admins.php 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292
  1. <?php
  2. require_once __DIR__ . '/../config.php';
  3. require_once __DIR__ . '/../includes/functions.php';
  4. // Check admin login
  5. if (!isset($_SESSION['admin_logged_in']) || !$_SESSION['admin_logged_in']) {
  6. header('Location: login.php');
  7. exit;
  8. }
  9. $pageTitle = 'Admins verwalten';
  10. $message = '';
  11. $messageType = '';
  12. function isValidAdminPasswordInput($password) {
  13. return is_string($password) && strlen($password) >= 8;
  14. }
  15. $adminAccounts = getAdminAccounts();
  16. function isValidAdminEmailInput($email) {
  17. return isValidAdminEmail($email);
  18. }
  19. if ($_SERVER['REQUEST_METHOD'] === 'POST') {
  20. if (isset($_POST['add_admin'])) {
  21. $username = normalizeAdminUsername($_POST['username'] ?? '');
  22. $description = normalizeAdminDescription($_POST['description'] ?? '');
  23. $email = normalizeAdminEmail($_POST['email'] ?? '');
  24. $password = $_POST['password'] ?? '';
  25. $passwordConfirm = $_POST['password_confirm'] ?? '';
  26. if (!isValidAdminUsername($username)) {
  27. $message = 'Ungültiger Benutzername. Erlaubt: 3-50 Zeichen (Buchstaben, Zahlen, Punkt, Unterstrich, Bindestrich).';
  28. $messageType = 'error';
  29. } elseif (isset($adminAccounts[$username])) {
  30. $message = 'Dieser Benutzername existiert bereits.';
  31. $messageType = 'error';
  32. } elseif (!isValidAdminDescription($description)) {
  33. $message = 'Beschreibung ist erforderlich (max. 120 Zeichen).';
  34. $messageType = 'error';
  35. } elseif (!isValidAdminEmailInput($email)) {
  36. $message = 'Gültige E-Mail ist erforderlich.';
  37. $messageType = 'error';
  38. } elseif (!isValidAdminPasswordInput($password)) {
  39. $message = 'Passwort muss mindestens 8 Zeichen lang sein.';
  40. $messageType = 'error';
  41. } elseif ($password !== $passwordConfirm) {
  42. $message = 'Passwort und Bestätigung stimmen nicht überein.';
  43. $messageType = 'error';
  44. } else {
  45. $adminAccounts[$username] = [
  46. 'password_hash' => password_hash($password, PASSWORD_BCRYPT),
  47. 'description' => $description,
  48. 'email' => $email
  49. ];
  50. saveAdminAccounts($adminAccounts);
  51. $message = 'Admin wurde erfolgreich angelegt.';
  52. $messageType = 'success';
  53. }
  54. }
  55. if (isset($_POST['update_description'])) {
  56. $targetUsername = normalizeAdminUsername($_POST['target_username'] ?? '');
  57. $description = normalizeAdminDescription($_POST['description'] ?? '');
  58. $email = normalizeAdminEmail($_POST['email'] ?? '');
  59. if (!isset($adminAccounts[$targetUsername])) {
  60. $message = 'Admin nicht gefunden.';
  61. $messageType = 'error';
  62. } elseif (!isValidAdminDescription($description)) {
  63. $message = 'Beschreibung ist erforderlich (max. 120 Zeichen).';
  64. $messageType = 'error';
  65. } elseif (!isValidAdminEmailInput($email)) {
  66. $message = 'Gültige E-Mail ist erforderlich.';
  67. $messageType = 'error';
  68. } else {
  69. $adminAccounts[$targetUsername]['description'] = $description;
  70. $adminAccounts[$targetUsername]['email'] = $email;
  71. saveAdminAccounts($adminAccounts);
  72. $message = 'Beschreibung und E-Mail wurden aktualisiert.';
  73. $messageType = 'success';
  74. }
  75. }
  76. if (isset($_POST['change_password'])) {
  77. $targetUsername = normalizeAdminUsername($_POST['target_username'] ?? '');
  78. $newPassword = $_POST['new_password'] ?? '';
  79. $newPasswordConfirm = $_POST['new_password_confirm'] ?? '';
  80. if (!isset($adminAccounts[$targetUsername])) {
  81. $message = 'Admin nicht gefunden.';
  82. $messageType = 'error';
  83. } elseif (!isValidAdminPasswordInput($newPassword)) {
  84. $message = 'Passwort muss mindestens 8 Zeichen lang sein.';
  85. $messageType = 'error';
  86. } elseif ($newPassword !== $newPasswordConfirm) {
