settings.php 27 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577
  1. <?php
  2. require_once __DIR__ . '/../config.php';
  3. require_once __DIR__ . '/../includes/functions.php';
  4. require_once __DIR__ . '/../includes/manage.php';
  5. // Check admin login
  6. if (!isset($_SESSION['admin_logged_in']) || !$_SESSION['admin_logged_in']) {
  7. header('Location: login.php');
  8. exit;
  9. }
  10. $pageTitle = 'Einstellungen';
  11. // This page rolls out updates and hands out backup archives, so every form on
  12. // it carries a CSRF token - including the admin forms, which are otherwise
  13. // identical to what admins.php did before.
  14. function settingsCsrfToken() {
  15. if (empty($_SESSION['settings_csrf_token'])) {
  16. $_SESSION['settings_csrf_token'] = bin2hex(random_bytes(32));
  17. }
  18. return $_SESSION['settings_csrf_token'];
  19. }
  20. function settingsCsrfValid($token) {
  21. return !empty($_SESSION['settings_csrf_token']) &&
  22. is_string($token) &&
  23. hash_equals($_SESSION['settings_csrf_token'], $token);
  24. }
  25. function isValidAdminPasswordInput($password) {
  26. return is_string($password) && strlen($password) >= 8;
  27. }
  28. // Every message on this page, rendered as .alert blocks in source order.
  29. // A single action can produce several: an update reports deployment, migrations
  30. // and hook failure separately.
  31. $notices = [];
  32. $adminAccounts = getAdminAccounts();
  33. if ($_SERVER['REQUEST_METHOD'] === 'POST') {
  34. if (!settingsCsrfValid($_POST['csrf_token'] ?? '')) {
  35. $notices[] = ['type' => 'error', 'text' => 'Ungültiges Sicherheitstoken. Bitte die Seite neu laden.'];
  36. } elseif (isset($_POST['create_backup'])) {
  37. try {
  38. $record = manageBackupCreate('manual');
  39. $notices[] = ['type' => 'success', 'text' => sprintf(
  40. 'Backup erstellt: %s (%d Dateien, %s).',
  41. $record['filename'],
  42. $record['file_count'],
  43. manageFormatBytes((int) $record['size'])
  44. )];
  45. // A failed upload is a warning, never an error: the local archive
  46. // is complete and valid either way.
  47. foreach ($record['remote_uploads'] as $upload) {
  48. if (empty($upload['success'])) {
  49. $notices[] = ['type' => 'warning', 'text' => 'Upload an ' . $upload['target'] .
  50. ' fehlgeschlagen: ' . ($upload['error'] ?? 'unbekannter Fehler')];
  51. }
  52. }
  53. manageHeartbeatSendQuietly();
  54. } catch (Throwable $exception) {
  55. $notices[] = ['type' => 'error', 'text' => 'Backup fehlgeschlagen: ' . $exception->getMessage()];
  56. }
  57. } elseif (isset($_POST['download_backup'])) {
  58. try {
  59. $path = manageBackupPath($_POST['filename'] ?? '');
  60. $handle = fopen($path, 'rb');
  61. $size = filesize($path);
  62. if ($handle === false || $size === false) {
  63. throw new RuntimeException('Das Backup konnte nicht geöffnet werden.');
  64. }
  65. header('Content-Type: application/zip');
  66. header('Content-Disposition: attachment; filename="' . addcslashes(basename($path), '"\\') . '"');
  67. header('Content-Length: ' . $size);
  68. header('Cache-Control: private, no-store');
  69. header('X-Content-Type-Options: nosniff');
  70. fpassthru($handle);
  71. fclose($handle);
  72. exit;
  73. } catch (Throwable $exception) {
  74. $notices[] = ['type' => 'error', 'text' => 'Download fehlgeschlagen: ' . $exception->getMessage()];
  75. }
  76. } elseif (isset($_POST['apply_update'])) {
  77. try {
  78. $result = manageUpdateApply(['force' => !empty($_POST['force'])]);
  79. $notices[] = ['type' => 'success', 'text' => sprintf(
  80. 'Update ausgerollt: %s → %s. %d Dateien kopiert, %d gesichert, %d übersprungen.',
  81. $result['from_version'] !== '' ? $result['from_version'] : 'unbekannt',
  82. $result['to_version'],
  83. $result['copied'],
  84. $result['backed_up'],
  85. $result['skipped']
  86. )];
  87. $notices[] = ['type' => 'info', 'text' => 'Die überschriebenen Dateien liegen unter ' .
