diff --git a/res/forum/api/remove_user.php b/res/forum/api/remove_user.php new file mode 100644 index 0000000..bcbcef9 --- /dev/null +++ b/res/forum/api/remove_user.php @@ -0,0 +1,23 @@ + query("SELECT username, admin FROM user WHERE username=\"" . $_SESSION["username"] . "\" AND admin=\"1\""); + +if ($out -> num_rows != 1) +{ + fail: + echo "nope"; + header("Location: ../../../index.php"); + return; +} + +if (!isset($_GET["username"])) return; + +$user_info_id = (($database -> query("SELECT user_info FROM user WHERE username=\"" . $_GET["username"] . "\"")) -> fetch_assoc())["user_info"]; + +$database -> query("DELETE FROM user WHERE user_info=" . $user_info_id); +$database -> query("DELETE FROM user_info WHERE id=" . $user_info_id); \ No newline at end of file