  87. $message = 'Passwort und Bestätigung stimmen nicht überein.';
  88. $messageType = 'error';
  89. } else {
  90. $adminAccounts[$targetUsername]['password_hash'] = password_hash($newPassword, PASSWORD_BCRYPT);
  91. saveAdminAccounts($adminAccounts);
  92. $message = 'Passwort wurde aktualisiert.';
  93. $messageType = 'success';
  94. }
  95. }
  96. if (isset($_POST['delete_admin'])) {
  97. $targetUsername = normalizeAdminUsername($_POST['target_username'] ?? '');
  98. if (!isset($adminAccounts[$targetUsername])) {
  99. $message = 'Admin nicht gefunden.';
  100. $messageType = 'error';
  101. } else {
  102. unset($adminAccounts[$targetUsername]);
  103. saveAdminAccounts($adminAccounts);
  104. if (isset($_SESSION['admin_username']) && $_SESSION['admin_username'] === $targetUsername) {
  105. $_SESSION['admin_logged_in'] = false;
  106. unset($_SESSION['admin_username']);
  107. session_destroy();
  108. header('Location: login.php');
  109. exit;
  110. }
  111. $message = 'Admin wurde gelöscht.';
  112. $messageType = 'success';
  113. }
  114. }
  115. $adminAccounts = getAdminAccounts();
  116. }
  117. $currentAdmin = isset($_SESSION['admin_username']) ? normalizeAdminUsername($_SESSION['admin_username']) : '';
  118. $changeUsername = normalizeAdminUsername($_GET['change'] ?? '');
  119. $selectedChangeUser = null;
  120. $editDescriptionUsername = normalizeAdminUsername($_GET['edit_description'] ?? '');
  121. $selectedDescriptionUser = null;
  122. if ($changeUsername !== '') {
  123. if (!isset($adminAccounts[$changeUsername])) {
  124. if ($message === '') {
  125. $message = 'Ausgewählter Admin wurde nicht gefunden.';
  126. $messageType = 'error';
  127. }
  128. } else {
  129. $selectedChangeUser = $changeUsername;
  130. }
  131. }
  132. if ($editDescriptionUsername !== '') {
  133. if (!isset($adminAccounts[$editDescriptionUsername])) {
  134. if ($message === '') {
  135. $message = 'Ausgewählter Admin wurde nicht gefunden.';
  136. $messageType = 'error';
  137. }
  138. } else {
  139. $selectedDescriptionUser = $editDescriptionUsername;
  140. }
  141. }
  142. ksort($adminAccounts);
  143. $bodyClass = 'admin-page';
  144. include __DIR__ . '/../includes/header.php';
  145. ?>
  146. <div class="admin-header">
  147. <h2>Admins verwalten</h2>
  148. <div>
  149. <a href="index.php" class="btn btn-secondary">Zurück zum Dashboard</a>
  150. </div>
  151. </div>
  152. <?php if ($message !== ''): ?>
  153. <div class="alert alert-<?php echo $messageType; ?>">
  154. <?php echo htmlspecialchars($message); ?>
  155. </div>
  156. <?php endif; ?>
  157. <div class="panel">
  158. <p><strong>Eingeloggt als:</strong> <?php echo htmlspecialchars($currentAdmin !== '' ? $currentAdmin : 'Unbekannt'); ?></p>
  159. </div>
  160. <div class="panel">
  161. <h3>Neuen Admin anlegen</h3>
  162. <form method="POST">
  163. <div class="form-group">
  164. <label for="username">Benutzername *</label>
  165. <input type="text" id="username" name="username" required maxlength="50" pattern="[A-Za-z0-9][A-Za-z0-9._-]{2,49}" placeholder="z.B. max.mustermann">
  166. </div>
  167. <div class="form-group">
  168. <label for="description">Beschreibung *</label>
  169. <input type="text" id="description" name="description" required maxlength="120" placeholder="z.B. Kassierer, Shop-Team">
  170. </div>
  171. <div class="form-group">
  172. <label for="email">E-Mail *</label>
  173. <input type="email" id="email" name="email" required maxlength="190" placeholder="z.B. max.mustermann@example.org">
  174. </div>
  175. <div class="form-group">
  176. <label for="password">Passwort (mind. 8 Zeichen) *</label>
  177. <input type="password" id="password" name="password" required minlength="8">
  178. </div>
  179. <div class="form-group">
  180. <label for="password_confirm">Passwort bestätigen *</label>