  88. $result['backup_dir'] . ' - nur für eine manuelle Wiederherstellung, es gibt kein Rollback.'];
  89. // The files are live at this point. A failing post-update step is
  90. // therefore reported on its own, not as "update failed".
  91. $hook = $result['hook'];
  92. if (is_array($hook)) {
  93. $applied = $hook['migrations']['applied'] ?? [];
  94. if ($applied !== []) {
  95. $notices[] = ['type' => 'success', 'text' => 'Migrationen ausgeführt: ' . implode(', ', $applied)];
  96. }
  97. if (empty($hook['success'])) {
  98. if (!empty($hook['failed_migration'])) {
  99. $notices[] = ['type' => 'error', 'text' => 'Die Dateien wurden ausgerollt, aber die Migration "' .
  100. $hook['failed_migration'] . '" ist fehlgeschlagen: ' . ($hook['error'] ?? '')];
  101. $notices[] = ['type' => 'error', 'text' => 'Die restlichen Migrationen wurden nicht ausgeführt. ' .
  102. 'Nach Behebung der Ursache unten "Migrationen ausführen" verwenden.'];
  103. } else {
  104. $notices[] = ['type' => 'error', 'text' => 'Die Dateien wurden ausgerollt, aber der ' .
  105. 'Post-Update-Hook ist fehlgeschlagen: ' . ($hook['error'] ?? '')];
  106. }
  107. }
  108. }
  109. manageHeartbeatSendQuietly();
  110. } catch (Throwable $exception) {
  111. $notices[] = ['type' => 'error', 'text' => 'Update fehlgeschlagen: ' . $exception->getMessage()];
  112. }
  113. } elseif (isset($_POST['run_migrations'])) {
  114. $report = manageUpdateRunMigrations();
  115. if ($report['applied'] !== []) {
  116. $notices[] = ['type' => 'success', 'text' => 'Migrationen ausgeführt: ' . implode(', ', $report['applied'])];
  117. }
  118. if (!$report['success']) {
  119. $notices[] = ['type' => 'error', 'text' => 'Migration "' . $report['failed'] . '" ist fehlgeschlagen: ' .
  120. $report['error']];
  121. } elseif ($report['applied'] === []) {
  122. $notices[] = ['type' => 'info', 'text' => 'Es gibt keine offenen Migrationen.'];
  123. }
  124. } elseif (isset($_POST['send_heartbeat'])) {
  125. try {
  126. $result = manageHeartbeatSend();
  127. $notices[] = ['type' => 'success', 'text' => 'Status an den Manage-Server gemeldet. Aktuelles Release: ' .
  128. ($result['latest'] !== '' ? $result['latest'] : 'keines') . '.'];
  129. } catch (Throwable $exception) {
  130. $notices[] = ['type' => 'error', 'text' => 'Statusmeldung fehlgeschlagen: ' . $exception->getMessage()];
  131. }
  132. } elseif (isset($_POST['add_admin'])) {
  133. $username = normalizeAdminUsername($_POST['username'] ?? '');
  134. $description = normalizeAdminDescription($_POST['description'] ?? '');
  135. $email = normalizeAdminEmail($_POST['email'] ?? '');
  136. $password = $_POST['password'] ?? '';
  137. $passwordConfirm = $_POST['password_confirm'] ?? '';
  138. if (!isValidAdminUsername($username)) {
  139. $notices[] = ['type' => 'error', 'text' => 'Ungültiger Benutzername. Erlaubt: 3-50 Zeichen (Buchstaben, Zahlen, Punkt, Unterstrich, Bindestrich).'];
  140. } elseif (isset($adminAccounts[$username])) {
  141. $notices[] = ['type' => 'error', 'text' => 'Dieser Benutzername existiert bereits.'];
  142. } elseif (!isValidAdminDescription($description)) {
  143. $notices[] = ['type' => 'error', 'text' => 'Beschreibung ist erforderlich (max. 120 Zeichen).'];
  144. } elseif (!isValidAdminEmail($email)) {
  145. $notices[] = ['type' => 'error', 'text' => 'Gültige E-Mail ist erforderlich.'];
  146. } elseif (!isValidAdminPasswordInput($password)) {
