From c57a1691349e16d65f1b7f7152fbd37468c90633 Mon Sep 17 00:00:00 2001 From: ENGO150 Date: Wed, 22 May 2024 17:20:11 +0200 Subject: [PATCH] created api for user update --- res/forum/api/update_user.php | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) create mode 100644 res/forum/api/update_user.php diff --git a/res/forum/api/update_user.php b/res/forum/api/update_user.php new file mode 100644 index 0000000..a6f3d7f --- /dev/null +++ b/res/forum/api/update_user.php @@ -0,0 +1,23 @@ + query("SELECT username, admin, user_info FROM user WHERE BINARY username=\"" . $_SESSION["username"] . "\" AND admin=\"1\""); + +if (!isset($_GET["old_username"])) return; + +if ($out -> num_rows != 1 && $_GET["old_username"] != $_SESSION["username"]) +{ + fail: + echo "nope"; + header("Location: ../../../index.php"); + return; +} + +$user_info_id = (($database -> query("SELECT user_info FROM user WHERE username=\"" . $_GET["old_username"] . "\"")) -> fetch_assoc())["user_info"]; + +$database -> query("UPDATE user SET username=\"" . $_GET["username"] . "\", admin=" . $_GET["admin"] . " WHERE user_info=" . $user_info_id); +$database -> query("UPDATE user_info SET sex=" . $_GET["sex"] . ", bio=\"" . $_GET["bio"] . "\", nickname=\"" . $_GET["nickname"] . "\" WHERE id=" . $user_info_id); \ No newline at end of file