  181. <input type="password" id="password_confirm" name="password_confirm" required minlength="8">
  182. </div>
  183. <button type="submit" name="add_admin" class="btn">Admin anlegen</button>
  184. </form>
  185. </div>
  186. <div class="panel">
  187. <h3>Admin-Liste</h3>
  188. <div class="table-responsive">
  189. <table class="responsive-table">
  190. <thead>
  191. <tr>
  192. <th>Benutzername</th>
  193. <th>Beschreibung</th>
  194. <th>E-Mail</th>
  195. <th>Aktionen</th>
  196. </tr>
  197. </thead>
  198. <tbody>
  199. <?php foreach ($adminAccounts as $username => $account): ?>
  200. <tr>
  201. <td data-label="Benutzername">
  202. <strong><?php echo htmlspecialchars($username); ?></strong>
  203. <?php if ($username === $currentAdmin): ?>
  204. <span class="status status-open" style="margin-left: 0.5rem;">Du</span>
  205. <?php endif; ?>
  206. </td>
  207. <td data-label="Beschreibung">
  208. <?php echo htmlspecialchars($account['description']); ?>
  209. </td>
  210. <td data-label="E-Mail">
  211. <?php echo htmlspecialchars($account['email']); ?>
  212. </td>
  213. <td data-label="Aktionen">
  214. <a href="admins.php?edit_description=<?php echo urlencode($username); ?>" class="btn btn-small btn-secondary">Profil ändern</a>
  215. <a href="admins.php?change=<?php echo urlencode($username); ?>" class="btn btn-small btn-secondary">Passwort ändern</a>
  216. <form method="POST" style="display: inline;" onsubmit="return confirm('Admin wirklich löschen?');">
  217. <input type="hidden" name="target_username" value="<?php echo htmlspecialchars($username); ?>">
  218. <button type="submit" name="delete_admin" class="btn btn-small">Löschen</button>
  219. </form>
  220. </td>
  221. </tr>
  222. <?php endforeach; ?>
  223. </tbody>
  224. </table>
  225. </div>
  226. </div>
  227. <?php if ($selectedDescriptionUser !== null): ?>
  228. <div class="panel">
  229. <h3>Profil ändern: <?php echo htmlspecialchars($selectedDescriptionUser); ?></h3>
  230. <form method="POST">
  231. <input type="hidden" name="target_username" value="<?php echo htmlspecialchars($selectedDescriptionUser); ?>">
  232. <div class="form-group">
  233. <label for="description_edit">Beschreibung *</label>
  234. <input type="text" id="description_edit" name="description" maxlength="120" required value="<?php echo htmlspecialchars($adminAccounts[$selectedDescriptionUser]['description']); ?>">
  235. </div>
  236. <div class="form-group">
  237. <label for="email_edit">E-Mail *</label>
  238. <input type="email" id="email_edit" name="email" maxlength="190" required value="<?php echo htmlspecialchars($adminAccounts[$selectedDescriptionUser]['email']); ?>">
  239. </div>
  240. <button type="submit" name="update_description" class="btn">Profil speichern</button>
  241. <a href="admins.php" class="btn btn-secondary">Abbrechen</a>
  242. </form>
  243. </div>
  244. <?php endif; ?>
  245. <?php if ($selectedChangeUser !== null): ?>
  246. <div class="panel">
  247. <h3>Passwort ändern: <?php echo htmlspecialchars($selectedChangeUser); ?></h3>
  248. <form method="POST">
  249. <input type="hidden" name="target_username" value="<?php echo htmlspecialchars($selectedChangeUser); ?>">
  250. <div class="form-group">
  251. <label for="new_password">Neues Passwort (mind. 8 Zeichen) *</label>
  252. <input type="password" id="new_password" name="new_password" required minlength="8">
  253. </div>
  254. <div class="form-group">
  255. <label for="new_password_confirm">Neues Passwort bestätigen *</label>
  256. <input type="password" id="new_password_confirm" name="new_password_confirm" required minlength="8">
  257. </div>
  258. <button type="submit" name="change_password" class="btn">Passwort speichern</button>
  259. <a href="admins.php" class="btn btn-secondary">Abbrechen</a>
  260. </form>
  261. </div>
  262. <?php endif; ?>
  263. <?php include __DIR__ . '/../includes/footer.php'; ?>