  147. $notices[] = ['type' => 'error', 'text' => 'Passwort muss mindestens 8 Zeichen lang sein.'];
  148. } elseif ($password !== $passwordConfirm) {
  149. $notices[] = ['type' => 'error', 'text' => 'Passwort und Bestätigung stimmen nicht überein.'];
  150. } else {
  151. $adminAccounts[$username] = [
  152. 'password_hash' => password_hash($password, PASSWORD_BCRYPT),
  153. 'description' => $description,
  154. 'email' => $email
  155. ];
  156. saveAdminAccounts($adminAccounts);
  157. $notices[] = ['type' => 'success', 'text' => 'Admin wurde erfolgreich angelegt.'];
  158. }
  159. } elseif (isset($_POST['update_description'])) {
  160. $targetUsername = normalizeAdminUsername($_POST['target_username'] ?? '');
  161. $description = normalizeAdminDescription($_POST['description'] ?? '');
  162. $email = normalizeAdminEmail($_POST['email'] ?? '');
  163. if (!isset($adminAccounts[$targetUsername])) {
  164. $notices[] = ['type' => 'error', 'text' => 'Admin nicht gefunden.'];
  165. } elseif (!isValidAdminDescription($description)) {
  166. $notices[] = ['type' => 'error', 'text' => 'Beschreibung ist erforderlich (max. 120 Zeichen).'];
  167. } elseif (!isValidAdminEmail($email)) {
  168. $notices[] = ['type' => 'error', 'text' => 'Gültige E-Mail ist erforderlich.'];
  169. } else {
  170. $adminAccounts[$targetUsername]['description'] = $description;
  171. $adminAccounts[$targetUsername]['email'] = $email;
  172. saveAdminAccounts($adminAccounts);
  173. $notices[] = ['type' => 'success', 'text' => 'Beschreibung und E-Mail wurden aktualisiert.'];
  174. }
  175. } elseif (isset($_POST['change_password'])) {
  176. $targetUsername = normalizeAdminUsername($_POST['target_username'] ?? '');
  177. $newPassword = $_POST['new_password'] ?? '';
  178. $newPasswordConfirm = $_POST['new_password_confirm'] ?? '';
  179. if (!isset($adminAccounts[$targetUsername])) {
  180. $notices[] = ['type' => 'error', 'text' => 'Admin nicht gefunden.'];
  181. } elseif (!isValidAdminPasswordInput($newPassword)) {
  182. $notices[] = ['type' => 'error', 'text' => 'Passwort muss mindestens 8 Zeichen lang sein.'];
  183. } elseif ($newPassword !== $newPasswordConfirm) {
  184. $notices[] = ['type' => 'error', 'text' => 'Passwort und Bestätigung stimmen nicht überein.'];
  185. } else {
  186. $adminAccounts[$targetUsername]['password_hash'] = password_hash($newPassword, PASSWORD_BCRYPT);
  187. saveAdminAccounts($adminAccounts);
  188. $notices[] = ['type' => 'success', 'text' => 'Passwort wurde aktualisiert.'];
  189. }
  190. } elseif (isset($_POST['delete_admin'])) {
  191. $targetUsername = normalizeAdminUsername($_POST['target_username'] ?? '');
  192. if (!isset($adminAccounts[$targetUsername])) {
  193. $notices[] = ['type' => 'error', 'text' => 'Admin nicht gefunden.'];
  194. } else {
  195. unset($adminAccounts[$targetUsername]);
  196. saveAdminAccounts($adminAccounts);
  197. if (isset($_SESSION['admin_username']) && $_SESSION['admin_username'] === $targetUsername) {
  198. $_SESSION['admin_logged_in'] = false;
  199. unset($_SESSION['admin_username']);
  200. session_destroy();
  201. header('Location: login.php');
  202. exit;
  203. }
  204. $notices[] = ['type' => 'success', 'text' => 'Admin wurde gelöscht.'];
  205. }
  206. }
  207. $adminAccounts = getAdminAccounts();
  208. }
  209. // Collected after the actions, so the page shows the state they produced.
  210. // Never throws: remote failures come back inside the array.
