'auth_mod'; $sql_value .= ( ( $sql_value != '' ) ? ', ' : '' ) . ( ( !isset($update_mod_status[$forum_id]) ) ? 0 : $update_mod_status[$forum_id]); $sql = "INSERT INTO " . AUTH_ACCESS_TABLE . " (forum_id, group_id, $sql_field) VALUES ($forum_id, $group_id, $sql_value)"; } else { $sql_values = ''; while ( list($auth_type, $value) = @each($update_acl_status[$forum_id]) ) { $sql_values .= ( ( $sql_values != '' ) ? ', ' : '' ) . $auth_type . ' = ' . $value; } $sql_values .= ( ( $sql_values != '' ) ? ', ' : '' ) . 'auth_mod = ' . ( ( !isset($update_mod_status[$forum_id]) ) ? 0 : $update_mod_status[$forum_id]); $sql = "UPDATE " . AUTH_ACCESS_TABLE . " SET $sql_values WHERE group_id = $group_id AND forum_id = $forum_id"; } if( !($result = $db->sql_query($sql)) ) { message_die(GENERAL_ERROR, "Couldn't update private forum permissions", "", __LINE__, __FILE__, $sql); } } } if ( $delete_sql != '' ) { $sql = "DELETE FROM " . AUTH_ACCESS_TABLE . " WHERE group_id = $group_id AND forum_id IN ($delete_sql)"; if( !($result = $db->sql_query($sql)) ) { message_die(GENERAL_ERROR, "Couldn't delete permission entries", "", __LINE__, __FILE__, $sql); } } $l_auth_return = ( $mode == 'user' ) ? $lang['Click_return_userauth'] : $lang['Click_return_groupauth']; $message = $lang['Auth_updated'] . '

' . sprintf($l_auth_return, '', '') . '

' . sprintf($lang['Click_return_admin_index'], '', ''); } // // Update user level to mod for appropriate users // $sql = "SELECT u.user_id FROM " . AUTH_ACCESS_TABLE . " aa, " . USER_GROUP_TABLE . " ug, " . USERS_TABLE . " u WHERE ug.group_id = aa.group_id AND u.user_id = ug.user_id AND ug.user_pending = 0 AND u.user_level NOT IN (" . MOD . ", " . ADMIN . ") GROUP BY u.user_id HAVING SUM(aa.auth_mod) > 0"; if ( !($result = $db->sql_query($sql)) ) { message_die(GENERAL_ERROR, "Couldn't obtain user/group permissions", "", __LINE__, __FILE__, $sql); } $set_mod = ''; while( $row = $db->sql_fetchrow($result) ) { $set_mod .= ( ( $set_mod != '' ) ? ', ' : '' ) . $row['user_id']; } $db->sql_freeresult($result); // // Update user level to user for appropriate users // switch ( SQL_LAYER ) { case 'postgresql': $sql = "SELECT u.user_id FROM " . USERS_TABLE . " u, " . USER_GROUP_TABLE . " ug, " . AUTH_ACCESS_TABLE . " aa WHERE ug.user_id = u.user_id AND aa.group_id = ug.group_id AND u.user_level NOT IN (" . USER . ", " . ADMIN . ") GROUP BY u.user_id HAVING SUM(aa.auth_mod) = 0 UNION ( SELECT u.user_id FROM " . USERS_TABLE . " u WHERE NOT EXISTS ( SELECT aa.auth_mod FROM " . USER_GROUP_TABLE . " ug, " . AUTH_ACCESS_TABLE . " aa WHERE ug.user_id = u.user_id AND aa.group_id = ug.group_id ) AND u.user_level NOT IN (" . USER . ", " . ADMIN . ") GROUP BY u.user_id )"; break; case 'oracle': $sql = "SELECT u.user_id FROM " . USERS_TABLE . " u, " . USER_GROUP_TABLE . " ug, " . AUTH_ACCESS_TABLE . " aa WHERE ug.user_id = u.user_id(+) AND aa.group_id = ug.group_id(+) AND u.user_level NOT IN (" . USER . ", " . ADMIN . ") GROUP BY u.user_id HAVING SUM(aa.auth_mod) = 0"; break; default: $sql = "SELECT u.user_id FROM ( ( " . USERS_TABLE . " u LEFT JOIN " . USER_GROUP_TABLE . " ug ON ug.user_id = u.user_id ) LEFT JOIN " . AUTH_ACCESS_TABLE . " aa ON aa.group_id = ug.group_id ) WHERE u.user_level NOT IN (" . USER . ", " . ADMIN . ") GROUP BY u.user_id HAVING SUM(aa.auth_mod) = 0"; break; } if ( !($result = $db->sql_query($sql)) ) { message_die(GENERAL_ERROR, "Couldn't obtain user/group permissions", "", __LINE__, __FILE__, $sql); } $unset_mod = ""; while( $row = $db->sql_fetchrow($result) ) { $unset_mod .= ( ( $unset_mod != '' ) ? ', ' : '' ) . $row['user_id']; } $db->sql_freeresult($result); if ( $set_mod != '' ) { $sql = "UPDATE " . USERS_TABLE . " SET user_level = " . MOD . " WHERE user_id IN ($set_mod)"; if( !