国内流行的内容管理系统(CMS)多端全媒体解决方案 https://www.dedebiz.com
Você não pode selecionar mais de 25 tópicos Os tópicos devem começar com uma letra ou um número, podem incluir traços ('-') e podem ter até 35 caracteres.

105 linhas
4.3KB

  1. <?php
  2. /**
  3. * 升级为管理员
  4. *
  5. * @version $Id: member_toadmin.php 1 14:09 2010年7月20日Z tianya $
  6. * @package DedeCMS.Administrator
  7. * @copyright Copyright (c) 2007 - 2018, DesDev, Inc.
  8. * @copyright Copyright (c) 2020, DedeBIZ.COM
  9. * @license https://www.dedebiz.com/license/v6
  10. * @link https://www.dedebiz.com
  11. */
  12. require_once(dirname(__FILE__)."/config.php");
  13. CheckPurview('member_Edit');
  14. if(empty($dopost)) $dopost = '';
  15. if(empty($fmdo)) $fmdo = '';
  16. $ENV_GOBACK_URL = isset($_COOKIE['ENV_GOBACK_URL']) ? 'member_main.php' : '';
  17. $row = array();
  18. /*----------------
  19. function __Toadmin()
  20. 升级为管理员
  21. ----------------*/
  22. if($dopost == "toadmin")
  23. {
  24. $pwd = trim($pwd);
  25. if($pwd!='' && preg_match("#[^0-9a-zA-Z_@!\.-]#", $pwd))
  26. {
  27. ShowMsg('密码不合法,请使用[0-9a-zA-Z_@!.-]内的字符!','-1', 0, 3000);
  28. exit();
  29. }
  30. $safecodeok = substr(md5($cfg_cookie_encode.$randcode), 0, 24);
  31. if($safecodeok != $safecode)
  32. {
  33. ShowMsg("请填写正确的安全验证串!", "member_toadmin.php?id={$id}");
  34. exit();
  35. }
  36. $pwdm = '';
  37. if($pwd!='')
  38. {
  39. $inputpwd = ",pwd";
  40. $inputpwdv = ",'".substr(md5($pwd), 5, 20)."'";
  41. $pwdm = ",pwd='".md5($pwd)."'";
  42. }else{
  43. $row = $dsql->GetOne("SELECT * FROM #@__member WHERE mid='$id'");
  44. $password = $row['pwd'];
  45. $inputpwd = ",pwd";
  46. $pwd = substr($password, 5, 20);
  47. $inputpwdv = ",'".$pwd."'";
  48. $pwdm = ",pwd='".$password."'";
  49. }
  50. $typeids=(empty($typeids))? "" : $typeids;
  51. if($typeids=='')
  52. {
  53. ShowMsg("请为该管理员指定管理栏目!","member_toadmin.php?id={$id}");
  54. exit();
  55. }
  56. $typeid = join(',', $typeids);
  57. if($typeid=='0') $typeid = '';
  58. if($id!=1)
  59. {
  60. $query = "INSERT INTO `#@__admin`(id,usertype,userid$inputpwd,uname,typeid,tname,email)
  61. VALUES('$id','$usertype','$userid'$inputpwdv,'$uname','$typeid','$tname','$email')";
  62. }
  63. else
  64. {
  65. $query = "INSERT INTO `#@__admin`(id,userid$inputpwd,uname,typeid,tname,email)
  66. VALUES('$id','$userid'$inputpwdv,'$uname','$typeid','$tname','$email')";
  67. }
  68. $dsql->ExecuteNoneQuery($query);
  69. $query = "UPDATE `#@__member` SET rank='100',uname='$uname',matt='10',email='$email'$pwdm WHERE mid='$id'";
  70. $dsql->ExecuteNoneQuery($query);
  71. $row = $dsql->GetOne("SELECT * FROM #@__admintype WHERE rank='$usertype'");
  72. $floginid = $cuserLogin->getUserName();
  73. $fromid = $cuserLogin->getUserID();
  74. $subject = "恭喜您已经成功提升为管理员";
  75. $message = "亲爱的会员{$userid},您已经成功提升为{$row['typename']},具体操作权限请同网站超级管理员联系。";
  76. $sendtime = $writetime = time();
  77. $inquery = "INSERT INTO `#@__member_pms` (`floginid`,`fromid`,`toid`,`tologinid`,`folder`,`subject`,`sendtime`,`writetime`,`hasview`,`isadmin`,`message`)
  78. VALUES ('$floginid','$fromid','$id','$userid','inbox','$subject','$sendtime','$writetime','0','0','$message'); ";
  79. $dsql->ExecuteNoneQuery($inquery);
  80. ShowMsg("成功升级一个帐户!","member_main.php");
  81. exit();
  82. }
  83. $id = preg_replace("#[^0-9]#", "", $id);
  84. //显示用户信息
  85. $randcode = mt_rand(10000, 99999);
  86. $safecode = substr(md5($cfg_cookie_encode.$randcode), 0, 24);
  87. $typeOptions = '';
  88. $typeid=(empty($typeid))? '' : $typeid;
  89. $typeids = explode(',', $typeid);
  90. $dsql->SetQuery("SELECT id,typename FROM `#@__arctype` WHERE reid=0 AND (ispart=0 OR ispart=1)");
  91. $dsql->Execute('op');
  92. while($nrow = $dsql->GetObject('op'))
  93. {
  94. $typeOptions .= "<option value='{$nrow->id}' class='btype'".(in_array($nrow->id, $typeids) ? ' selected' : '').">{$nrow->typename}</option>\r\n";
  95. $dsql->SetQuery("SELECT id,typename FROM #@__arctype WHERE reid={$nrow->id} AND (ispart=0 OR ispart=1)");
  96. $dsql->Execute('s');
  97. while($nrow = $dsql->GetObject('s'))
  98. {
  99. $typeOptions .= "<option value='{$nrow->id}' class='stype'".(in_array($nrow->id, $typeids) ? ' selected' : '').">—{$nrow->typename}</option>\r\n";
  100. }
  101. }
  102. $row = $dsql->GetOne("SELECT * FROM #@__member WHERE mid='$id'");
  103. include DedeInclude('templets/member_toadmin.htm');