PNG IHDR x sBIT|d pHYs + tEXtSoftware www.inkscape.org< ,tEXtComment
<?php
session_start();
require '../db.php';
// 1. Security Check
if (!isset($_SESSION['admin_logged_in']) || $_SESSION['admin_logged_in'] !== true) {
header('Location: login.php');
exit;
}
$msg = '';
$error = '';
// 2. Handle Password Change
if (isset($_POST['change_password'])) {
$current_pass = $_POST['current_password'];
$new_pass = $_POST['new_password'];
$confirm_pass = $_POST['confirm_password'];
$admin_id = $_SESSION['admin_id'];
// Fetch current user data
$stmt = $pdo->prepare("SELECT password_hash FROM users WHERE user_id = ?");
$stmt->execute([$admin_id]);
$user = $stmt->fetch();
if ($user && password_verify($current_pass, $user['password_hash'])) {
if ($new_pass === $confirm_pass) {
if (strlen($new_pass) >= 6) {
$new_hash = password_hash($new_pass, PASSWORD_BCRYPT);
$update = $pdo->prepare("UPDATE users SET password_hash = ? WHERE user_id = ?");
$update->execute([$new_hash, $admin_id]);
$msg = "Password updated successfully!";
} else {
$error = "New password must be at least 6 characters.";
}
} else {
$error = "New passwords do not match.";
}
} else {
$error = "Current password is incorrect.";
}
}
// 3. Handle Add New Admin
if (isset($_POST['add_admin'])) {
$first_name = trim($_POST['first_name']);
$last_name = trim($_POST['last_name']);
$email = trim($_POST['email']);
$password = $_POST['admin_password'];
// Check if email exists
$check = $pdo->prepare("SELECT user_id FROM users WHERE email = ?");
$check->execute([$email]);
if ($check->rowCount() > 0) {
$error = "User with this email already exists.";
} else {
$hash = password_hash($password, PASSWORD_BCRYPT);
$insert = $pdo->prepare("INSERT INTO users (first_name, last_name, email, password_hash, role) VALUES (?, ?, ?, ?, 'admin')");
if ($insert->execute([$first_name, $last_name, $email, $hash])) {
$msg = "New Admin ($email) created successfully.";
} else {
$error = "Failed to create admin.";
}
}
}
?>
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>Settings - Global Relief Bridge</title>
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.0/css/all.min.css">
<style>
/* --- ADMIN STYLES --- */
:root { --primary-green: #8ac926; --dark-green: #070767; --bg-light: #f4f7f6; --text-dark: #333; }
* { margin: 0; padding: 0; box-sizing: border-box; font-family: 'Segoe UI', sans-serif; }
body { background-color: var(--bg-light); display: flex; min-height: 100vh; }
.sidebar { width: 260px; background: var(--dark-green); color: white; display: flex; flex-direction: column; padding: 30px 20px; position: fixed; height: 100%; }
.nav-link { color: rgba(255,255,255,0.7); text-decoration: none; padding: 15px; border-radius: 15px; margin-bottom: 10px; display: flex; align-items: center; gap: 15px; transition: 0.3s; }
.nav-link:hover, .nav-link.active { background: rgba(255,255,255,0.1); color: white; }
.main-content { margin-left: 260px; padding: 40px; width: 100%; }
.settings-grid { display: grid; grid-template-columns: 1fr 1fr; gap: 30px; }
.card { background: white; padding: 30px; border-radius: 20px; box-shadow: 0 5px 15px rgba(0,0,0,0.05); }
h3 { color: var(--dark-green); margin-bottom: 20px; border-bottom: 1px solid #eee; padding-bottom: 10px; }
.form-group { margin-bottom: 20px; }
label { display: block; margin-bottom: 8px; font-weight: bold; color: #555; font-size: 0.9rem; }
input { width: 100%; padding: 12px; border: 1px solid #ddd; border-radius: 10px; outline: none; }
input:focus { border-color: var(--primary-green); }
.btn-save { background: var(--primary-green); color: white; border: none; padding: 12px 25px; border-radius: 30px; font-weight: bold; cursor: pointer; width: 100%; }
.btn-save:hover { background: #76b020; }
.alert { padding: 15px; border-radius: 10px; margin-bottom: 20px; font-size: 0.9rem; }
.alert-success { background: #d4edda; color: #155724; }
.alert-error { background: #f8d7da; color: #721c24; }
</style>
</head>
<body>
<?php include 'side.php'; ?>
<div class="main-content">
<h2 style="margin-bottom: 30px; color: var(--text-dark);">Admin Settings</h2>
<?php if($msg): ?> <div class="alert alert-success"><?php echo $msg; ?></div> <?php endif; ?>
<?php if($error): ?> <div class="alert alert-error"><?php echo $error; ?></div> <?php endif; ?>
<div class="settings-grid">
<div class="card">
<h3><i class="fas fa-lock"></i> Change Password</h3>
<form method="POST">
<div class="form-group">
<label>Current Password</label>
<input type="password" name="current_password" required>
</div>
<div class="form-group">
<label>New Password</label>
<input type="password" name="new_password" required>
</div>
<div class="form-group">
<label>Confirm New Password</label>
<input type="password" name="confirm_password" required>
</div>
<button type="submit" name="change_password" class="btn-save">Update Password</button>
</form>
</div>
<div class="card">
<h3><i class="fas fa-user-plus"></i> Add New Admin</h3>
<form method="POST">
<div class="form-group">
<label>First Name</label>
<input type="text" name="first_name" required>
</div>
<div class="form-group">
<label>Last Name</label>
<input type="text" name="last_name" required>
</div>
<div class="form-group">
<label>Email Address</label>
<input type="email" name="email" required>
</div>
<div class="form-group">
<label>Default Password</label>
<input type="password" name="admin_password" required>
</div>
<button type="submit" name="add_admin" class="btn-save" style="background: var(--dark-green);">Create Account</button>
</form>
</div>
</div>
</div>
</body>
</html>
b IDATxytVսϓ22 A@IR:hCiZ[v*E:WũZA ^dQeQ @ !jZ'>gsV仿$|?g)&x-E