-
Notifications
You must be signed in to change notification settings - Fork 24
Expand file tree
/
Copy pathticket-list.php
More file actions
36 lines (27 loc) · 1.32 KB
/
Copy pathticket-list.php
File metadata and controls
36 lines (27 loc) · 1.32 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
<?php
/** @var object $con */
/** @var object $view */
/** @var array<string> $urlparts */
if(empty($user['userId'])) showErrorPage(HTTP_UNAUTHORIZED);
if(empty($urlparts[2])) showErrorPage(HTTP_NOT_FOUND);
$targetUserHash = $urlparts[2];
if(($targetUserHash !== 'self' && !ctype_xdigit($targetUserHash))) showErrorPage(HTTP_NOT_FOUND);
require(SRC_ROOT.'/lib/moderation.php');
if($targetUserHash === 'self' || $targetUserHash === $user['hash']) {
$shownUser = $user;
}
else {
if(!canModerate(null, $user)) showErrorPage(HTTP_UNAUTHORIZED);
$shownUser = getUserByHash($targetUserHash);
if(!$shownUser) showErrorPage(HTTP_NOT_FOUND);
}
$tickets = $con->getAll(<<<SQL
SELECT requestId, kind, category, stateFlags, IF(LENGTH(requestSearchable) > 256, CONCAT(SUBSTR(requestSearchable, 1, 256), '...'), requestSearchable) AS requestSearchable
FROM moderationRequests
WHERE initiatorUserId = {$shownUser['userId']}
ORDER BY created DESC
SQL); // @security: $shownUser['userId'] comes from the database and is int, therefore sql inert.
$view->assign('pagetitle', $shownUser['userId'] == $user['userId'] ? "My Moderation Requests - " : "Moderation Requests initiated by {$shownUser['name']} - ");
$view->assign('shownUser', $shownUser, null, true);
$view->assign('tickets', $tickets, null, true);
$view->display('ticket-list');