<?

if($_POST['task'] == "insert")
{
	mysql_query("INSERT INTO `users` ( `id` , `firstname` , `lastname` , `email` , `password` , `role` , `rights` , `comment` )
				VALUES (
				NULL , '".$_POST['firstname']."', '".$_POST['lastname']."', '".$_POST['email']."', '".$_POST['password']."', '', '".$_POST['rights']."', '".$_POST['comment']."'
				)");
	log_action($_SESSION['user_email'],"Created User: ".$_POST['email']);

}
elseif($_POST['task'] == "editit")
{
	mysql_query("update users set firstname = '".$_POST['firstname']."',lastname = '".$_POST['lastname']."',email = '".$_POST['email']."',password = '".$_POST['password']."',rights = '".$_POST['rights']."',comment = '".$_POST['comment']."' where id = '".$_POST['id']."'");
		log_action($_SESSION['user_email'],"Edited User: ".$_POST['email']);

}
elseif($_GET['task'] == "delete")
{
	$result = mysql_query("select email from users where id = '".$_GET['id']."'");
	$row = mysql_fetch_object($result);
	mysql_query("delete from users where id = '".$_GET['id']."'");
	log_action($_SESSION['user_email'],"Deleted User: ".$row->email);

}


?>


<div class="abk">Users</div>
<div class="body">


<? if($_GET['task'] == "edit")
{

$result = mysql_query("select * from users where id='".$_GET['id']."'");
$row = mysql_fetch_object($result);
?>
<form action="index.php?show=users" method="post">
<table width="100%" cellpadding="3" cellspacing="1">
<tr>
<td class="table_header" colspan="6">Edit User</td>
</tr>
<tr>
<td class="table_body_active">Firstname</td>
<td  class="table_body"><input type="text" name="firstname" value="<? echo $row->firstname ?>" /></td>
<td class="table_body_active">Lastname</td>
<td  class="table_body"><input type="text" name="lastname"  value="<? echo $row->lastname ?>"  /></td>
<td class="table_body_active">Email</td>
<td  class="table_body"><input type="text" name="email"   value="<? echo $row->email ?>"  /></td>
</tr>
<tr>
<td class="table_body_active">Password</td>
<td  class="table_body"><input type="text" name="password"   value="<? echo $row->password ?>"  /></td>
<td class="table_body_active">Comment</td>
<td  class="table_body"><input type="text" name="comment"   value="<? echo $row->comment ?>"  /></td>
<td class="table_body_active">Rights</td>
<td  class="table_body"><input type="text" name="rights"  value="<? echo $row->rights ?>"   /></td>
</tr>
<tr>
<td class="table_body" colspan="6" align="center"><input type="submit" value="Save" /><input type="hidden" name="task" value="editit" /><input type="hidden" name="id" value="<? echo $row->id ?>"</td>
</tr>
</table>


</form>

<?
}
else
{

?>
<form action="index.php?show=users" method="post">
<table width="100%" cellpadding="3" cellspacing="1">
<tr>
<td class="table_header" colspan="6">Insert new User</td>
</tr>
<tr>
<td class="table_body_active">Firstname</td>
<td  class="table_body"><input type="text" name="firstname" /></td>
<td class="table_body_active">Lastname</td>
<td  class="table_body"><input type="text" name="lastname" /></td>
<td class="table_body_active">Email</td>
<td  class="table_body"><input type="text" name="email" /></td>
</tr>
<tr>
<td class="table_body_active">Password</td>
<td  class="table_body"><input type="text" name="password" /></td>
<td class="table_body_active">Comment</td>
<td  class="table_body"><input type="text" name="comment" /></td>
<td class="table_body_active">Rights</td>
<td  class="table_body"><input type="text" name="rights" /></td>
</tr>
<tr>
<td class="table_body" colspan="6" align="center"><input type="submit" value="Save" /><input type="hidden" name="task" value="insert" /></td>
</tr>
</table>


</form>

<? } ?>

<br />
<table width="100%" cellpadding="3" cellspacing="1">
<tr class="table_header">
<td>Firstname</td>
<td>Lastname</td>
<td>email</td>
<td>Passwort</td>
<td>Comment</td>
<td> Rights</td>
<td> &nbsp;</td>
<td> &nbsp;</td>
</tr>
<?

	$result = db_query("select * from users order by lastname");
	while($row = db_fetch_object($result))
	{ ?>
		<tr class="table_body">
        <td><? echo $row->firstname ?></td>
        <td><? echo $row->lastname ?></td>
        <td><? echo $row->email ?></td>
        <td><? echo $row->password ?></td>
        <td><? echo $row->comment ?></td>
        <td><? if(strlen($row->rights) > 20) echo substr($row->rights,0,20)."..."; else echo $row->rights; ?></td>
<td><a href="index.php?show=users&amp;task=edit&amp;id=<? echo $row->id ?>"><img src="symbols/b_edit.png" border="0" /></a></td>
<td><a onclick="return confirm('Do you really want to delete this user?');" href="index.php?show=users&amp;task=delete&amp;id=<? echo $row->id ?>"><img src="symbols/b_drop.png" border="0" /></a></td>
        </tr>
	<? }

?>
</table>

</div>