cvs: php-master-web / users.sql /fetch cvsforwarding.php cvspasswd.php cvsusers.php cvswriters.php /manage users.php
| From: | jim winstead | Date: | Fri, 19 Oct 2001 22:05:47 +0000 |
| Subject: | cvs: php-master-web / users.sql /fetch cvsforwarding.php cvspasswd.php cvsusers.php cvswriters.php /manage users.php | ||
| Groups: | php.mirrors | ||
| Request: | Send a blank email to php-mirrors+get-7100@lists.php.net to get a copy of this message | ||
jimw Fri Oct 19 18:05:47 2001 EDT
Modified files:
/php-master-web users.sql
/php-master-web/fetch cvsforwarding.php cvspasswd.php cvsusers.php
cvswriters.php
/php-master-web/manage users.php
Log:
merge users_cvs back into users. just added complexity that wasn't really worth it.
Index: php-master-web/users.sql diff -u php-master-web/users.sql:1.2 php-master-web/users.sql:1.3 --- php-master-web/users.sql:1.2 Fri Oct 19 17:07:55 2001 +++ php-master-web/users.sql Fri Oct 19 18:05:45 2001 @@ -10,31 +10,26 @@ /* the users table is the main one. it contains the name, email, and crypted password for each user. the password is crypted using the standard unix DES-based crypt (for interop with cvs) */ -/* we have a full-text index on name and email for searching, and we - require unique email addresses for each account. */ +/* we have a full-text index on name, username and email for searching, and we + require unique email addresses for each account. the username must also + be unique (when present). */ /* a user will be able to change the email address associated with their account if they know the password. */ +/* the cvsaccess field requires more thought. we might want to expand + it to a more general flags field or something. it already implies + an email alias in addition to cvs access. */ CREATE TABLE IF NOT EXISTS users ( userid INT NOT NULL AUTO_INCREMENT, name VARCHAR(255) NOT NULL DEFAULT '', email VARCHAR(255) NOT NULL DEFAULT '', passwd VARCHAR(16) NOT NULL DEFAULT '', + username VARCHAR(16) DEFAULT NULL, + cvsaccess INT(1) NOT NULL DEFAULT 0, PRIMARY KEY(userid), UNIQUE (email), - FULLTEXT (name,email) -); - -/* the users_cvs table contains the cvs username and whether or not - the user has been approved for cvs access. not all users will have - cvs usernames. the cvs usernames have to be unique. */ -/* this probably could be merged back into the main users table. */ -CREATE TABLE IF NOT EXISTS users_cvs ( - userid INT NOT NULL, - cvsuser CHAR(16) NOT NULL, - approved INT(1) NOT NULL DEFAULT 0, - PRIMARY KEY(userid), - UNIQUE (cvsuser) -); + UNIQUE (username), + FULLTEXT (name,email,username) +) TYPE=MyISAM; /* the user_note table just contains notes about each user. */ CREATE TABLE IF NOT EXISTS users_note ( @@ -44,4 +39,4 @@ note TEXT, PRIMARY KEY (noteid), FULLTEXT (note) -); +) TYPE=MyISAM; Index: php-master-web/fetch/cvsforwarding.php diff -u php-master-web/fetch/cvsforwarding.php:1.6 php-master-web/fetch/cvsforwarding.php:1.7 --- php-master-web/fetch/cvsforwarding.php:1.6 Wed Oct 17 22:25:14 2001 +++ php-master-web/fetch/cvsforwarding.php Fri Oct 19 18:05:46 2001 @@ -7,10 +7,10 @@ // Connect and generate the list from the DB if (@mysql_connect("localhost","nobody","")) { if (@mysql_select_db("php3")) { - $res = @mysql_query("SELECT cvsuser,email FROM users LEFT JOIN users_cvs USING (userid) WHERE email