diff --git a/management.php b/management.php index 0de3af6b1e..506a973d40 100644 --- a/management.php +++ b/management.php @@ -1,146 +1,146 @@ -php_library_path . "login_library.php"; - require $xerte_toolkits_site->php_library_path . "display_library.php"; +require $xerte_toolkits_site->php_library_path . "login_library.php"; - /* - * As with index.php, check for posts and similar - */ - - if((!isset($_POST["login"]))&&(!isset($_POST["password"]))){ +require $xerte_toolkits_site->php_library_path . "display_library.php"; - $buffer = login_page_format_top(file_get_contents($xerte_toolkits_site->root_file_path . $xerte_toolkits_site->website_code_path . "mgt_top")); +/* + * As with index.php, check for posts and similar + */ - $buffer .= "

This is the management panel. Only site administrators can access this resource.

"; +if((!isset($_POST["login"]))&&(!isset($_POST["password"]))){ - $buffer .= login_page_format_bottom(file_get_contents($xerte_toolkits_site->root_file_path . $xerte_toolkits_site->website_code_path . "login_bottom")); + $buffer = login_page_format_top(file_get_contents($xerte_toolkits_site->root_file_path . $xerte_toolkits_site->website_code_path . "mgt_top")); - echo $buffer; + $buffer .= "

This is the management panel. Only site administrators can access this resource.

"; - } + $buffer .= login_page_format_bottom(file_get_contents($xerte_toolkits_site->root_file_path . $xerte_toolkits_site->website_code_path . "login_bottom")); - /* - * Some data has been posted, interpret as a log in attempt - */ + echo $buffer; - if ($_SERVER['REQUEST_METHOD'] == 'POST') { - - /** - * Username and password left empty - */ +} - if(($_POST["login"]=="")&&($_POST["password"]=="")){ - - $buffer = login_page_format_top(file_get_contents($xerte_toolkits_site->root_file_path . $xerte_toolkits_site->website_code_path . "mgt_top")); +/* + * Some data has been posted, interpret as a log in attempt + */ - $buffer .= "

Please enter your username and password

"; +if ($_SERVER['REQUEST_METHOD'] == 'POST') { - $buffer .= login_page_format_bottom(file_get_contents($xerte_toolkits_site->root_file_path . $xerte_toolkits_site->website_code_path . "login_bottom")); + /** + * Username and password left empty + */ - echo $buffer; + if(($_POST["login"]=="")&&($_POST["password"]=="")){ - /* - * Username left empty - */ - - }else if($_POST["login"]==""){ + $buffer = login_page_format_top(file_get_contents($xerte_toolkits_site->root_file_path . $xerte_toolkits_site->website_code_path . "mgt_top")); - $buffer = login_page_format_top(file_get_contents($xerte_toolkits_site->root_file_path . $xerte_toolkits_site->website_code_path . "mgt_top")); + $buffer .= "

Please enter your username and password

"; - $buffer .= "

Please enter your username

"; + $buffer .= login_page_format_bottom(file_get_contents($xerte_toolkits_site->root_file_path . $xerte_toolkits_site->website_code_path . "login_bottom")); - $buffer .= login_page_format_bottom(file_get_contents($xerte_toolkits_site->root_file_path . $xerte_toolkits_site->website_code_path . "login_bottom")); + echo $buffer; - echo $buffer; - - /* - * Password left empty - */ - - }else if($_POST["password"]==""){ - - $buffer = login_page_format_top(file_get_contents($xerte_toolkits_site->root_file_path . $xerte_toolkits_site->website_code_path . "mgt_top")); + /* + * Username left empty + */ - $buffer .= "

Please enter your password

"; + }else if($_POST["login"]==""){ - $buffer .= login_page_format_bottom(file_get_contents($xerte_toolkits_site->root_file_path . $xerte_toolkits_site->website_code_path . "login_bottom")); + $buffer = login_page_format_top(file_get_contents($xerte_toolkits_site->root_file_path . $xerte_toolkits_site->website_code_path . "mgt_top")); - echo $buffer; - - - /* - * Password and username provided, so try to authenticate - */ - - }else{ - - if(($_POST["login"]==$xerte_toolkits_site->admin_username)&&($_POST["password"]==$xerte_toolkits_site->admin_password)){ - - $_SESSION['toolkits_logon_id'] = "site_administrator"; + $buffer .= "

Please enter your username

"; - require $xerte_toolkits_site->php_library_path . "database_library.php"; + $buffer .= login_page_format_bottom(file_get_contents($xerte_toolkits_site->root_file_path . $xerte_toolkits_site->website_code_path . "login_bottom")); - require $xerte_toolkits_site->php_library_path . "user_library.php"; + echo $buffer; - $_SESSION['toolkits_logon_username'] = "adminuser"; + /* + * Password left empty + */ - $mysql_id=database_connect("management.php database connect success","management.php database connect fail"); - - /* - * Check the user is set as an admin in the usertype record in the logindetails table, and display the page - */ - - echo file_get_contents($xerte_toolkits_site->website_code_path . "admin_headers"); + }else if($_POST["password"]==""){ - echo ""; + /* + * Password and username provided, so try to authenticate + */ - echo admin_page_format_top(file_get_contents($xerte_toolkits_site->website_code_path . "admin_top")); + }else{ - echo file_get_contents($xerte_toolkits_site->website_code_path . "admin_middle"); - + if(($_POST["login"]==$xerte_toolkits_site->admin_username)&&($_POST["password"]==$xerte_toolkits_site->admin_password)){ - }else{ - - /* - * Wrong password message - */ + $_SESSION['toolkits_logon_id'] = "site_administrator"; - $buffer = login_page_format_top(file_get_contents($xerte_toolkits_site->root_file_path . $xerte_toolkits_site->website_code_path . "login_top")); + require $xerte_toolkits_site->php_library_path . "database_library.php"; - $buffer .= "

Sorry that password combination was not correct

"; + require $xerte_toolkits_site->php_library_path . "user_library.php"; - $buffer .= login_page_format_bottom(file_get_contents($xerte_toolkits_site->root_file_path . $xerte_toolkits_site->website_code_path . "login_bottom")); - echo $buffer; + $_SESSION['toolkits_logon_username'] = "adminuser"; - } + $mysql_id=database_connect("management.php database connect success","management.php database connect fail"); - } - - } + /* + * Check the user is set as an admin in the usertype record in the logindetails table, and display the page + */ + + echo file_get_contents($xerte_toolkits_site->website_code_path . "admin_headers"); + + echo ""; + + echo admin_page_format_top(file_get_contents($xerte_toolkits_site->website_code_path . "admin_top")); + + echo file_get_contents($xerte_toolkits_site->website_code_path . "admin_middle"); + + + }else{ + + /* + * Wrong password message + */ + + $buffer = login_page_format_top(file_get_contents($xerte_toolkits_site->root_file_path . $xerte_toolkits_site->website_code_path . "login_top")); + + $buffer .= "

Sorry that password combination was not correct

"; + + $buffer .= login_page_format_bottom(file_get_contents($xerte_toolkits_site->root_file_path . $xerte_toolkits_site->website_code_path . "login_bottom")); + echo $buffer; + + } + + } + +} ?>