diff --git a/sys0-code/app/manage_user.php b/sys0-code/app/manage_user.php index e97064f..df94645 100644 --- a/sys0-code/app/manage_user.php +++ b/sys0-code/app/manage_user.php @@ -115,9 +115,9 @@ function load_user() $stmt = mysqli_prepare($link, $sql); mysqli_stmt_execute($stmt); } - if(isset($_POST['username'])) + if(isset($_GET['username']) && isset($_GET["delete"])) { - $username_td=$_POST['username']; + $username_td=$_GET['username']; $username_td=htmlspecialchars($username_td); $sql="DELETE FROM users WHERE username = '$username_td';"; //echo($sql); @@ -126,15 +126,6 @@ function load_user() deleteDirectory("/var/www/html/user_files/$username_td/"); log_("Deleted $username_td","BAN:DELETION"); } - else if(isset($_POST["ban"])) - { - $username_td=htmlspecialchars($_POST["ban"]); - $reason=htmlspecialchars($_POST["reason"]); - $sql="UPDATE users SET banned = 1, banned_reason='$reason' WHERE username='$username_td'"; - $stmt = mysqli_prepare($link, $sql); - mysqli_stmt_execute($stmt); - log_("Banned $username_td","BAN:BAN"); - } else if(isset($_POST["unban"])) { $username_td=htmlspecialchars($_POST["unban"]); @@ -278,7 +269,7 @@ function load_user() else echo('