diff -r c72d6d51f3d3 -r c255196bc447 delete_user.php --- a/delete_user.php Wed Mar 12 20:45:56 2008 +0000 +++ b/delete_user.php Tue Mar 25 22:45:31 2008 +0000 @@ -20,103 +20,87 @@ */ require_once("inc/toolkit.inc.php"); +include_once("inc/header.inc.php"); -$id = ($_POST["id"]) ? $_POST["id"] : $_GET["id"]; +verify_permission(user_edit_own) ? $perm_edit_own = "1" : $perm_edit_own = "0" ; +verify_permission(user_edit_others) ? $perm_edit_others = "1" : $perm_edit_others = "0" ; + +if (!(isset($_GET['id']) && v_num($_GET['id']))) { + error(ERR_INV_INPUT); + include_once("inc/footer.inc.php"); + exit; +} else { + $uid = $_GET['id']; +} + +if ($_POST['commit']) { + if (delete_user($uid,$_POST['zone'])) { + success(SUC_USER_DEL); + } +} else { + + if (($uid != $_SESSION['userid'] && !verify_permission(user_edit_others)) || ($uid == $_SESSION['userid'] && !verify_permission(user_edit_own))) { + error(ERR_PERM_DEL_USER); + include_once("inc/footer.inc.php"); + exit; + } else { + $fullname = get_fullname_from_userid($uid); + $zones = get_zones("own",$uid); + + echo "