<?php
session_start();
include('includes/config.php');
?>
<!DOCTYPE html>
<html>
<head>
<link href="style.css" rel="stylesheet" type="text/css">
<title>PDC - Pas de chance !</title>
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
<link rel="shortcut icon" type="image/x-icon" href="images/favicon.ico">
</head>
<body>
<header><a href='/'>Pas De Chance</a></header>
<?php include('includes/nav.php'); ?>
<?php
if(isset($_SESSION['Rang']))
{
if($_SESSION['Rang'] == 'Administrateur')
{
if(isset($_POST['membres']))
{
if(isset($_POST['action']))
{
$action = $_POST['action'];
$pseudo = $_POST['pseudo'];
}
if($action == 'Voir')
{
$reponse = $bdd->query('SELECT * from membres WHERE Pseudo = \''.$pseudo.'\'');
$data = $reponse->fetch();
echo 'Id : '.$data['Id'].'<br />';
echo 'Pseudo : '.$data['Pseudo'].'<br />';
echo 'Email : '.$data['Email'].'<br />';
if($data['Rang'] == '1')
{
$rang = 'Membre';
}
if($data['Rang'] == '2')
{
$rang = 'Modérateur';
}
if($data['Rang'] == '3')
{
$rang = 'Administrateur';
}
echo 'Rang : '.$rang.'';
}
if($action == 'Éditer' || $_GET['action'] == 'Éditer')
{
$reponse = $bdd->query('SELECT * from membres WHERE Pseudo = \''.$pseudo.'\'');
$data = $reponse->fetch();
echo '<form action="panel.php?action=Éditer" method="post">';
echo 'Pseudo : <input type="text" name="Pseudo" value="'.$data['Pseudo'].'"><br />';
echo 'Email : <input type="email" name="Email" value="'.$data['Email'].'"><br />';
if($data['Rang'] == '1')
{
$rang = 'Membre';
echo '<select name="rang"><option selected>Membre</option><option>Modérateur</option><option>Administrateur</option></select>';
}
if($data['Rang'] == '2')
{
$rang = 'Modérateur';
echo '<select name="rang"><option>Membre</option><option selected>Modérateur</option><option>Administrateur</option></select>';
}
if($data['Rang'] == '3')
{
$rang = 'Administrateur';
echo '<select name="rang"><option>Membre</option><option>Modérateur</option><option selected>Administrateur</option></select>';
}
echo '<input type=image value=submit src="images/valider.png" name="membres">';
echo '</form>';
if(isset($_POST['Edit']))
{
if($data['Rang'] == 'Membre')
{
$rang = '1';
}
if($data['Rang'] == 'Modérateur')
{
$rang = '2';
}
if($data['Rang'] == 'Administrateur')
{
$rang = '3';
}
$reponse = $bdd->query("UPDATE membres SET Pseudo = \"".$_POST['Pseudo']."\", Email = \"".$_POST['Email']."\", Rang = \"".$rang."\" WHERE Pseudo = \"".$_POST['Pseudo']."\"");
echo '<script>window.location.replace("panel.php")</script>';
}
}
if($action == 'Supprimer')
{
$reponse = $bdd->query('DELETE from membres WHERE Pseudo = \''.$pseudo.'\'');
echo '<script>window.location.replace("panel.php")</script>';
}
}
if(isset($_POST['news']))
{
if(isset($_POST['action']))
{
$action = $_POST['action'];
$titre = $_POST['titre_news'];
}
if($action == 'Écrire une news' || $_GET['action'] == 'ÉcrireNews')
{
echo '<form action="panel.php?action=ÉcrireNews" method="post">';
echo 'Titre : <input type="text" name="Titre" value=""><br />';
echo 'Contenu : <br /><textarea name="Contenu"><br />';
echo '<input type=image value=submit src="images/valider.png" name="news">';
echo '</form>';
if(isset($_POST['Titre']))
{
$reponse = $bdd->query("INSERT INTO news SET Titre = \"".$_POST['Titre']."\", Contenu = \"".$_POST['Contenu']."\", timestamp = \"".time()."\", Auteur = \"".$_SESSION['Pseudo']."\"");
echo '<script>window.location.replace("panel.php")</script>';
}
}
if($action == 'Lire')
{
$reponse = $bdd->query('SELECT * from news WHERE Titre = \''.$titre.'\'');
$data = $reponse->fetch();
echo 'Id : '.$data['Id'].'<br />';
echo 'Titre : '.$data['Titre'].'<br />';
echo 'Contenu : <br />'.$data['Contenu'].'<br />';
echo 'Le '.date('d/m/Y à h\hi', $data['timestamp']).' par '.$data['Auteur'].'';
}
if($action == 'Éditer' || $_GET['action'] == 'Éditer')
{
$reponse = $bdd->query('SELECT * from news WHERE Titre = \''.$titre.'\'');
$data = $reponse->fetch();
