(* COCANWIKI scripts. * Written by Richard W.M. Jones . * Copyright (C) 2004 Merjis Ltd. * $Id: edit_user.ml,v 1.1 2004/09/08 12:45:38 rich Exp $ *) open Apache open Registry open Cgi open Printf open Cocanwiki open Cocanwiki_strings open Cocanwiki_ok let run r (q : cgi) (dbh : Dbi.connection) (hostid, _, _) self = let userid = int_of_string (q#param "userid") in (* Get the user's original name. If we're going to change the * name, we need to do additional checks. *) let sth = dbh#prepare_cached "select name from users where hostid = ? and id = ?" in sth#execute [`Int hostid; `Int userid]; let original_name = sth#fetch1string () in let name = trim (q#param "name") in if original_name <> name then ( if name = "" then ( error ~back_button:true ~title:"Bad username" q "The username you gave is empty."; raise CgiExit ); (* Check it's not a duplicate, then change it. *) let sth = dbh#prepare_cached "select id from users where hostid = ? and name = ?" in sth#execute [`Int hostid; `String name]; (try sth#fetch1 (); error ~back_button:true ~title:"Username already taken" q ("That username has already been taken by another user."); raise CgiExit with Not_found -> ()); let sth = dbh#prepare_cached "update users set name = ? where hostid = ? and id = ?" in sth#execute [`String name; `Int hostid; `Int userid] ); (* Change email address and permissions. *) let email = trim (q#param "email") in let email = if email = "" then `Null else `String email in let can_edit = q#param_true "can_edit" in let can_manage_users = q#param_true "can_manage_users" in (* Trying to remove manage users permission from self? *) (match can_manage_users, self with | false, User (id, _, _) when id = userid -> error ~back_button:true ~title:"Remove manage users from self" q ("You tried to remove 'Manage users' permission from yourself. "^ "You can't do this. You'll have to do it from another "^ "user account."); raise CgiExit | _ -> ()); let sth = dbh#prepare_cached "update users set email = ?, can_edit = ?, can_manage_users = ? where hostid = ? and id = ?" in sth#execute [email; `Bool can_edit; `Bool can_manage_users; `Int hostid; `Int userid]; (* Finish up. *) dbh#commit (); let buttons = [ ok_button "/_users" ] in ok ~buttons ~title:"Saved" q "Changes were saved." let () = register_script ~restrict:[CanManageUsers] run