Codi de la pàgina gestio.php
\n"; echo "alert('Operació NO realitzada. L'usuari $uusuario ja está donat d'alta'); \n"; echo " \n"; } $result = mysql_query("SELECT id FROM usuarios WHERE nombre='$unombre'", $link); $total2 =@mysql_num_rows($result); if ($total2!=0) { echo " \n"; } if ($total==0 AND $total2==0){ $sql= "INSERT INTO usuarios (nombre, clave, cargo, usuario) "; $sql.= "VALUES ('$unombre', '$uclave', '$ucargo', '$uusuario')"; mysql_query($sql,$link); echo " \n"; } break; case "baixausuari": mysql_select_db("basepame",$link); $sql= "DELETE FROM usuarios WHERE id='$idbaixa'"; mysql_query($sql,$link); echo " \n"; break; } ?> include ("seguridad.php"); if ($_SESSION['cargo'] !='coordinador informàtica'){ echo " \n"; } ?> include ("cabecera.inc"); ?> include ("intranet.inc"); ?>
\n"; echo "
\n"; echo "
\n"; echo "
Donar d'alta a nous usuaris
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
Nom
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
Usuari
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
Clau
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
Àmbit
\n"; echo "
\n"; $sql = "SELECT ambito FROM ambitos ORDER BY ambito"; $result = mysql_query($sql, $link); echo "
\n"; while ($row = mysql_fetch_row($result)){ echo "
".$row[0]."
\n"; } echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
donar d'alta
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo " \n"; break; case "baixa": $link=mysql_pconnect('','pame','pame'); mysql_select_db("basepame",$link); if ($id==''){ echo "
\n"; echo "
\n"; echo "
\n"; echo "
Donar de baixa a usuaris
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
Usuari \n"; $result = mysql_query("SELECT id,usuario FROM usuarios ORDER BY usuario", $link); echo "
\n"; echo "
\n"; while ($row = mysql_fetch_row($result)){ echo "
".$row[1]."
\n"; } echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; } else { $result = mysql_query("SELECT usuario FROM usuarios WHERE id='$id'", $link); $row = mysql_fetch_row($result); echo "
\n"; echo "
\n"; echo "
\n"; echo "
Donar de baixa a l'usuari
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
Usuari
$row[0]
\n"; echo "
donar de baixa
\n"; echo "
\n"; echo "
\n"; echo "
\n"; } break; case "dades": $link=mysql_pconnect('','pame','pame'); mysql_select_db("basepame",$link); if ($id==''){ echo "
\n"; echo "
\n"; echo "
\n"; echo "
Seleccioneu a l'usuari
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
Usuari \n"; $result = mysql_query("SELECT id,usuario FROM usuarios ORDER BY usuario", $link); echo "
\n"; echo "
\n"; while ($row = mysql_fetch_row($result)){ echo "
".$row[1]."
\n"; } echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; } else { $result = mysql_query("SELECT usuario FROM usuarios WHERE id='$id'", $link); $row = mysql_fetch_row($result); $usuario=$row[0]; if ($eliminarfoto!=''){ $eliminarfoto= explode('-',$eliminarfoto); $sql="UPDATE usuarios SET foto='' WHERE usuario='$usuario'"; $result=mysql_query($sql); @unlink('imagenes/fotos/'.$eliminarfoto[1]); } if ($eliminarvideo!=''){ $eliminarvideo= explode('-',$eliminarvideo); $sql="UPDATE usuarios SET nomvideo='' WHERE usuario='$usuario'"; $result=mysql_query($sql); @unlink('imagenes/videos/'.$eliminarvideo[1]); } if ($foto!=''){ if ($cambiofoto!=''){ @unlink('imagenes/fotos/'.$cambiofoto); } $fotonombre=$_FILES['foto']['name']; $upfile='imagenes/fotos/'.$fotonombre; move_uploaded_file($foto,$upfile); $sql="UPDATE usuarios SET foto='$fotonombre' WHERE usuario='$usuario'"; $result=mysql_query($sql); } if ($video!=''){ if ($cambiovideo!=''){ @unlink('imagenes/videos/'.$cambiovideo); } $videonombre=$_FILES['video']['name']; $upfile='imagenes/videos/'.$videonombre; move_uploaded_file($video,$upfile); $sql="UPDATE usuarios SET nomvideo='$videonombre' WHERE usuario='$usuario'"; $result=mysql_query($sql); } if ($canvinova!=''){ $sql="SELECT clave FROM usuarios WHERE usuario='$usuario'"; $result=mysql_query($sql,$link); $row=mysql_fetch_row($result); if ($canviantiga==$row[0]){ $sql="UPDATE usuarios SET clave='$canvinova' WHERE usuario='$usuario'"; $result=mysql_query($sql); echo " \n"; } else { echo " \n"; } } $sql="SELECT * FROM usuarios WHERE usuario='$usuario'"; $result=mysql_query($sql,$link); $row=mysql_fetch_row($result); $extension= explode('.',$row[6]); if ($row[5]!=''){ echo "Foto -
\n"; $fototexto=$row[5]; } if ($row[6]!=''){ $videotexto=$row[6]; echo " Vídeo -\n"; switch ($extension[1]){ case"avi": echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; break; case"mov": echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; break; } } echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
Foto/Vídeo
\n"; echo "
canviar
\n"; echo "
\n"; echo "
\n"; echo "
Usuari
\n"; echo "
".$usuario."
\n"; echo "
\n"; echo "
\n"; echo "
Nom
\n"; echo "
".$row[1]."
\n"; echo "
\n"; echo "
\n"; echo "
Àmbit
\n"; echo "
".$row[7]."
\n"; echo "
\n"; echo "
\n"; echo "
Contrasenya
\n"; echo "
******
\n"; echo "
canviar
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
"; echo "
"; echo "
"; echo "
\n"; echo "
\n"; echo "
Canvi de fotografia / vídeo
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
Fotografia
\n"; echo "
format: jpg - tamany i pes 100x100px 2Kb
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; if ($fototexto!=''){ echo "
\n"; echo "
\n"; echo "
\n"; echo " \n"; } echo "
\n"; echo "
Vídeo
\n"; echo "
format: mov ó avi - tamany i pes 100x75px màx.1990Kb
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; if ($videotexto!=''){ echo "
\n"; echo "
\n"; echo "
\n"; } echo "
\n"; echo "
\n"; echo "
\n"; echo "
cancelar
\n"; echo "
aceptar
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
Canvi de contrasenya
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
contrasenya antiga
\n"; echo "
\n"; echo "
"; echo "
\n"; echo "
\n"; echo "
contrasenya nova
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
cancelar
\n"; echo "
aceptar
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; } break; } break; } ?>
\n"; echo "
\n"; echo "
\n"; echo "
Usuaris
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; echo "
\n"; switch ($gestio){ case "usuarios": echo "
\n"; echo "
Altes
\n"; echo "
Baixes
\n"; echo "
Dades personals
\n"; echo "
\n"; break; } echo "
\n"; echo " \n"; ?>