IS NOT NULL AND approved"); + $res = @mysql_query("SELECT username,email FROM users WHERE email != '' AND cvsaccess"); if ($res) { while ($row = @mysql_fetch_array($res)) { - echo "$row[cvsuser]: $row[email];\n"; + echo "$row[username]: $row[email];\n"; } } } Index: php-master-web/fetch/cvspasswd.php diff -u php-master-web/fetch/cvspasswd.php:1.4 php-master-web/fetch/cvspasswd.php:1.5 --- php-master-web/fetch/cvspasswd.php:1.4 Thu Oct 18 18:21:26 2001 +++ php-master-web/fetch/cvspasswd.php Fri Oct 19 18:05:46 2001 @@ -7,10 +7,10 @@ // Connect and generate the list from the DB if (@mysql_connect("localhost","nobody","")) { if (@mysql_select_db("php3")) { - $res = @mysql_query("SELECT cvsuser,passwd FROM users LEFT JOIN users_cvs USING (userid) WHERE passwd != '' AND approved"); + $res = @mysql_query("SELECT username,passwd FROM users WHERE passwd != '' AND cvsaccess"); if ($res) { while ($row = @mysql_fetch_array($res)) { - echo "$row[cvsuser]:$row[passwd]:cvs\n"; + echo "$row[username]:$row[passwd]:cvs\n"; } # the read-only cvsread account echo "cvsread::cvs\n"; Index: php-master-web/fetch/cvsusers.php diff -u php-master-web/fetch/cvsusers.php:1.3 php-master-web/fetch/cvsusers.php:1.4 --- php-master-web/fetch/cvsusers.php:1.3 Wed Oct 17 21:09:51 2001 +++ php-master-web/fetch/cvsusers.php Fri Oct 19 18:05:46 2001 @@ -7,10 +7,10 @@ // Connect and generate the list from the DB if (@mysql_connect("localhost","nobody","")) { if (@mysql_select_db("php3")) { - $res = @mysql_query("SELECT cvsuser,name,email FROM users LEFT JOIN users_cvs USING (userid) WHERE approved"); + $res = @mysql_query("SELECT username,name,email FROM users WHERE cvsaccess"); if ($res) { while ($row = @mysql_fetch_array($res)) { - echo "$row[cvsuser]:$row[name]:$row[email]\n"; + echo "$row[username]:$row[name]:$row[email]\n"; } } } Index: php-master-web/fetch/cvswriters.php diff -u php-master-web/fetch/cvswriters.php:1.2 php-master-web/fetch/cvswriters.php:1.3 --- php-master-web/fetch/cvswriters.php:1.2 Wed Oct 17 19:22:25 2001 +++ php-master-web/fetch/cvswriters.php Fri Oct 19 18:05:46 2001 @@ -7,11 +7,10 @@ // Connect and generate the list from the DB if (@mysql_connect("localhost","nobody","")) { if (@mysql_select_db("php3")) { - $res = @mysql_query("SELECT cvsuser FROM users_cvs WHERE approved"); + $res = @mysql_query("SELECT username FROM users WHERE cvsaccess"); if ($res) { while ($row = @mysql_fetch_array($res)) { - if ($row[cvsuser] == 'cvsread') continue; - echo "$row[cvsuser]\n"; + echo "$row[username]\n"; } } } Index: php-master-web/manage/users.php diff -u php-master-web/manage/users.php:1.10 php-master-web/manage/users.php:1.11 --- php-master-web/manage/users.php:1.10 Thu Oct 18 18:34:06 2001 +++ php-master-web/manage/users.php Fri Oct 19 18:05:46 2001 @@ -20,8 +20,8 @@ # ?username=whatever will look up 'whatever' by email or cvs username if (isset($username) && !isset($id)) { - $query = "SELECT users.userid FROM users LEFT JOIN users_cvs USING (userid)" - . " WHERE cvsuser='$username' OR email='$username'"; + $query = "SELECT userid FROM users" + . " WHERE username='$username' OR email='$username'"; $res = query($query); if (!($id = @mysql_result($res,0))) { warn("wasn't able to find user matching '".clean($username)."'"); @@ -40,41 +40,31 @@ if ($in[rawpasswd]) { $in[passwd] = crypt($in[rawpasswd],substr(md5(time()),0,2)); } - $approved = $in[approved] ? 