($result = $db->sql_query($sql)) ) { message_die(GENERAL_ERROR, "Couldn't update user level", "", __LINE__, __FILE__, $sql); } } if ( $unset_mod != '' ) { $sql = "UPDATE " . USERS_TABLE . " SET user_level = " . USER . " WHERE user_id IN ($unset_mod)"; if( !($result = $db->sql_query($sql)) ) { message_die(GENERAL_ERROR, "Couldn't update user level", "", __LINE__, __FILE__, $sql); } } $sql = 'SELECT user_id FROM ' . USER_GROUP_TABLE . " WHERE group_id = $group_id"; $result = $db->sql_query($sql); $group_user = array(); while ($row = $db->sql_fetchrow($result)) { $group_user[$row['user_id']] = $row['user_id']; } $db->sql_freeresult($result); $sql = "SELECT ug.user_id, COUNT(auth_mod) AS is_auth_mod FROM " . AUTH_ACCESS_TABLE . " aa, " . USER_GROUP_TABLE . " ug WHERE ug.user_id IN (" . implode(', ', $group_user) . ") AND aa.group_id = ug.group_id AND aa.auth_mod = 1 GROUP BY ug.user_id"; if ( !($result = $db->sql_query($sql)) ) { message_die(GENERAL_ERROR, 'Could not obtain moderator status', '', __LINE__, __FILE__, $sql); } while ($row = $db->sql_fetchrow($result)) { if ($row['is_auth_mod']) { unset($group_user[$row['user_id']]); } } $db->sql_freeresult($result); if (sizeof($group_user)) { $sql = "UPDATE " . USERS_TABLE . " SET user_level = " . USER . " WHERE user_id IN (" . implode(', ', $group_user) . ") AND user_level = " . MOD; if ( !($result = $db->sql_query($sql)) ) { message_die(GENERAL_ERROR, 'Could not update user level', '', __LINE__, __FILE__, $sql); } } // Start Quick Administrator User Options and Information MOD if( $return_to_profile ) { $message = $lang['Auth_updated'] . '

' . sprintf($lang['Click_return_userprofile'], '', '') . '

' . sprintf($lang['Click_return_admin_index'], '', ''); } // End Quick Administrator User Options and Information MOD message_die(GENERAL_MESSAGE, $message); } } else if ( ( $mode == 'user' && ( isset($HTTP_POST_VARS['username']) || $user_id ) ) || ( $mode == 'group' && $group_id ) ) { if ( isset($HTTP_POST_VARS['username']) ) { $this_userdata = get_userdata($HTTP_POST_VARS['username'], true); if ( !is_array($this_userdata) ) { message_die(GENERAL_MESSAGE, $lang['No_such_user']); } $user_id = $this_userdata['user_id']; } // // Front end // $sql = "SELECT f.* FROM " . FORUMS_TABLE . " f, " . CATEGORIES_TABLE . " c WHERE f.cat_id = c.cat_id ORDER BY c.cat_order, f.forum_order ASC"; if ( !($result = $db->sql_query($sql)) ) { message_die(GENERAL_ERROR, "Couldn't obtain forum information", "", __LINE__, __FILE__, $sql); } $forum_access = array(); while( $row = $db->sql_fetchrow($result) ) { $forum_access[] = $row; } $db->sql_freeresult($result); if( empty($adv) ) { for($i = 0; $i < count($forum_access); $i++) { $forum_id = $forum_access[$i]['forum_id']; $forum_auth_level[$forum_id] = AUTH_ALL; for($j = 0; $j < count($forum_auth_fields); $j++) { $forum_access[$i][$forum_auth_fields[$j]] . ' :: '; if ( $forum_access[$i][$forum_auth_fields[$j]] == AUTH_ACL ) { $forum_auth_level[$forum_id] = AUTH_ACL; $forum_auth_level_fields[$forum_id][] = $forum_auth_fields[$j]; } } } } $sql = "SELECT u.user_id, u.username, u.user_level, g.group_id, g.group_name, g.group_single_user, ug.user_pending FROM " . USERS_TABLE . " u, " . GROUPS_TABLE . " g, " . USER_GROUP_TABLE . " ug WHERE "; $sql .= ( $mode == 'user' ) ? "u.user_id = $user_id AND ug.user_id = u.user_id AND g.group_id = ug.group_id" : "g.group_id = $group_id AND ug.group_id = g.group_id AND u.user_id = ug.user_id"; if ( !($result = $db->sql_query($sql)) ) { message_die(GENERAL_ERROR, "Couldn't obtain user/group information", "", __LINE__, __FILE__, $sql); } $ug_info = array(); while( $row = $db->sql_fetchrow($result) ) { $ug_info[] = $row; } $db->sql_freeresult($result); $sql = ( $mode == 'user' ) ? "SELECT aa.