277 lines
13 KiB
PHP
277 lines
13 KiB
PHP
<?php
|
|
session_start();
|
|
require_once 'db/config.php';
|
|
|
|
if (!isset($_SESSION['user_id'])) {
|
|
header("Location: /login.php");
|
|
exit;
|
|
}
|
|
|
|
$userId = $_SESSION['user_id'];
|
|
$db = db();
|
|
|
|
// Check if user is admin
|
|
$stmt = $db->prepare("SELECT role FROM users WHERE id = ?");
|
|
$stmt->execute([$userId]);
|
|
$user = $stmt->fetch(PDO::FETCH_ASSOC);
|
|
|
|
if (!$user || $user['role'] !== 'admin') {
|
|
header("Location: /dashboard.php");
|
|
exit;
|
|
}
|
|
|
|
// Admin-specific actions
|
|
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
|
// Edit Subscription
|
|
if (isset($_POST['edit_subscription'])) {
|
|
$subscription_id = $_POST['subscription_id'];
|
|
$name = $_POST['name'];
|
|
$cost = $_POST['cost'];
|
|
$renewal_date = $_POST['renewal_date'];
|
|
$category = $_POST['category'];
|
|
$frequency = $_POST['frequency'];
|
|
|
|
$stmt = $db->prepare("UPDATE subscriptions SET name = ?, cost = ?, renewal_date = ?, category = ?, frequency = ? WHERE id = ?");
|
|
$stmt->execute([$name, $cost, $renewal_date, $category, $frequency, $subscription_id]);
|
|
}
|
|
// Delete Subscription
|
|
elseif (isset($_POST['delete_subscription'])) {
|
|
$subscription_id = $_POST['subscription_id'];
|
|
$stmt = $db->prepare("DELETE FROM subscriptions WHERE id = ?");
|
|
$stmt->execute([$subscription_id]);
|
|
}
|
|
// TODO: Add user management actions (e.g., edit, delete user, reset password)
|
|
header("Location: admin.php");
|
|
exit;
|
|
}
|
|
|
|
|
|
// Fetch aggregated metrics
|
|
$totalUsers = $db->query("SELECT COUNT(*) FROM users")->fetchColumn();
|
|
$totalSubscriptions = $db->query("SELECT COUNT(*) FROM subscriptions")->fetchColumn();
|
|
$totalValue = $db->query("SELECT SUM(cost) FROM subscriptions")->fetchColumn();
|
|
|
|
// Fetch all users and subscriptions
|
|
$users = $db->query("SELECT id, name, email, role, is_active, created_at FROM users ORDER BY created_at DESC")->fetchAll(PDO::FETCH_ASSOC);
|
|
$subscriptions = $db->query("SELECT s.*, u.name as user_name FROM subscriptions s JOIN users u ON s.user_id = u.id ORDER BY s.renewal_date ASC")->fetchAll(PDO::FETCH_ASSOC);
|
|
|
|
?>
|
|
<!DOCTYPE html>
|
|
<html lang="en">
|
|
<head>
|
|
<meta charset="UTF-8">
|
|
<meta name="viewport" content="width=device-width, initial-scale=1.0">
|
|
<title>Admin Panel - Subscription Manager</title>
|
|
<link href="https://cdn.jsdelivr.net/npm/bootstrap@5.3.2/dist/css/bootstrap.min.css" rel="stylesheet">
|
|
<link rel="stylesheet" href="assets/css/custom.css">
|
|
</head>
|
|
<body>
|
|
|
|
<nav class="navbar navbar-expand-lg navbar-light bg-white shadow-sm">
|
|
<div class="container-fluid">
|
|
<a class="navbar-brand" href="/admin.php">Admin Panel</a>
|
|
<ul class="navbar-nav ms-auto">
|
|
<li class="nav-item">
|
|
<span class="navbar-text me-3">Welcome, <?php echo htmlspecialchars($_SESSION['user_name']); ?> (Admin)!</span>
|
|
</li>
|
|
<li class="nav-item">
|
|
<a href="/dashboard.php" class="btn btn-outline-secondary me-2">My Dashboard</a>
|
|
</li>
|
|
<li class="nav-item">
|
|
<a href="logout.php" class="btn btn-outline-primary">Logout</a>
|
|
</li>
|
|
</ul>
|
|
</div>
|
|
</nav>
|
|
|
|
<div class="container mt-5">
|
|
<!-- Aggregated Metrics -->
|
|
<div class="row mb-4">
|
|
<div class="col-md-4">
|
|
<div class="card text-white bg-primary">
|
|
<div class="card-body">
|
|
<h5 class="card-title">Total Users</h5>
|
|
<p class="card-text fs-2 fw-bold"><?php echo $totalUsers; ?></p>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