  211. $status = manageClientStatus();
  212. // No cron on this host, so the report to the Manage server rides along with
  213. // this page load - at most once an hour.
  214. manageHeartbeatSendIfDue();
  215. $updateAvailable = $status['update'] !== null && !empty($status['update']['available']);
  216. $latestVersion = $status['update']['latest'] ?? '';
  217. $currentAdmin = isset($_SESSION['admin_username']) ? normalizeAdminUsername($_SESSION['admin_username']) : '';
  218. $changeUsername = normalizeAdminUsername($_GET['change'] ?? '');
  219. $selectedChangeUser = null;
  220. $editDescriptionUsername = normalizeAdminUsername($_GET['edit_description'] ?? '');
  221. $selectedDescriptionUser = null;
  222. if ($changeUsername !== '') {
  223. if (!isset($adminAccounts[$changeUsername])) {
  224. $notices[] = ['type' => 'error', 'text' => 'Ausgewählter Admin wurde nicht gefunden.'];
  225. } else {
  226. $selectedChangeUser = $changeUsername;
  227. }
  228. }
  229. if ($editDescriptionUsername !== '') {
  230. if (!isset($adminAccounts[$editDescriptionUsername])) {
  231. $notices[] = ['type' => 'error', 'text' => 'Ausgewählter Admin wurde nicht gefunden.'];
  232. } else {
  233. $selectedDescriptionUser = $editDescriptionUsername;
  234. }
  235. }
  236. ksort($adminAccounts);
  237. $csrfToken = settingsCsrfToken();
  238. $bodyClass = 'admin-page';
  239. include __DIR__ . '/../includes/header.php';
  240. ?>
  241. <div class="admin-header">
  242. <h2>Einstellungen</h2>
  243. <div>
  244. <a href="index.php" class="btn btn-secondary">Zurück zum Dashboard</a>
  245. </div>
  246. </div>
  247. <?php foreach ($notices as $notice): ?>
  248. <div class="alert alert-<?php echo htmlspecialchars($notice['type']); ?>">
  249. <?php echo htmlspecialchars($notice['text']); ?>
  250. </div>
  251. <?php endforeach; ?>
  252. <?php if (!$status['configured']): ?>
  253. <div class="alert alert-warning">
  254. Der Manage-Client ist nicht konfiguriert. Ohne <code>MANAGE_SERVER_URL</code>, <code>MANAGE_INSTANCE</code>
  255. und <code>MANAGE_TOKEN</code> in <code>config.php</code> funktionieren Update-Prüfung und Backup-Upload nicht.
  256. Lokale Backups lassen sich trotzdem erstellen.
  257. </div>
  258. <?php endif; ?>
  259. <div class="admin-stats">
  260. <div class="stat-card">
  261. <h3>Installierte Version</h3>
  262. <div class="stat-value"><?php echo htmlspecialchars($status['version'] !== '' ? $status['version'] : 'unbekannt'); ?></div>
  263. </div>
  264. <div class="stat-card">
  265. <h3>Aktuelles Release</h3>
  266. <div class="stat-value"><?php echo htmlspecialchars($latestVersion !== '' ? $latestVersion : '–'); ?></div>
  267. </div>
  268. <div class="stat-card">
  269. <h3>Lokale Backups</h3>
  270. <div class="stat-value"><?php echo count($status['backups']); ?></div>
  271. </div>
  272. <div class="stat-card">
  273. <h3>Letztes Backup</h3>
  274. <div class="stat-value" style="font-size: 1.2rem;">
  275. <?php echo $status['last_backup_at'] !== null ? htmlspecialchars(formatDate($status['last_backup_at'])) : 'nie'; ?>
  276. </div>
  277. </div>
  278. </div>
  279. <div class="panel">
  280. <h3>System</h3>
  281. <?php if ($status['update_error'] !== null): ?>
  282. <div class="alert alert-warning">
  283. Die Update-Prüfung ist fehlgeschlagen: <?php echo htmlspecialchars($status['update_error']); ?>
  284. </div>
  285. <?php elseif ($updateAvailable): ?>
  286. <div class="alert alert-warning">
  287. Version <?php echo htmlspecialchars($latestVersion); ?> steht bereit. Vor dem Ausrollen sollte ein
  288. aktuelles Backup vorliegen – ein Update lässt sich nicht zurücknehmen.
