51ff3226 |
1 | <?php |
2 | |
ac3bdc72 |
3 | function executorlist() { |
4 | global $db,$error,$node; |
5 | $node_id=$node['node_id']; |
6 | if ($node['node_permission']!='owner') { |
7 | $error=$error_messages['EVENT_PERMISSION_ERROR']; |
8 | return false; |
9 | } |
51ff3226 |
10 | |
ac3bdc72 |
11 | $executors=explode(";",$_POST['executorlist']); // XXX sqli |
12 | $db->query("update node_access set node_permission='' where |
13 | node_id=$node_id and node_permission='exec'"); |
14 | foreach ($executors as $execitpr) { |
15 | $set=$db->query("select user_id from users where login='$executor'"); |
16 | $set->next(); |
17 | if ($set->getString('user_id')) { |
18 | $q="update node_access set node_permission='exec' where node_id=$node_id and |
51ff3226 |
19 | user_id='".$set->getString('user_id')."'"; |
ac3bdc72 |
20 | $changed=$db->update($q); |
21 | if (!$changed) { |
22 | $q="insert into node_access set |
51ff3226 |
23 | node_permission='exec',node_id=$node_id,user_id=".$set->getString('user_id'); |
ac3bdc72 |
24 | $db->query($q); |
25 | $logger::log('add exec',$node_id,'ok',$executor); |
51ff3226 |
26 | |
51ff3226 |
27 | } |
51ff3226 |
28 | } |
ac3bdc72 |
29 | else { $error .= "$executor does not exist..."; } |
51ff3226 |
30 | } |
ac3bdc72 |
31 | } |
51ff3226 |
32 | ?> |