1 : 0; + $cvsaccess = $in[cvsaccess] ? 1 : 0; if ($id) { # update main table data if (isset($in[email]) && isset($in[name])) { $query = "UPDATE users SET name='$in[name]',email='$in[email]'" . ($in[passwd] ? ",passwd='$in[passwd]'" : "") + . ($in[username] ? ",username='$in[username]'" : "") + . ",cvsaccess=$cvsaccess" . " WHERE userid=$id"; query($query); } - # update cvsusers stuff - # TODO: create users_cvs record for user that didn't already have one - # (can't just use REPLACE because of the unique index on cvsuser) - $query = "UPDATE users_cvs" - . " SET cvsuser='$in[cvsuser]',approved=$approved" - . " WHERE userid=$id"; - query($query); warn("record $id updated"); unset($id); } else { $query = "INSERT users SET name='$in[name]',email='$in[email]'" - . ($in[passwd] ? ",passwd='$in[passwd]'" : ""); + . ($in[username] ? ",username='$in[username]'" : "") + . ($in[passwd] ? ",passwd='$in[passwd]'" : "") + . ",cvsaccess=$cvsaccess"; query($query); $nid = mysql_insert_id(); - # TODO: handle failure better - if ($in[cvsuser]) { - $query = "INSERT users_cvs" - . " SET userid=$nid,cvsuser='$in[cvsuser]',approved=$approved"; - query($query); - } - warn("record $nid added"); } } @@ -82,7 +72,7 @@ } if ($id) { - $query = "SELECT * FROM users LEFT JOIN users_cvs USING (userid)" + $query = "SELECT * FROM users" . " WHERE users.userid=$id"; $res = query($query); $row = mysql_fetch_array($res); @@ -118,11 +108,11 @@ </tr> <tr> <th align="right">CVS username:</th> - <td><input type="text" name="in[cvsuser]" value="<?php echo htmlspecialchars($row[cvsuser]);?>" size="16" maxlength="16" /></td> + <td><input type="text" name="in[username]" value="<?php echo htmlspecialchars($row[username]);?>" size="16" maxlength="16" /></td> </tr> <tr> <th align="right">CVS access?</th> - <td><input type="checkbox" name="in[approved]"<?php echo $row[approved] ? " checked" : "";?> /></td> + <td><input type="checkbox" name="in[cvsaccess]"<?php echo $row[cvsaccess] ? " checked" : "";?> /></td> </tr> <tr> <td><input type="submit" value="<?php echo $id ? "Change" : "Add";?>" /> @@ -152,16 +142,16 @@ $limit = "LIMIT $begin,$max"; $orderby = $order ? "ORDER BY $order" : ""; -$searchby = $search ? "WHERE MATCH(name,email) AGAINST ('$search') OR MATCH(note) AGAINST ('$search') OR users_cvs.cvsuser = '$search'" : ""; +$searchby = $search ? "WHERE MATCH(name,email,username) AGAINST ('$search') OR MATCH(note) AGAINST ('$search')" : ""; $query = "SELECT DISTINCT COUNT(users.userid) FROM users"; if ($searchby) - $query .= " LEFT JOIN users_cvs USING (userid) LEFT JOIN users_note USING(userid) $searchby"; + $query .= " LEFT JOIN users_note USING(userid) $searchby"; $res = mysql_query($query) or die("query '$query' failed: ".mysql_error()); $total = mysql_result($res,0); -$query = "SELECT DISTINCT users.userid,approved,cvsuser,name,email,note FROM users LEFT JOIN users_cvs USING (userid) LEFT JOIN users_note USING (userid) $searchby $orderby $limit"; +$query = "SELECT DISTINCT users.userid,cvsaccess,username,name,email,note FROM users LEFT JOIN users_note USING (userid) $searchby $orderby $limit"; #echo "<pre>$query</pre>"; $res = mysql_query($query) @@ -182,7 +172,7 @@ <th><a href="<?php echo "$PHP_SELF?",array_to_url($extra,array("full" => $full ? 