  289. </div>
  290. <?php elseif ($status['configured']): ?>
  291. <div class="alert alert-success">Der Shop ist auf dem aktuellen Stand.</div>
  292. <?php endif; ?>
  293. <div class="table-responsive">
  294. <table class="responsive-table">
  295. <tbody>
  296. <tr>
  297. <td data-label="Instanz"><strong>Instanz</strong></td>
  298. <td><?php echo htmlspecialchars($status['instance'] !== '' ? $status['instance'] : '–'); ?></td>
  299. </tr>
  300. <tr>
  301. <td data-label="Manage-Server"><strong>Manage-Server</strong></td>
  302. <td><?php echo htmlspecialchars($status['server_url'] !== '' ? $status['server_url'] : '–'); ?></td>
  303. </tr>
  304. <tr>
  305. <td data-label="PHP-Version"><strong>PHP-Version</strong></td>
  306. <td><?php echo htmlspecialchars($status['php_version']); ?></td>
  307. </tr>
  308. <tr>
  309. <td data-label="Offene Migrationen"><strong>Offene Migrationen</strong></td>
  310. <td><?php echo count($status['pending_migrations']); ?></td>
  311. </tr>
  312. </tbody>
  313. </table>
  314. </div>
  315. <form method="POST" style="margin-top: 1rem;" onsubmit="return confirm('Update jetzt ausrollen? Dateien werden überschrieben und es gibt kein Rollback.');">
  316. <input type="hidden" name="csrf_token" value="<?php echo htmlspecialchars($csrfToken); ?>">
  317. <div class="form-group">
  318. <label>
  319. <input type="checkbox" name="force" value="1">
  320. Erneut ausrollen, auch wenn keine neuere Version vorliegt
  321. </label>
  322. </div>
  323. <button type="submit" name="apply_update" class="btn">Update ausrollen</button>
  324. <button type="submit" name="send_heartbeat" class="btn btn-secondary">Status melden</button>
  325. </form>
  326. </div>
  327. <div class="panel">
  328. <h3>Backup</h3>
  329. <p>
  330. Gesichert werden die Daten unter <code>data/</code> und die Produktbilder unter
  331. <code>assets/images/</code>. Lokal bleiben die letzten
  332. <?php echo (int) MANAGE_BACKUP_LOCAL_RETENTION; ?> Archive erhalten, jedes wird zusätzlich an den
  333. Manage-Server übertragen.
  334. <?php if ((int) MANAGE_BACKUP_AUTO_INTERVAL_SECONDS > 0): ?>
  335. Zusätzlich erstellt das Dashboard automatisch alle
  336. <?php echo (int) round(MANAGE_BACKUP_AUTO_INTERVAL_SECONDS / 86400); ?> Tage ein Backup.
  337. <?php endif; ?>
  338. </p>
  339. <form method="POST">
  340. <input type="hidden" name="csrf_token" value="<?php echo htmlspecialchars($csrfToken); ?>">
  341. <button type="submit" name="create_backup" class="btn">Backup jetzt erstellen</button>
  342. </form>
  343. <?php if ($status['backups'] === []): ?>
  344. <p style="margin-top: 1rem;">Es wurde noch kein Backup erstellt.</p>
  345. <?php else: ?>
  346. <div class="table-responsive" style="margin-top: 1rem;">
  347. <table class="responsive-table">
  348. <thead>
  349. <tr>
  350. <th>Datei</th>
  351. <th>Erstellt</th>
  352. <th>Auslöser</th>
  353. <th>Dateien</th>
  354. <th>Größe</th>
  355. <th>Upload</th>
  356. <th>Aktionen</th>
  357. </tr>
  358. </thead>
  359. <tbody>
  360. <?php foreach ($status['backups'] as $backup): ?>
  361. <tr>
  362. <td data-label="Datei"><strong><?php echo htmlspecialchars($backup['filename']); ?></strong></td>
  363. <td data-label="Erstellt"><?php echo htmlspecialchars(formatDate($backup['created_at'])); ?></td>
  364. <td data-label="Auslöser"><?php echo htmlspecialchars($backup['trigger'] ?? ''); ?></td>
  365. <td data-label="Dateien"><?php echo (int) ($backup['file_count'] ?? 0); ?></td>
  366. <td data-label="Größe"><?php echo htmlspecialchars(manageFormatBytes((int) ($backup['size'] ?? 0))); ?></td>
  367. <td data-label="Upload">
  368. <?php
  369. $uploads = is_array($backup['remote_uploads'] ?? null) ? $backup['remote_uploads'] : [];
  370. if ($uploads === []) {
  371. echo '<span class="status status-expired">nicht übertragen</span>';
  372. } else {
  373. foreach ($uploads as $upload) {
  374. if (!empty($upload['success'])) {
  375. echo '<span class="status status-picked">' . htmlspecialchars($upload['target']) . ': OK</span>';
  376. } else {
  377. echo '<span class="status status-expired" title="' .
