Main Navigation
<?php
$connection = mysql_connect($hostname, $user, $pass) or die ("Unable to connect!");
if ($ulevel == admin)
{
$query = "SELECT * FROM pages ORDER BY id ASC";
$result = mysql_db_query($db, $query, $connection) or die ("Could not execute query: $query. " . mysql_error());
while(list($aname, $name, $content, $hidden)= mysql_fetch_array($result))
{
echo "-----$name ";
}
}
else
{
$query = "SELECT * FROM pages WHERE hidden = 'n' ORDER BY id ASC";
$result = mysql_db_query($db, $query, $connection) or die ("Could not execute query: $query. " . mysql_error());
while(list($aname, $name, $content, $hidden)= mysql_fetch_array($result))
{
echo "-----$name ";
}
}
?>
|
<?php
if (!$page)
{
$page="main";
}
if ($page)
{
$query = "SELECT * FROM pages WHERE aname = '$page'";
$result = mysql_db_query($db, $query, $connection) or die ("Could not execute query: $query. " . mysql_error());
while(list($aname, $name, $content, $hidden, $id)= mysql_fetch_array($result))
{
echo "$name ";
echo " $content";
}
}
//usercp
if ($page == usercp)
{
if (!$action)
{
echo "Change Password";
echo " Change Email";
echo " Change Bio
";
$user_info = "SELECT * FROM users WHERE username = '$uname'";
$user_info_result = mysql_db_query($db, $user_info, $connection) or die ("Could not execute query: $user_info. " . mysql_error());
while(list($id, $username, $password, $userlevel, $email, $bio) = mysql_fetch_array($user_info_result))
{
echo "Username: $username ";
echo "Password: $password ";
echo "Userlevel: $userlevel ";
echo "Email: $email ";
echo "Bio: $bio ";
}
}
//password edit
if ($action == change_pass)
{
if (!$submit)
{
echo "";
echo "";
echo "";
$user_info = "SELECT * FROM users WHERE username = '$uname'";
$user_info_result = mysql_db_query($db, $user_info, $connection) or die ("Could not execute query: $user_info. " . mysql_error());
while(list($id, $username, $password, $userlevel, $email, $bio) = mysql_fetch_array($user_info_result))
{
echo "New Pass ";
}
echo "";
}
else
{
$user_pass = "UPDATE users SET password = '$password2' WHERE username = '$uname'";
$user_pass_result = mysql_db_query($db, $user_pass, $connection) or die ("Could not execute query: $user_pass. " . mysql_error());
echo "Password Changed";
}
}
//password edit code end
//email edit
if ($action == change_email)
{
if (!$submit)
{
echo "";
echo "";
echo "";
$user_info = "SELECT * FROM users WHERE username = '$uname'";
$user_info_result = mysql_db_query($db, $user_info, $connection) or die ("Could not execute query: $user_info. " . mysql_error());
while(list($id, $username, $password, $userlevel, $email, $bio) = mysql_fetch_array($user_info_result))
{
echo "New Email ";
}
echo "";
}
else
{
$user_email = "UPDATE users SET email = '$email2' WHERE username = '$uname'";
$user_email_result = mysql_db_query($db, $user_email, $connection) or die ("Could not execute query: $user_email. " . mysql_error());
echo "Email Changed";
}
}
//email edit code end
//bio edit
if ($action == change_bio)
{
if (!$submit)
{
echo "";
echo "";
echo "";
$user_info = "SELECT * FROM users WHERE username = '$uname'";
$user_info_result = mysql_db_query($db, $user_info, $connection) or die ("Could not execute query: $user_info. " . mysql_error());
while(list($id, $username, $password, $userlevel, $email, $bio) = mysql_fetch_array($user_info_result))
{
echo "Biography$bio ";
}
echo "";
}
else
{
$user_bio = "UPDATE users SET bio = '$bio2' WHERE username = '$uname'";
$user_bio_result = mysql_db_query($db, $user_bio, $connection) or die ("Could not execute query: $user_bio. " . mysql_error());
echo "Biography Changed";
}
}
//bio edit code end
}
//usercp code end
//memberlist
if ($page == memberlist)
{
if (!$userid)
{
$userlist = "SELECT * FROM users";
$userlist_result = mysql_db_query($db, $userlist, $connection) or die ("Could not execute query: $userlist. " . mysql_error());
echo "
";
while(list($id, $username, $password, $userlevel, $email, $bio)= mysql_fetch_array($userlist_result))
{
echo "$username | ";
}
echo " ";
}
else
{
$userlist = "SELECT * FROM users WHERE id = '$userid'";
$userlist_result = mysql_db_query($db, $userlist, $connection) or die ("Could not execute query: $userlist. " . mysql_error());
while(list($id, $username, $password, $userlevel, $email, $bio)= mysql_fetch_array($userlist_result))
{
echo "Name: $username Userlevel: $userlevel Email:email ";
echo "Bio: $bio
";
}
}
}
//memberlist end
//pmlist
if ($page == pm_list)
{
echo "";
$pm_list = "SELECT * FROM pm WHERE to2 = '$uname'";
$pm_list_result = mysql_db_query($db, $pm_list, $connection) or die ("Could not execute query: $pm_list. " . mysql_error());
echo "";