0 : 1));?>"><?php echo $full ? "⊗" : "⊕";?></a></th> <th><a href="<?php echo "$PHP_SELF?",array_to_url($extra,array("order"=>"name"));?>">name</a></th> <th><a href="<?php echo "$PHP_SELF?",array_to_url($extra,array("order"=>"email"));?>">email</a></th> - <th><a href="<?php echo "$PHP_SELF?",array_to_url($extra,array("order"=>"cvsuser"));?>">username</a></th> + <th><a href="<?php echo "$PHP_SELF?",array_to_url($extra,array("order"=>"username"));?>">username</a></th> </tr> <?php $color = '#dddddd'; @@ -192,7 +182,7 @@ <td align="center"><a href="<?php echo "$PHP_SELF?id=$row[userid]";?>">edit</a></td> <td><?php echo htmlspecialchars($row[name]);?></td> <td><?php echo htmlspecialchars($row[email]);?></td> - <td<?php if ($row[cvsuser] && !$row[approved]) echo ' bgcolor="#ff',substr($color,2),'"';?>><?php echo htmlspecialchars($row[cvsuser]);?></td> + <td<?php if ($row[username] && !$row[cvsaccess]) echo ' bgcolor="#ff',substr($color,2),'"';?>><?php echo htmlspecialchars($row[username]);?></td> </tr> <?php if ($full && $row[note]) {?> @@ -214,8 +204,8 @@ if (isset($in[email]) && !is_emailable_address($in[email])) { return "'".clean($in[email])."' does not look like a valid email address"; } - if ($in[cvsuser] && !preg_match("/^[-\w]+\$/",$in[cvsuser])) { - return "'".clean($in[cvsuser])."' is not a valid username"; + if ($in[username] && !preg_match("/^[-\w]+\$/",$in[username])) { + return "'".clean($in[username])."' is not a valid username"; } if ($in[rawpasswd] && $in[rawpasswd] != $in[rawpasswd2]) { return "the passwords you specified did not match!"; @@ -231,9 +221,9 @@ $userid = (int)$userid; $quser = addslashes($user); - $query = "SELECT users.userid FROM users LEFT JOIN users_cvs USING (userid)" - . " WHERE users.userid=$userid" - . " AND (email='$quser' OR cvsuser='$quser')"; + $query = "SELECT userid FROM users" + . " WHERE userid=$userid" + . " AND (email='$quser' OR username='$quser')"; $res = mysql_query($query); return $res ? mysql_num_rows($res) : false;
Index: php-master-web/users.sql diff -u php-master-web/users.sql:1.2 php-master-web/users.sql:1.3 --- php-master-web/users.sql:1.2 Fri Oct 19 17:07:55 2001 +++ php-master-web/users.sql Fri Oct 19 18:05:45 2001 @@ -10,31 +10,26 @@ /* the users table is the main one. it contains the name, email, and crypted password for each user. the password is crypted using the standard unix DES-based crypt (for interop with cvs) */ -/* we have a full-text index on name and email for searching, and we - require unique email addresses for each account. */ +/* we have a full-text index on name, username and email for searching, and we + require unique email addresses for each account. the username must also + be unique (when present). */ /* a user will be able to change the email address associated with their account if they know the password. */ +/* the cvsaccess field requires more thought. we might want to expand + it to a more general flags field or something. it already implies + an email alias in addition to cvs access. */ CREATE TABLE IF NOT EXISTS users ( userid INT NOT NULL AUTO_INCREMENT, name VARCHAR(255) NOT NULL DEFAULT '', email VARCHAR(255) NOT NULL DEFAULT '', passwd VARCHAR(16) NOT NULL DEFAULT '', + username VARCHAR(16) DEFAULT NULL, + cvsaccess INT(1) NOT NULL DEFAULT 