echo '<form action="panel.php?action=Éditer" method="post">';
echo 'Titre : <input type="text" name="Titre" value="'.$data['Titre'].'"><br />';
echo 'Contenu : <br /><textarea name="Contenu">'.$data['Contenu'].'</textarea><br />';
echo '<input type=image value=submit src="images/valider.png" name="news">';
echo '</form>';
$_SESSION['Titre'] = $data['Titre'];
if(isset($_POST['Edit']))
{
$reponse = $bdd->query("UPDATE news SET Titre = \"".$_POST['Titre']."\", Contenu = \"".$_POST['Contenu']."\" WHERE Titre = \"".$_SESSION['Titre']."\"");
echo '<script>window.location.replace("panel.php")</script>';
}
}
if($action == 'Supprimer')
{
$reponse = $bdd->query('DELETE from membres WHERE Pseudo = \''.$pseudo.'\'');
echo '<script>window.location.replace("panel.php")</script>';
}
}
if(isset($_POST['profils']))
{
if(isset($_POST['action']))
{
$action = $_POST['action'];
$pseudo = $_POST['pseudo'];
}
if($action == 'Voir')
{
$reponse = $bdd->query("SELECT * from profils WHERE Pseudo = \"".$pseudo."\"");
$data = $reponse->fetch();
echo 'Pseudo : '.$data['Pseudo'].'<br />';
echo 'Email : '.$data['Email'].'<br />';
echo 'Biographie : <br />'.$data['Biographique'].'';
}
if($action == 'Éditer' || $_GET['action'] == 'Edit')
{
$reponse = $bdd->query("SELECT * from profils WHERE Pseudo = \"".$pseudo."\"");
$data = $reponse->fetch();
echo '<form action="panel.php?action=Edit" method="post">';
echo 'Pseudo : <input type="text" name="Pseudo" value="'.$data['Pseudo'].'"><br />';
echo 'Email : <input type="email" name="Email" value="'.$data['Email'].'"><br />';
echo 'Biographie : <br /><textarea name="Biographie">'.$data['Biographie'].'</textarea><br />';
echo '<input type=image value=submit src="images/valider.png" name="profils">';
echo '</form>';
$_SESSION['Pseudo_profil_edit'] = $data['Pseudo'];
if(isset($_POST['Pseudo']))
{
$reponse = $bdd->query("UPDATE profils SET Pseudo = \"".$_POST['Pseudo']."\", Email = \"".$_POST['Email']."\", Biographie = \"".$_POST['Biographie']."\" WHERE Pseudo = \"".$_SESSION['Pseudo_profil_edit']."\"");
echo '<script>window.location.replace("panel.php")</script>';
}
}
}
echo '<fieldset><legend>Gestion Membres</legend>';
echo '<form action="" method="post">';
echo 'Action : <select name="action"><option selected></option><option>Voir</option><option>Éditer</option><option>Supprimer</option></select><br />';
echo '<select name="pseudo">';
echo '<option selected></select>';
$reponse = $bdd->query('SELECT * from membres ORDER BY Id');
while($donnees = $reponse->fetch())
{
echo '<option>'.$donnees['Pseudo'].'</option>';
}
echo '</select><br />';
echo '<input type=image value=submit src="images/valider.png" name="membres">';
echo '</form>';
echo '</fieldset>';
echo '<fieldset><legend>Gestion News</legend>';
echo '<form action="" method="post">';
echo 'Action : <select name="action"><option selected></option><option>Écrire une news</option><option>Lire</option><option>Éditer</option><option>Supprimer</option></select><br />';
echo 'Choississez laquelle : <select name="titre_news">';
echo '<option selected></option>';
$reponse = $bdd->query('SELECT * from news ORDER BY Id DESC');
while($donnees = $reponse->fetch())
{
echo '<option>'.$donnees['Titre'].'</option>';
}
echo '</select><br />';
echo '<input type=image value=submit src="images/valider.png" name="news">';
echo '</form>';
echo '</fieldset>';
echo '<fieldset><legend>Gestion Profils</legend>';
echo '<form action="" method="post">';
echo '<select name="action"><option selected></option><option>Voir</option><option>Éditer</option></select><br />';
echo '<select method="post" action="">';
echo '<option selected></option>';
$reponse = $bdd->query('SELECT * from profils');
while($donnees = $reponse->fetch())
{
echo '<option>'.$donnees['Pseudo'].'</option>';
}
echo '</select><br />';
echo '<input type=image value=submit src="images/valider.png" name="profils">';
echo '</form>';
echo '</fieldset>';
}
}
?>
</body>
</html>