  378. htmlspecialchars($upload['error'] ?? '') . '">' .
  379. htmlspecialchars($upload['target']) . ': Fehler</span>';
  380. }
  381. }
  382. }
  383. ?>
  384. </td>
  385. <td data-label="Aktionen">
  386. <form method="POST" style="display: inline;">
  387. <input type="hidden" name="csrf_token" value="<?php echo htmlspecialchars($csrfToken); ?>">
  388. <input type="hidden" name="filename" value="<?php echo htmlspecialchars($backup['filename']); ?>">
  389. <button type="submit" name="download_backup" class="btn btn-small btn-secondary">Herunterladen</button>
  390. </form>
  391. </td>
  392. </tr>
  393. <?php endforeach; ?>
  394. </tbody>
  395. </table>
  396. </div>
  397. <?php endif; ?>
  398. </div>
  399. <?php if ($status['pending_migrations'] !== []): ?>
  400. <div class="panel">
  401. <h3>Offene Migrationen</h3>
  402. <p>Diese Migrationen wurden noch nicht ausgeführt:</p>
  403. <ul>
  404. <?php foreach ($status['pending_migrations'] as $migration): ?>
  405. <li><code><?php echo htmlspecialchars($migration['id']); ?></code></li>
  406. <?php endforeach; ?>
  407. </ul>
  408. <form method="POST">
  409. <input type="hidden" name="csrf_token" value="<?php echo htmlspecialchars($csrfToken); ?>">
  410. <button type="submit" name="run_migrations" class="btn">Migrationen ausführen</button>
  411. </form>
  412. </div>
  413. <?php endif; ?>
  414. <?php foreach ($status['errors'] as $error): ?>
  415. <div class="alert alert-warning"><?php echo htmlspecialchars($error); ?></div>
  416. <?php endforeach; ?>
  417. <div class="panel">
  418. <p><strong>Eingeloggt als:</strong> <?php echo htmlspecialchars($currentAdmin !== '' ? $currentAdmin : 'Unbekannt'); ?></p>
  419. </div>
  420. <div class="panel">
  421. <h3>Neuen Admin anlegen</h3>
  422. <form method="POST">
  423. <input type="hidden" name="csrf_token" value="<?php echo htmlspecialchars($csrfToken); ?>">
  424. <div class="form-group">
  425. <label for="username">Benutzername *</label>
  426. <input type="text" id="username" name="username" required maxlength="50" pattern="[A-Za-z0-9][A-Za-z0-9._-]{2,49}" placeholder="z.B. max.mustermann">
  427. </div>
  428. <div class="form-group">
  429. <label for="description">Beschreibung *</label>
  430. <input type="text" id="description" name="description" required maxlength="120" placeholder="z.B. Kassierer, Shop-Team">
  431. </div>
  432. <div class="form-group">
  433. <label for="email">E-Mail *</label>
  434. <input type="email" id="email" name="email" required maxlength="190" placeholder="z.B. max.mustermann@example.org">
  435. </div>
  436. <div class="form-group">
  437. <label for="password">Passwort (mind. 8 Zeichen) *</label>
  438. <input type="password" id="password" name="password" required minlength="8">
  439. </div>
  440. <div class="form-group">
  441. <label for="password_confirm">Passwort bestätigen *</label>
  442. <input type="password" id="password_confirm" name="password_confirm" required minlength="8">
  443. </div>
  444. <button type="submit" name="add_admin" class="btn">Admin anlegen</button>
  445. </form>
  446. </div>
  447. <div class="panel">
  448. <h3>Admin-Liste</h3>
  449. <div class="table-responsive">
  450. <table class="responsive-table">
  451. <thead>
  452. <tr>
  453. <th>Benutzername</th>
  454. <th>Beschreibung</th>
  455. <th>E-Mail</th>
  456. <th>Aktionen</th>
  457. </tr>
  458. </thead>
  459. <tbody>
  460. <?php foreach ($adminAccounts as $username => $account): ?>
  461. <tr>
  462. <td data-label="Benutzername">