0, PRIMARY KEY(userid), UNIQUE (email), - FULLTEXT (name,email) -); - -/* the users_cvs table contains the cvs username and whether or not - the user has been approved for cvs access. not all users will have - cvs usernames. the cvs usernames have to be unique. */ -/* this probably could be merged back into the main users table. */ -CREATE TABLE IF NOT EXISTS users_cvs ( - userid INT NOT NULL, - cvsuser CHAR(16) NOT NULL, - approved INT(1) NOT NULL DEFAULT 0, - PRIMARY KEY(userid), - UNIQUE (cvsuser) -); + UNIQUE (username), + FULLTEXT (name,email,username) +) TYPE=MyISAM; /* the user_note table just contains notes about each user. */ CREATE TABLE IF NOT EXISTS users_note ( @@ -44,4 +39,4 @@ note TEXT, PRIMARY KEY (noteid), FULLTEXT (note) -); +) TYPE=MyISAM; Index: php-master-web/fetch/cvsforwarding.php diff -u php-master-web/fetch/cvsforwarding.php:1.6 php-master-web/fetch/cvsforwarding.php:1.7 --- php-master-web/fetch/cvsforwarding.php:1.6 Wed Oct 17 22:25:14 2001 +++ php-master-web/fetch/cvsforwarding.php Fri Oct 19 18:05:46 2001 @@ -7,10 +7,10 @@ // Connect and generate the list from the DB if (@mysql_connect("localhost","nobody","")) { if (@mysql_select_db("php3")) { - $res = @mysql_query("SELECT cvsuser,email FROM users LEFT JOIN users_cvs USING (userid) WHERE email IS NOT NULL AND approved"); + $res = @mysql_query("SELECT username,email FROM users WHERE email != '' AND cvsaccess"); if ($res) { while ($row = @mysql_fetch_array($res)) { - echo "$row[cvsuser]: $row[email];\n"; + echo "$row[username]: $row[email];\n"; } } } Index: php-master-web/fetch/cvspasswd.php diff -u php-master-web/fetch/cvspasswd.php:1.4 php-master-web/fetch/cvspasswd.php:1.5 --- php-master-web/fetch/cvspasswd.php:1.4 Thu Oct 18 18:21:26 2001 +++ php-master-web/fetch/cvspasswd.php Fri Oct 19 18:05:46 2001 @@ -7,10 +7,10 @@ // Connect and generate the list from the DB if (@mysql_connect("localhost","nobody","")) { if (@mysql_select_db("php3")) { - $res = @mysql_query("SELECT cvsuser,passwd FROM users LEFT JOIN users_cvs USING (userid) WHERE passwd != '' AND approved"); + $res = @mysql_query("SELECT username,passwd FROM users WHERE passwd != '' AND cvsaccess"); if ($res) { while ($row = @mysql_fetch_array($res)) { - echo "$row[cvsuser]:$row[passwd]:cvs\n"; + echo "$row[username]:$row[passwd]:cvs\n"; } # the read-only cvsread account echo "cvsread::cvs\n"; Index: php-master-web/fetch/cvsusers.php diff -u php-master-web/fetch/cvsusers.php:1.3 php-master-web/fetch/cvsusers.php:1.4 --- php-master-web/fetch/cvsusers.php:1.3 Wed Oct 17 21:09:51 2001 +++ php-master-web/fetch/cvsusers.php Fri Oct 19 18:05:46 2001 @@ -7,10 +7,10 @@ // Connect and generate the list from the DB if (@mysql_connect("localhost","nobody","")) { if (@mysql_select_db("php3")) { - $res = @mysql_query("SELECT cvsuser,name,email FROM users LEFT JOIN users_cvs USING (userid) WHERE approved"); + $res = @mysql_query("SELECT username,name,email FROM users WHERE cvsaccess"); if ($res) { while ($row = @mysql_fetch_array($res)) { - echo "$row[cvsuser]:$row[name]:$row[email]\n"; + echo "$row[username]:$row[name]:$row[email]\n"; } } } Index: php-master-web/fetch/cvswriters.php diff -u php-master-web/fetch/cvswriters.php:1.2 php-master-web/fetch/cvswriters.php:1.3 --- php-master-web/fetch/cvswriters.php:1.2 Wed Oct 17 19:22:25 