while(list($id, $to2, $from2, $subject, $message)= mysql_fetch_array($pm_list_result))
{
echo "Subject:$subject From: $from2 Delete
| ";
}
echo "New PM | ";
echo " ";
}
//pmlist end
//read pm
if ($page == read_pm)
{
echo "";
$pm_list = "SELECT * FROM pm WHERE id = '$pmid'";
$pm_list_result = mysql_db_query($db, $pm_list, $connection) or die ("Could not execute query: $pm_list. " . mysql_error());
while(list($id, $to2, $from2, $subject, $message)= mysql_fetch_array($pm_list_result))
{
echo "From: $from2 ";
echo "Subject: $subject ";
echo "Message: $message ";
echo "Reply";
}
echo "";
}
//read pm end
//new pm
if ($page == new_pm)
{
if (!$submit)
{
echo "";
echo "";
echo "";
$user_list = "SELECT * FROM users";
$user_list_result = mysql_db_query($db, $user_list, $connection) or die ("Could not execute query: $user_list. " . mysql_error());
while(list($id, $username, $password, $userlevel, $email, $bio)= mysql_fetch_array($user_list_result))
{
echo "$username";
}
echo " ";
echo "Subject: ";
echo " ";
echo "";
echo "";
}
else
{
$send_pm = "INSERT INTO pm (to2, from2, subject, message) VALUES ('$usern', '$uname', '$subject', '$message')";
$send_pm_result = mysql_db_query($db, $send_pm, $connection) or die ("Could not execute query: $send_pm. " . mysql_error());
if ($send_pm_result)
{
echo "PM sent to $usern!";
}
else
{
echo "Failed to send pm!";
}
}
}
//new pm end
//reply pm
if ($page == reply)
{
if (!$submit)
{
echo "";
echo "";
echo "";
echo "$usern";
echo " ";
echo "Subject: ";
echo " ";
echo "";
echo "";
}
else
{
$send_pm = "INSERT INTO pm (to2, from2, subject, message) VALUES ('$usern', '$uname', '$subject', '$message')";
$send_pm_result = mysql_db_query($db, $send_pm, $connection) or die ("Could not execute query: $send_pm. " . mysql_error());
if ($send_pm_result)
{
echo "PM sent to $usern!";
}
else
{
echo "Failed to send pm!";
}
}
}
//reply pm end
//delete pm
if ($page == delete_pm)
{
$delete_pm = "DELETE FROM pm WHERE id = '$pmid'";
$delete_pm_result = mysql_db_query($db, $delete_pm, $connection) or die ("Could not execute query: $delete_pm. " . mysql_error());
if ($delete_pm_result)
{
echo "PM deleted!";
}
else
{
echo "Failed to delete pm!";
}
}
//delete pm end
//login
if ($page == login)
{
if (! isset($uname))
{
if (!$submit)
{
?>
Username:
Password:
<?php
}
else
{
$hostname="localhost:5432";
$user="*******";
$pass="*******";
// connect and insert form data into database
$connection = mysql_connect($hostname, $user, $pass) or die ("Unable to connect!");
$query="SELECT * FROM users WHERE username = '$username1' AND password = '$password1'";
$result = mysql_db_query($db, $query, $connection) or die ("Could not execute query: $query. " . mysql_error());
while(list($id, $username, $password, $userlevel, $email, $bio) = mysql_fetch_array($result))
{
$uname = $username;
session_register(uname);
$ulevel = $userlevel;
session_register(ulevel);
echo "Welcome $uname! ";
echo "You are now logged in";
}
}
}
else
{
echo "You are already logged in $uname";
}
//login end
if ($action == logout)
{
echo "You are now logged out.";
session_destroy();
}
}
//register
if ($page == register)
{
if (! isset($uname))
{
if (!$submit)
{
?>
Username(between 3 and 14 characters):
Password:
<?php
}
else
{
$username=$_POST['username'];
$password=$_POST['password'];
if ($username && $password)
{
$register = "INSERT INTO users (username, password) VALUES ('$username', '$password')";
$register_result = mysql_db_query($db, $register, $connection) or die ("Could not execute query: $register. " . mysql_error());
// check for result code
if ($register_result)
{
echo " Registration Successfull. You may now login.";
}
else
{
echo "Failed to register";
}
}
else
{
echo "You need to fill out the whole form";
}
// close connection
mysql_close($connection);
}
}
else
{
echo "You are already registered and logged in.";
}
}
//register end
?>
<?php
if (isset($uname))
{
echo "Welcome, $uname. Userlevel: $ulevel ";
}
else
{
echo "Welcome guest. ";
}
?>
<?php
if ($page != register)
{
echo "Stats:";
$query2 = "SELECT * FROM pages";
$result2 = mysql_db_query($db, $query2, $connection) or die ("Could not execute query: $query2. " . mysql_error());
while(list($aname, $name, $content, $hidden)= mysql_fetch_array($result2))
{
if ($hidden == n)
{
$total_public_pages++;
}
}
echo " Pages: $total_public_pages ";
$users = "SELECT * FROM users";
$users_result = mysql_db_query($db, $users, $connection) or die ("Could not execute query: $users. " . mysql_error());
while(list($id, $username, $password, $userlevel)= mysql_fetch_array($users_result))
{
$total_users++;
}
echo "Users: $total_users";
}
?>
|
|