*, g.group_single_user FROM " . AUTH_ACCESS_TABLE . " aa, " . USER_GROUP_TABLE . " ug, " . GROUPS_TABLE. " g WHERE ug.user_id = $user_id AND g.group_id = ug.group_id AND aa.group_id = ug.group_id AND g.group_single_user = 1" : "SELECT * FROM " . AUTH_ACCESS_TABLE . " WHERE group_id = $group_id"; if ( !($result = $db->sql_query($sql)) ) { message_die(GENERAL_ERROR, "Couldn't obtain user/group permissions", "", __LINE__, __FILE__, $sql); } $auth_access = array(); $auth_access_count = array(); while( $row = $db->sql_fetchrow($result) ) { $auth_access[$row['forum_id']][] = $row; $auth_access_count[$row['forum_id']]++; } $db->sql_freeresult($result); $is_admin = ( $mode == 'user' ) ? ( ( $ug_info[0]['user_level'] == ADMIN && $ug_info[0]['user_id'] != ANONYMOUS ) ? 1 : 0 ) : 0; for($i = 0; $i < count($forum_access); $i++) { $forum_id = $forum_access[$i]['forum_id']; unset($prev_acl_setting); for($j = 0; $j < count($forum_auth_fields); $j++) { $key = $forum_auth_fields[$j]; $value = $forum_access[$i][$key]; switch( $value ) { case AUTH_ALL: case AUTH_REG: $auth_ug[$forum_id][$key] = 1; break; case AUTH_ACL: $auth_ug[$forum_id][$key] = ( !empty($auth_access_count[$forum_id]) ) ? check_auth(AUTH_ACL, $key, $auth_access[$forum_id], $is_admin) : 0; $auth_field_acl[$forum_id][$key] = $auth_ug[$forum_id][$key]; if ( isset($prev_acl_setting) ) { if ( $prev_acl_setting != $auth_ug[$forum_id][$key] && empty($adv) ) { $adv = 1; } } $prev_acl_setting = $auth_ug[$forum_id][$key]; break; case AUTH_MOD: $auth_ug[$forum_id][$key] = ( !empty($auth_access_count[$forum_id]) ) ? check_auth(AUTH_MOD, $key, $auth_access[$forum_id], $is_admin) : 0; break; case AUTH_ADMIN: $auth_ug[$forum_id][$key] = $is_admin; break; default: $auth_ug[$forum_id][$key] = 0; break; } } // // Is user a moderator? // $auth_ug[$forum_id]['auth_mod'] = ( !empty($auth_access_count[$forum_id]) ) ? check_auth(AUTH_MOD, 'auth_mod', $auth_access[$forum_id], 0) : 0; } $i = 0; @reset($auth_ug); while( list($forum_id, $user_ary) = @each($auth_ug) ) { if ( empty($adv) ) { if ( $forum_auth_level[$forum_id] == AUTH_ACL ) { $allowed = 1; for($j = 0; $j < count($forum_auth_level_fields[$forum_id]); $j++) { if ( !$auth_ug[$forum_id][$forum_auth_level_fields[$forum_id][$j]] ) { $allowed = 0; } } $optionlist_acl = ''; } else { $optionlist_acl = ' '; } } else { for($j = 0; $j < count($forum_access); $j++) { if ( $forum_access[$j]['forum_id'] == $forum_id ) { for($k = 0; $k < count($forum_auth_fields); $k++) { $field_name = $forum_auth_fields[$k]; if( $forum_access[$j][$field_name] == AUTH_ACL ) { $optionlist_acl_adv[$forum_id][$k] = ''; } } } } } $optionlist_mod = ''; $row_class = ( !( $i % 2 ) ) ? 'row2' : 'row1'; $row_color = ( !( $i % 2 ) ) ? $theme['td_color1'] : $theme['td_color2']; $template->assign_block_vars('forums', array( 'ROW_COLOR' => '#' . $row_color, 'ROW_CLASS' => $row_class, 'FORUM_NAME' => $forum_access[$i]['forum_name'], 'U_FORUM_AUTH' => append_sid("admin_forumauth.$phpEx?f=" . $forum_access[$i]['forum_id']), 'S_MOD_SELECT' => $optionlist_mod) ); if( !$adv ) { $template->assign_block_vars('forums.aclvalues', array( 'S_ACL_SELECT' => $optionlist_acl) ); } else { for($j = 0; $j < count($forum_auth_fields); $j++) { $template->assign_block_vars('forums.aclvalues', array( 'S_ACL_SELECT' => $optionlist_acl_adv[$forum_id][$j]) ); } } $i++; } // @reset($auth_user); if ( $mode == 'user' ) { $t_username = $ug_info[0]['username']; $s_user_type = ( $is_admin ) ? '' : ''; } else { $t_groupname = $ug_info[0]['group_name']; } $name = array(); $id = array(); for($i = 0; $i < count($ug_info); $i++) { if( ( $mode == 'user' && !$ug_info[$i]['group_single_user'] ) || $mode == 'grou