国内流行的内容管理系统(CMS)多端全媒体解决方案 https://www.dedebiz.com
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

96 lines
4.2KB

  1. <?php
  2. /**
  3. * 升级为管理员
  4. *
  5. * @version $Id: member_toadmin.php 1 14:09 2010年7月20日Z tianya $
  6. * @package DedeBIZ.Administrator
  7. * @copyright Copyright (c) 2020, DedeBIZ.COM
  8. * @license https://www.dedebiz.com/license
  9. * @link https://www.dedebiz.com
  10. */
  11. require_once(dirname(__FILE__) . "/config.php");
  12. CheckPurview('member_Edit');
  13. if (empty($dopost)) $dopost = '';
  14. if (empty($fmdo)) $fmdo = '';
  15. $ENV_GOBACK_URL = isset($_COOKIE['ENV_GOBACK_URL']) ? 'member_main.php' : '';
  16. $row = array();
  17. /*----------------
  18. function __Toadmin()
  19. 升级为管理员
  20. ----------------*/
  21. if ($dopost == "toadmin") {
  22. $pwd = trim($pwd);
  23. if ($pwd != '' && preg_match("#[^0-9a-zA-Z_@!\.-]#", $pwd)) {
  24. ShowMsg('密码不合法,请使用[0-9a-zA-Z_@!.-]内的字符!', '-1', 0, 3000);
  25. exit();
  26. }
  27. $safecodeok = substr(md5($cfg_cookie_encode . $randcode), 0, 24);
  28. if ($safecodeok != $safecode) {
  29. ShowMsg("请填写正确的安全验证串!", "member_toadmin.php?id={$id}");
  30. exit();
  31. }
  32. $pwdm = '';
  33. if ($pwd != '') {
  34. $inputpwd = ",pwd";
  35. $inputpwdv = ",'" . substr(md5($pwd), 5, 20) . "'";
  36. $pwdm = ",pwd='" . md5($pwd) . "'";
  37. } else {
  38. $row = $dsql->GetOne("SELECT * FROM #@__member WHERE mid='$id'");
  39. $password = $row['pwd'];
  40. $inputpwd = ",pwd";
  41. $pwd = substr($password, 5, 20);
  42. $inputpwdv = ",'" . $pwd . "'";
  43. $pwdm = ",pwd='" . $password . "'";
  44. }
  45. $typeids = (empty($typeids)) ? "" : $typeids;
  46. if ($typeids == '') {
  47. ShowMsg("请为该管理员指定管理栏目!", "member_toadmin.php?id={$id}");
  48. exit();
  49. }
  50. $typeid = join(',', $typeids);
  51. if ($typeid == '0') $typeid = '';
  52. if ($id != 1) {
  53. $query = "INSERT INTO `#@__admin`(id,usertype,userid$inputpwd,uname,typeid,tname,email)
  54. VALUES('$id','$usertype','$userid'$inputpwdv,'$uname','$typeid','$tname','$email')";
  55. } else {
  56. $query = "INSERT INTO `#@__admin`(id,userid$inputpwd,uname,typeid,tname,email)
  57. VALUES('$id','$userid'$inputpwdv,'$uname','$typeid','$tname','$email')";
  58. }
  59. $dsql->ExecuteNoneQuery($query);
  60. $query = "UPDATE `#@__member` SET rank='100',uname='$uname',matt='10',email='$email'$pwdm WHERE mid='$id'";
  61. $dsql->ExecuteNoneQuery($query);
  62. $row = $dsql->GetOne("SELECT * FROM #@__admintype WHERE rank='$usertype'");
  63. $floginid = $cuserLogin->getUserName();
  64. $fromid = $cuserLogin->getUserID();
  65. $subject = "恭喜您已经成功提升为管理员";
  66. $message = "亲爱的会员{$userid},您已经成功提升为{$row['typename']},具体操作权限请同网站超级管理员联系。";
  67. $sendtime = $writetime = time();
  68. $inquery = "INSERT INTO `#@__member_pms` (`floginid`,`fromid`,`toid`,`tologinid`,`folder`,`subject`,`sendtime`,`writetime`,`hasview`,`isadmin`,`message`)
  69. VALUES ('$floginid','$fromid','$id','$userid','inbox','$subject','$sendtime','$writetime','0','0','$message'); ";
  70. $dsql->ExecuteNoneQuery($inquery);
  71. ShowMsg("成功升级一个帐户!", "member_main.php");
  72. exit();
  73. }
  74. $id = preg_replace("#[^0-9]#", "", $id);
  75. //显示用户信息
  76. $randcode = mt_rand(10000, 99999);
  77. $safecode = substr(md5($cfg_cookie_encode . $randcode), 0, 24);
  78. $typeOptions = '';
  79. $typeid = (empty($typeid)) ? '' : $typeid;
  80. $typeids = explode(',', $typeid);
  81. $dsql->SetQuery("SELECT id,typename FROM `#@__arctype` WHERE reid=0 AND (ispart=0 OR ispart=1)");
  82. $dsql->Execute('op');
  83. while ($nrow = $dsql->GetObject('op')) {
  84. $typeOptions .= "<option value='{$nrow->id}' class='btype'" . (in_array($nrow->id, $typeids) ? ' selected' : '') . ">{$nrow->typename}</option>\r\n";
  85. $dsql->SetQuery("SELECT id,typename FROM #@__arctype WHERE reid={$nrow->id} AND (ispart=0 OR ispart=1)");
  86. $dsql->Execute('s');
  87. while ($nrow = $dsql->GetObject('s')) {
  88. $typeOptions .= "<option value='{$nrow->id}' class='stype'" . (in_array($nrow->id, $typeids) ? ' selected' : '') . ">—{$nrow->typename}</option>\r\n";
  89. }
  90. }
  91. $row = $dsql->GetOne("SELECT * FROM #@__member WHERE mid='$id'");
  92. include DedeInclude('templets/member_toadmin.htm');