");?>
load_user()"); require_once "../config/config.php"; if(isset($_GET["update_id"]) && $_GET["rid"]==$_SESSION["rid"]-1){ $tid=$_GET["update_id"]; $perms=get_perm_string(); $sql="UPDATE users SET role = '$perms' WHERE id=$tid"; $stmt = mysqli_prepare($link, $sql); mysqli_stmt_execute($stmt); } if(isset($_POST['username'])) { $username_td=$_POST['username']; $username_td=htmlspecialchars($username_td); $sql="DELETE FROM users WHERE username = '$username_td';"; //echo($sql); $stmt = mysqli_prepare($link, $sql); mysqli_stmt_execute($stmt); deleteDirectory("/var/www/html/user_files/$username_td/"); log_("Deleted $username_td","BAN:DELETION"); } else if(isset($_POST["ban"])) { $username_td=htmlspecialchars($_POST["ban"]); $reason=htmlspecialchars($_POST["reason"]); $sql="UPDATE users SET banned = 1, banned_reason='$reason' WHERE username='$username_td'"; $stmt = mysqli_prepare($link, $sql); mysqli_stmt_execute($stmt); log_("Banned $username_td","BAN:BAN"); } else if(isset($_POST["unban"])) { $username_td=htmlspecialchars($_POST["unban"]); $sql="UPDATE users SET banned = 0 WHERE username='$username_td'"; $stmt = mysqli_prepare($link, $sql); mysqli_stmt_execute($stmt); log_("Unanned $username_td","BAN:UNBAN"); } //how many users do we have? $cnt=0; $sql="SELECT COUNT(*) FROM users"; if($stmt = mysqli_prepare($link, $sql)){ // Bind variables to the prepared statement as parameters // Attempt to execute the prepared statement if(mysqli_stmt_execute($stmt)){ // Store result mysqli_stmt_store_result($stmt); mysqli_stmt_bind_result($stmt, $cnt); if(mysqli_stmt_fetch($stmt)){ } } else{ echo "