2001 +++ php-master-web/fetch/cvswriters.php Fri Oct 19 18:05:46 2001 @@ -7,11 +7,10 @@ // Connect and generate the list from the DB if (@mysql_connect("localhost","nobody","")) { if (@mysql_select_db("php3")) { - $res = @mysql_query("SELECT cvsuser FROM users_cvs WHERE approved"); + $res = @mysql_query("SELECT username FROM users WHERE cvsaccess"); if ($res) { while ($row = @mysql_fetch_array($res)) { - if ($row[cvsuser] == 'cvsread') continue; - echo "$row[cvsuser]\n"; + echo "$row[username]\n"; } } } Index: php-master-web/manage/users.php diff -u php-master-web/manage/users.php:1.10 php-master-web/manage/users.php:1.11 --- php-master-web/manage/users.php:1.10 Thu Oct 18 18:34:06 2001 +++ php-master-web/manage/users.php Fri Oct 19 18:05:46 2001 @@ -20,8 +20,8 @@ # ?username=whatever will look up 'whatever' by email or cvs username if (isset($username) && !isset($id)) { - $query = "SELECT users.userid FROM users LEFT JOIN users_cvs USING (userid)" - . " WHERE cvsuser='$username' OR email='$username'"; + $query = "SELECT userid FROM users" + . " WHERE username='$username' OR email='$username'"; $res = query($query); if (!($id = @mysql_result($res,0))) { warn("wasn't able to find user matching '".clean($username)."'"); @@ -40,41 +40,31 @@ if ($in[rawpasswd]) { $in[passwd] = crypt($in[rawpasswd],substr(md5(time()),0,2)); } - $approved = $in[approved] ? 1 : 0; + $cvsaccess = $in[cvsaccess] ? 1 : 0; if ($id) { # update main table data if (isset($in[email]) && isset($in[name])) { $query = "UPDATE users SET name='$in[name]',email='$in[email]'" . ($in[passwd] ? ",passwd='$in[passwd]'" : "") + . ($in[username] ? ",username='$in[username]'" : "") + . ",cvsaccess=$cvsaccess" . " WHERE userid=$id"; query($query); } - # update cvsusers stuff - # TODO: create users_cvs record for user that didn't already have one - # (can't just use REPLACE because of the unique index on cvsuser) - $query = "UPDATE users_cvs" - . " SET cvsuser='$in[cvsuser]',approved=$approved" - . " WHERE userid=$id"; - query($query); warn("record $id updated"); unset($id); } else { $query = "INSERT users SET name='$in[name]',email='$in[email]'" - . ($in[passwd] ? ",passwd='$in[passwd]'" : ""); + . ($in[username] ? ",username='$in[username]'" : "") + . ($in[passwd] ? ",passwd='$in[passwd]'" : "") + . ",cvsaccess=$cvsaccess"; query($query); $nid = mysql_insert_id(); - # TODO: handle failure better - if ($in[cvsuser]) { - $query = "INSERT users_cvs" - . " SET userid=$nid,cvsuser='$in[cvsuser]',approved=$approved"; - query($query); - } - warn("record $nid added"); } } @@ -82,7 +72,7 @@ } if ($id) { - $query = "SELECT * FROM users LEFT JOIN users_cvs USING (userid)" + $query = "SELECT * FROM users" . " WHERE users.userid=$id"; $res = query($query); $row = mysql_fetch_array($res); @@ -118,11 +108,11 @@ </tr> <tr> <th align="right">CVS username:</th> - <td><input type="text" name="in[cvsuser]" value="<?php echo htmlspecialchars($row[cvsuser]);?>" size="16" maxlength="16" /></td> + <td><input type="text" name="in[username]" value="<?php echo htmlspecialchars($row[username]);?>" size="16" maxlength="16" /></td> </tr> <tr> <th align="right">CVS access?</th> - <td><input type="checkbox" name="in[approved]"<?php echo $row[approved] ? " checked" : "";?> /></td> + <td><input type="checkbox" name="in[cvsaccess]"<?php echo $row[cvsaccess] ? " checked" : "";?