<div class="col-md-4">
|
|
<div class="card text-white bg-success">
|
|
<div class="card-body">
|
|
<h5 class="card-title">Total Subscriptions</h5>
|
|
<p class="card-text fs-2 fw-bold"><?php echo $totalSubscriptions; ?></p>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
<div class="col-md-4">
|
|
<div class="card text-white bg-info">
|
|
<div class="card-body">
|
|
<h5 class="card-title">Total Value Tracked</h5>
|
|
<p class="card-text fs-2 fw-bold">$<?php echo number_format($totalValue ?? 0, 2); ?></p>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<!-- User Management -->
|
|
<div class="card shadow-sm mb-5">
|
|
<div class="card-header">
|
|
<h4 class="mb-0">User Management</h4>
|
|
</div>
|
|
<div class="card-body">
|
|
<div class="table-responsive">
|
|
<table class="table table-hover">
|
|
<thead>
|
|
<tr>
|
|
<th>Name</th>
|
|
<th>Email</th>
|
|
<th>Role</th>
|
|
<th>Active</th>
|
|
<th>Joined</th>
|
|
<th>Actions</th>
|
|
</tr>
|
|
</thead>
|
|
<tbody>
|
|
<?php foreach ($users as $u): ?>
|
|
<tr>
|
|
<td><?php echo htmlspecialchars($u['name']); ?></td>
|
|
<td><?php echo htmlspecialchars($u['email']); ?></td>
|
|
<td><?php echo htmlspecialchars($u['role']); ?></td>
|
|
<td><?php echo $u['is_active'] ? 'Yes' : 'No'; ?></td>
|
|
<td><?php echo date("Y-m-d", strtotime($u['created_at'])); ?></td>
|
|
<td>
|
|
<button class="btn btn-sm btn-outline-secondary" disabled>Edit</button>
|
|
<a href="reset-password.php?user_id=<?php echo $u['id']; ?>" class="btn btn-sm btn-outline-warning" target="_blank">Reset Password</a>
|
|
</td>
|
|
</tr>
|
|
<?php endforeach; ?>
|
|
</tbody>
|
|
</table>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<!-- Subscription Management -->
|
|
<div class="card shadow-sm">
|
|
<div class="card-header">
|
|
<h4 class="mb-0">All Subscriptions</h4>
|
|
</div>
|
|
<div class="card-body">
|
|
<div class="table-responsive">
|
|
<table class="table table-hover">
|
|
<thead>
|
|
<tr>
|
|
<th>User</th>
|
|
<th>Subscription</th>
|
|
<th>Cost</th>
|
|
<th>Renewal Date</th>
|
|
<th>Actions</th>
|
|
</tr>
|
|
</thead>
|
|
<tbody>
|
|
<?php foreach ($subscriptions as $sub): ?>
|
|
<tr>
|
|
<td><?php echo htmlspecialchars($sub['user_name']); ?></td>
|
|
<td><?php echo htmlspecialchars($sub['name']); ?></td>
|
|
<td>$<?php echo number_format($sub['cost'], 2); ?></td>
|
|
<td><?php echo htmlspecialchars($sub['renewal_date']); ?></td>
|
|
<td>
|
|
<button class="btn btn-sm btn-outline-secondary edit-btn"
|
|
data-id="<?php echo $sub['id']; ?>"
|
|
data-name="<?php echo htmlspecialchars($sub['name']); ?>"
|
|
data-cost="<?php echo $sub['cost']; ?>"
|
|
data-renewal_date="<?php echo $sub['renewal_date']; ?>"
|
|
data-category="<?php echo htmlspecialchars($sub['category']); ?>"
|
|
data-frequency="<?php echo htmlspecialchars($sub['frequency']); ?>"
|
|
data-bs-toggle="modal" data-bs-target="#editSubscriptionModal">Edit</button>
|
|
<form method="POST" style="display: inline-block;" onsubmit="return confirm('Are you sure you want to delete this subscription?');">
|
|
<input type="hidden" name="subscription_id" value="<?php echo $sub['id']; ?>">
|
|
<button type="submit" name="delete_subscription" class="btn btn-sm btn-outline-danger">Delete</button>
|
|
</form>
|
|
</td>
|
|
</tr>
|
|
<?php endforeach; ?>
|
|
</tbody>
|
|
</table>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<!-- Edit Subscription Modal (for Admin) -->
|
|
