36146-vm/admin.php
Flatlogic Bot 65d71ae74f v1
2025-11-23 19:41:44 +00:00

277 lines
13 KiB
PHP

<?php
session_start();
require_once 'db/config.php';
if (!isset($_SESSION['user_id'])) {
header("Location: /login.php");
exit;
}
$userId = $_SESSION['user_id'];
$db = db();
// Check if user is admin
$stmt = $db->prepare("SELECT role FROM users WHERE id = ?");
$stmt->execute([$userId]);
$user = $stmt->fetch(PDO::FETCH_ASSOC);
if (!$user || $user['role'] !== 'admin') {
header("Location: /dashboard.php");
exit;
}
// Admin-specific actions
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
// Edit Subscription
if (isset($_POST['edit_subscription'])) {
$subscription_id = $_POST['subscription_id'];
$name = $_POST['name'];
$cost = $_POST['cost'];
$renewal_date = $_POST['renewal_date'];
$category = $_POST['category'];
$frequency = $_POST['frequency'];
$stmt = $db->prepare("UPDATE subscriptions SET name = ?, cost = ?, renewal_date = ?, category = ?, frequency = ? WHERE id = ?");
$stmt->execute([$name, $cost, $renewal_date, $category, $frequency, $subscription_id]);
}
// Delete Subscription
elseif (isset($_POST['delete_subscription'])) {
$subscription_id = $_POST['subscription_id'];
$stmt = $db->prepare("DELETE FROM subscriptions WHERE id = ?");
$stmt->execute([$subscription_id]);
}
// TODO: Add user management actions (e.g., edit, delete user, reset password)
header("Location: admin.php");
exit;
}
// Fetch aggregated metrics
$totalUsers = $db->query("SELECT COUNT(*) FROM users")->fetchColumn();
$totalSubscriptions = $db->query("SELECT COUNT(*) FROM subscriptions")->fetchColumn();
$totalValue = $db->query("SELECT SUM(cost) FROM subscriptions")->fetchColumn();
// Fetch all users and subscriptions
$users = $db->query("SELECT id, name, email, role, is_active, created_at FROM users ORDER BY created_at DESC")->fetchAll(PDO::FETCH_ASSOC);
$subscriptions = $db->query("SELECT s.*, u.name as user_name FROM subscriptions s JOIN users u ON s.user_id = u.id ORDER BY s.renewal_date ASC")->fetchAll(PDO::FETCH_ASSOC);
?>
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Admin Panel - Subscription Manager</title>
<link href="https://cdn.jsdelivr.net/npm/bootstrap@5.3.2/dist/css/bootstrap.min.css" rel="stylesheet">
<link rel="stylesheet" href="assets/css/custom.css">
</head>
<body>
<nav class="navbar navbar-expand-lg navbar-light bg-white shadow-sm">
<div class="container-fluid">
<a class="navbar-brand" href="/admin.php">Admin Panel</a>
<ul class="navbar-nav ms-auto">
<li class="nav-item">
<span class="navbar-text me-3">Welcome, <?php echo htmlspecialchars($_SESSION['user_name']); ?> (Admin)!</span>
</li>
<li class="nav-item">
<a href="/dashboard.php" class="btn btn-outline-secondary me-2">My Dashboard</a>
</li>
<li class="nav-item">
<a href="logout.php" class="btn btn-outline-primary">Logout</a>
</li>
</ul>
</div>
</nav>
<div class="container mt-5">
<!-- Aggregated Metrics -->
<div class="row mb-4">
<div class="col-md-4">
<div class="card text-white bg-primary">
<div class="card-body">
<h5 class="card-title">Total Users</h5>
<p class="card-text fs-2 fw-bold"><?php echo $totalUsers; ?></p>
</div>
</div>
</div>
<div class="col-md-4">
<div class="card text-white bg-success">
<div class="card-body">
<h5 class="card-title">Total Subscriptions</h5>
<p class="card-text fs-2 fw-bold"><?php echo $totalSubscriptions; ?></p>
</div>
</div>
</div>
<div class="col-md-4">
<div class="card text-white bg-info">
<div class="card-body">
<h5 class="card-title">Total Value Tracked</h5>
<p class="card-text fs-2 fw-bold">$<?php echo number_format($totalValue ?? 0, 2); ?></p>
</div>
</div>
</div>
</div>
<!-- User Management -->
<div class="card shadow-sm mb-5">
<div class="card-header">
<h4 class="mb-0">User Management</h4>
</div>
<div class="card-body">
<div class="table-responsive">
<table class="table table-hover">
<thead>
<tr>
<th>Name</th>
<th>Email</th>
<th>Role</th>
<th>Active</th>
<th>Joined</th>
<th>Actions</th>
</tr>
</thead>
<tbody>
<?php foreach ($users as $u): ?>
<tr>
<td><?php echo htmlspecialchars($u['name']); ?></td>
<td><?php echo htmlspecialchars($u['email']); ?></td>
<td><?php echo htmlspecialchars($u['role']); ?></td>
<td><?php echo $u['is_active'] ? 'Yes' : 'No'; ?></td>
<td><?php echo date("Y-m-d", strtotime($u['created_at'])); ?></td>
<td>
<button class="btn btn-sm btn-outline-secondary" disabled>Edit</button>
<a href="reset-password.php?user_id=<?php echo $u['id']; ?>" class="btn btn-sm btn-outline-warning" target="_blank">Reset Password</a>
</td>
</tr>
<?php endforeach; ?>
</tbody>
</table>
</div>
</div>
</div>
<!-- Subscription Management -->
<div class="card shadow-sm">
<div class="card-header">
<h4 class="mb-0">All Subscriptions</h4>