> /></td> </tr> <tr> <td><input type="submit" value="<?php echo $id ? "Change" : "Add";?>" /> @@ -152,16 +142,16 @@ $limit = "LIMIT $begin,$max"; $orderby = $order ? "ORDER BY $order" : ""; -$searchby = $search ? "WHERE MATCH(name,email) AGAINST ('$search') OR MATCH(note) AGAINST ('$search') OR users_cvs.cvsuser = '$search'" : ""; +$searchby = $search ? "WHERE MATCH(name,email,username) AGAINST ('$search') OR MATCH(note) AGAINST ('$search')" : ""; $query = "SELECT DISTINCT COUNT(users.userid) FROM users"; if ($searchby) - $query .= " LEFT JOIN users_cvs USING (userid) LEFT JOIN users_note USING(userid) $searchby"; + $query .= " LEFT JOIN users_note USING(userid) $searchby"; $res = mysql_query($query) or die("query '$query' failed: ".mysql_error()); $total = mysql_result($res,0); -$query = "SELECT DISTINCT users.userid,approved,cvsuser,name,email,note FROM users LEFT JOIN users_cvs USING (userid) LEFT JOIN users_note USING (userid) $searchby $orderby $limit"; +$query = "SELECT DISTINCT users.userid,cvsaccess,username,name,email,note FROM users LEFT JOIN users_note USING (userid) $searchby $orderby $limit"; #echo "<pre>$query</pre>"; $res = mysql_query($query) @@ -182,7 +172,7 @@ <th><a href="<?php echo "$PHP_SELF?",array_to_url($extra,array("full" => $full ? 0 : 1));?>"><?php echo $full ? "⊗" : "⊕";?></a></th> <th><a href="<?php echo "$PHP_SELF?",array_to_url($extra,array("order"=>"name"));?>">name</a></th> <th><a href="<?php echo "$PHP_SELF?",array_to_url($extra,array("order"=>"email"));?>">email</a></th> - <th><a href="<?php echo "$PHP_SELF?",array_to_url($extra,array("order"=>"cvsuser"));?>">username</a></th> + <th><a href="<?php echo "$PHP_SELF?",array_to_url($extra,array("order"=>"username"));?>">username</a></th> </tr> <?php $color = '#dddddd'; @@ -192,7 +182,7 @@ <td align="center"><a href="<?php echo "$PHP_SELF?id=$row[userid]";?>">edit</a></td> <td><?php echo htmlspecialchars($row[name]);?></td> <td><?php echo htmlspecialchars($row[email]);?></td> - <td<?php if ($row[cvsuser] && !$row[approved]) echo ' bgcolor="#ff',substr($color,2),'"';?>><?php echo htmlspecialchars($row[cvsuser]);?></td> + <td<?php if ($row[username] && !$row[cvsaccess]) echo ' bgcolor="#ff',substr($color,2),'"';?>><?php echo htmlspecialchars($row[username]);?></td> </tr> <?php if ($full && $row[note]) {?> @@ -214,8 +204,8 @@ if (isset($in[email]) && !is_emailable_address($in[email])) { return "'".clean($in[email])."' does not look like a valid email address"; } - if ($in[cvsuser] && !preg_match("/^[-\w]+\$/",$in[cvsuser])) { - return "'".clean($in[cvsuser])."' is not a valid username"; + if ($in[username] && !preg_match("/^[-\w]+\$/",$in[username])) { + return "'".clean($in[username])."' is not a valid username"; } if ($in[rawpasswd] && $in[rawpasswd] != $in[rawpasswd2]) { return "the passwords you specified did not match!"; @@ -231,9 +221,9 @@ $userid = (int)$userid; $quser = addslashes($user); - $query = "SELECT users.userid FROM users LEFT JOIN users_cvs USING (userid)" - . " WHERE users.userid=$userid" - . " AND (email='$quser' OR cvsuser='$quser')"; + $query = "SELECT userid FROM users" + . " WHERE userid=$userid" + . " AND (email='$quser' OR username='$quser')"; $res = mysql_query($query); return $res ? mysql_num_rows($res) : false;