<div class="modal fade" id="editSubscriptionModal" tabindex="-1" aria-labelledby="editSubscriptionModalLabel" aria-hidden="true">
|
|
<div class="modal-dialog">
|
|
<div class="modal-content">
|
|
<div class="modal-header">
|
|
<h5 class="modal-title" id="editSubscriptionModalLabel">Edit Subscription</h5>
|
|
<button type="button" class="btn-close" data-bs-dismiss="modal" aria-label="Close"></button>
|
|
</div>
|
|
<form method="POST">
|
|
<div class="modal-body">
|
|
<input type="hidden" id="edit_subscription_id" name="subscription_id">
|
|
<div class="mb-3">
|
|
<label for="edit_name" class="form-label">Subscription Name</label>
|
|
<input type="text" class="form-control" id="edit_name" name="name" required>
|
|
</div>
|
|
<div class="mb-3">
|
|
<label for="edit_cost" class="form-label">Monthly Cost (USD)</label>
|
|
<input type="number" step="0.01" class="form-control" id="edit_cost" name="cost" required>
|
|
</div>
|
|
<div class="mb-3">
|
|
<label for="edit_renewal_date" class="form-label">Next Renewal Date</label>
|
|
<input type="date" class="form-control" id="edit_renewal_date" name="renewal_date" required>
|
|
</div>
|
|
<div class="mb-3">
|
|
<label for="edit_category" class="form-label">Category</label>
|
|
<input type="text" class="form-control" id="edit_category" name="category" placeholder="e.g., Streaming, Software">
|
|
</div>
|
|
<div class="mb-3">
|
|
<label for="edit_frequency" class="form-label">Frequency</label>
|
|
<select class="form-select" id="edit_frequency" name="frequency">
|
|
<option>Monthly</option>
|
|
<option>Yearly</option>
|
|
</select>
|
|
</div>
|
|
</div>
|
|
<div class="modal-footer">
|
|
<button type="button" class="btn btn-secondary" data-bs-dismiss="modal">Close</button>
|
|
<button type="submit" name="edit_subscription" class="btn btn-primary">Save Changes</button>
|
|
</div>
|
|
</form>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<script src="https://cdn.jsdelivr.net/npm/bootstrap@5.3.2/dist/js/bootstrap.bundle.min.js"></script>
|
|
<script>
|
|
document.addEventListener('DOMContentLoaded', function () {
|
|
var editSubscriptionModal = document.getElementById('editSubscriptionModal');
|
|
editSubscriptionModal.addEventListener('show.bs.modal', function (event) {
|
|
var button = event.relatedTarget;
|
|
var id = button.getAttribute('data-id');
|
|
var name = button.getAttribute('data-name');
|
|
var cost = button.getAttribute('data-cost');
|
|
var renewal_date = button.getAttribute('data-renewal_date');
|
|
var category = button.getAttribute('data-category');
|
|
var frequency = button.getAttribute('data-frequency');
|
|
|
|
var modalTitle = editSubscriptionModal.querySelector('.modal-title');
|
|
var modalBodyInputId = editSubscriptionModal.querySelector('#edit_subscription_id');
|
|
var modalBodyInputName = editSubscriptionModal.querySelector('#edit_name');
|
|
var modalBodyInputCost = editSubscriptionModal.querySelector('#edit_cost');
|
|
var modalBodyInputRenewalDate = editSubscriptionModal.querySelector('#edit_renewal_date');
|
|
var modalBodyInputCategory = editSubscriptionModal.querySelector('#edit_category');
|
|
var modalBodyInputFrequency = editSubscriptionModal.querySelector('#edit_frequency');
|
|
|
|
modalTitle.textContent = 'Edit ' + name;
|
|
modalBodyInputId.value = id;
|
|
modalBodyInputName.value = name;
|
|
modalBodyInputCost.value = cost;
|
|
modalBodyInputRenewalDate.value = renewal_date;
|
|
modalBodyInputCategory.value = category;
|
|
modalBodyInputFrequency.value = frequency;
|
|
});
|
|
});
|
|
</script>
|
|
</body>
|
|
</html>
|