</div>
<div class="card-body">
<div class="table-responsive">
<table class="table table-hover">
<thead>
<tr>
<th>User</th>
<th>Subscription</th>
<th>Cost</th>
<th>Renewal Date</th>
<th>Actions</th>
</tr>
</thead>
<tbody>
<?php foreach ($subscriptions as $sub): ?>
<tr>
<td><?php echo htmlspecialchars($sub['user_name']); ?></td>
<td><?php echo htmlspecialchars($sub['name']); ?></td>
<td>$<?php echo number_format($sub['cost'], 2); ?></td>
<td><?php echo htmlspecialchars($sub['renewal_date']); ?></td>
<td>
<button class="btn btn-sm btn-outline-secondary edit-btn"
data-id="<?php echo $sub['id']; ?>"
data-name="<?php echo htmlspecialchars($sub['name']); ?>"
data-cost="<?php echo $sub['cost']; ?>"
data-renewal_date="<?php echo $sub['renewal_date']; ?>"
data-category="<?php echo htmlspecialchars($sub['category']); ?>"
data-frequency="<?php echo htmlspecialchars($sub['frequency']); ?>"
data-bs-toggle="modal" data-bs-target="#editSubscriptionModal">Edit</button>
<form method="POST" style="display: inline-block;" onsubmit="return confirm('Are you sure you want to delete this subscription?');">
<input type="hidden" name="subscription_id" value="<?php echo $sub['id']; ?>">
<button type="submit" name="delete_subscription" class="btn btn-sm btn-outline-danger">Delete</button>
</form>
</td>
</tr>
<?php endforeach; ?>
</tbody>
</table>
</div>
</div>
</div>
</div>
<!-- Edit Subscription Modal (for Admin) -->
<div class="modal fade" id="editSubscriptionModal" tabindex="-1" aria-labelledby="editSubscriptionModalLabel" aria-hidden="true">
<div class="modal-dialog">
<div class="modal-content">
<div class="modal-header">
<h5 class="modal-title" id="editSubscriptionModalLabel">Edit Subscription</h5>
<button type="button" class="btn-close" data-bs-dismiss="modal" aria-label="Close"></button>
</div>
<form method="POST">
<div class="modal-body">
<input type="hidden" id="edit_subscription_id" name="subscription_id">
<div class="mb-3">
<label for="edit_name" class="form-label">Subscription Name</label>
<input type="text" class="form-control" id="edit_name" name="name" required>
</div>
<div class="mb-3">
<label for="edit_cost" class="form-label">Monthly Cost (USD)</label>
<input type="number" step="0.01" class="form-control" id="edit_cost" name="cost" required>
</div>
<div class="mb-3">
<label for="edit_renewal_date" class="form-label">Next Renewal Date</label>
<input type="date" class="form-control" id="edit_renewal_date" name="renewal_date" required>
</div>
<div class="mb-3">
<label for="edit_category" class="form-label">Category</label>
<input type="text" class="form-control" id="edit_category" name="category" placeholder="e.g., Streaming, Software">
</div>
<div class="mb-3">
<label for="edit_frequency" class="form-label">Frequency</label>
<select class="form-select" id="edit_frequency" name="frequency">
<option>Monthly</option>
<option>Yearly</option>
</select>
</div>
</div>
<div class="modal-footer">
<button type="button" class="btn btn-secondary" data-bs-dismiss="modal">Close</button>
<button type="submit" name="edit_subscription" class="btn btn-primary">Save Changes</button>
</div>
</form>
</div>
</div>
</div>
<script src="https://cdn.jsdelivr.net/npm/bootstrap@5.3.2/dist/js/bootstrap.bundle.min.js"></script>
<script>
document.addEventListener('DOMContentLoaded', function () {
var editSubscriptionModal = document.getElementById('editSubscriptionModal');
editSubscriptionModal.addEventListener('show.bs.modal', function (event) {
var button = event.relatedTarget;
var id = button.getAttribute('data-id');
var name = button.getAttribute('data-name');
var cost = button.getAttribute('data-cost');
var renewal_date = button.getAttribute('data-renewal_date');
var category = button.getAttribute('data-category');
var frequency = button.getAttribute('data-frequency');
var modalTitle = editSubscriptionModal.querySelector('.modal-title');
var modalBodyInputId = editSubscriptionModal.querySelector('#edit_subscription_id');
var modalBodyInputName = editSubscriptionModal.querySelector('#edit_name');
var modalBodyInputCost = editSubscriptionModal.querySelector('#edit_cost');
var modalBodyInputRenewalDate = editSubscriptionModal.querySelector('#edit_renewal_date');
var modalBodyInputCategory = editSubscriptionModal.querySelector('#edit_category');
var modalBodyInputFrequency = editSubscriptionModal.querySelector('#edit_frequency');
modalTitle.textContent = 'Edit ' + name;
modalBodyInputId.value = id;
modalBodyInputName.value = name;
modalBodyInputCost.value = cost;
modalBodyInputRenewalDate.value = renewal_date;
modalBodyInputCategory.value = category;
modalBodyInputFrequency.value = frequency;
});
});
</script>
</body>
</html>