mirror of
https://github.com/Foltik/Shimapan
synced 2024-11-30 14:31:42 -05:00
Only allow root user to see other users files
This commit is contained in:
parent
d31979782e
commit
98bd5c1fce
@ -141,7 +141,7 @@ function fetchFiles($date, $count, $keyword, $action)
|
||||
include('./search.php');
|
||||
|
||||
if ($action === 'Fetch All') {
|
||||
if ($_SESSION['level'] < '2') {
|
||||
if ($_SESSION['level'] === '0') {
|
||||
$q = $db->prepare("SELECT * FROM files ORDER BY id DESC LIMIT :count");
|
||||
} else {
|
||||
$q = $db->prepare("SELECT * FROM files WHERE user = (:user) ORDER BY id DESC LIMIT :count");
|
||||
@ -164,7 +164,7 @@ function fetchFiles($date, $count, $keyword, $action)
|
||||
echo '<p>'.$i.' Files in total at being shown.</p>';
|
||||
echo '</table>';
|
||||
} elseif ($action === 'Fetch') {
|
||||
if ($_SESSION['level'] < '2') {
|
||||
if ($_SESSION['level'] === '0') {
|
||||
$q = $db->prepare("SELECT * FROM files WHERE originalname LIKE (:keyword) AND date LIKE (:date) OR filename LIKE (:keyword) AND date LIKE (:date) ORDER BY id DESC LIMIT :count");
|
||||
} else {
|
||||
$q = $db->prepare("SELECT * FROM files WHERE originalname LIKE (:keyword) AND date LIKE (:date) AND user = (:user) OR filename LIKE (:keyword) AND date LIKE (:date) AND user = (:userid) ORDER BY id DESC LIMIT :count");
|
||||
|
Loading…
Reference in New Issue
Block a user