
$test=true;
if ($test) {
echo "<input type=button value=Delete onClick=\"confirmDelete('postdeleterights.php?user_rights=$user_rights&user=$user')\">\n";
}
?>
<input type=button value="Cancel" onClick="window.close()">
</p>
</form>
</body>
</html>