  463. <strong><?php echo htmlspecialchars($username); ?></strong>
  464. <?php if ($username === $currentAdmin): ?>
  465. <span class="status status-open" style="margin-left: 0.5rem;">Du</span>
  466. <?php endif; ?>
  467. </td>
  468. <td data-label="Beschreibung">
  469. <?php echo htmlspecialchars($account['description']); ?>
  470. </td>
  471. <td data-label="E-Mail">
  472. <?php echo htmlspecialchars($account['email']); ?>
  473. </td>
  474. <td data-label="Aktionen">
  475. <a href="settings.php?edit_description=<?php echo urlencode($username); ?>" class="btn btn-small btn-secondary">Profil ändern</a>
  476. <a href="settings.php?change=<?php echo urlencode($username); ?>" class="btn btn-small btn-secondary">Passwort ändern</a>
  477. <form method="POST" style="display: inline;" onsubmit="return confirm('Admin wirklich löschen?');">
  478. <input type="hidden" name="csrf_token" value="<?php echo htmlspecialchars($csrfToken); ?>">
  479. <input type="hidden" name="target_username" value="<?php echo htmlspecialchars($username); ?>">
  480. <button type="submit" name="delete_admin" class="btn btn-small">Löschen</button>
  481. </form>
  482. </td>
  483. </tr>
  484. <?php endforeach; ?>
  485. </tbody>
  486. </table>
  487. </div>
  488. </div>
  489. <?php if ($selectedDescriptionUser !== null): ?>
  490. <div class="panel">
  491. <h3>Profil ändern: <?php echo htmlspecialchars($selectedDescriptionUser); ?></h3>
  492. <form method="POST">
  493. <input type="hidden" name="csrf_token" value="<?php echo htmlspecialchars($csrfToken); ?>">
  494. <input type="hidden" name="target_username" value="<?php echo htmlspecialchars($selectedDescriptionUser); ?>">
  495. <div class="form-group">
  496. <label for="description_edit">Beschreibung *</label>
  497. <input type="text" id="description_edit" name="description" maxlength="120" required value="<?php echo htmlspecialchars($adminAccounts[$selectedDescriptionUser]['description']); ?>">
  498. </div>
  499. <div class="form-group">
  500. <label for="email_edit">E-Mail *</label>
  501. <input type="email" id="email_edit" name="email" maxlength="190" required value="<?php echo htmlspecialchars($adminAccounts[$selectedDescriptionUser]['email']); ?>">
  502. </div>
  503. <button type="submit" name="update_description" class="btn">Profil speichern</button>
  504. <a href="settings.php" class="btn btn-secondary">Abbrechen</a>
  505. </form>
  506. </div>
  507. <?php endif; ?>
  508. <?php if ($selectedChangeUser !== null): ?>
  509. <div class="panel">
  510. <h3>Passwort ändern: <?php echo htmlspecialchars($selectedChangeUser); ?></h3>
  511. <form method="POST">
  512. <input type="hidden" name="csrf_token" value="<?php echo htmlspecialchars($csrfToken); ?>">
  513. <input type="hidden" name="target_username" value="<?php echo htmlspecialchars($selectedChangeUser); ?>">
  514. <div class="form-group">
  515. <label for="new_password">Neues Passwort (mind. 8 Zeichen) *</label>
  516. <input type="password" id="new_password" name="new_password" required minlength="8">
  517. </div>
  518. <div class="form-group">
  519. <label for="new_password_confirm">Neues Passwort bestätigen *</label>
  520. <input type="password" id="new_password_confirm" name="new_password_confirm" required minlength="8">
  521. </div>
  522. <button type="submit" name="change_password" class="btn">Passwort speichern</button>
  523. <a href="settings.php" class="btn btn-secondary">Abbrechen</a>
  524. </form>
  525. </div>
  526. <?php endif; ?>
  527. <?php include __DIR__ . '/../includes/footer.php'; ?>