SECURITY : admin action are always loggued

This commit is contained in:
sparkyx 2025-01-19 12:13:41 +01:00
parent fcb62c09de
commit ba773b09d0
2 changed files with 17 additions and 5 deletions

View file

@ -36,21 +36,30 @@ $rep=new Database();
$User=new Noalyss_user($rep);
$User->Check();
$audit=true;
if ($User->admin != 1)
{
$theme=(isset($User->theme))?$User->theme:"";
$User->audit('FAIL',"ADMIN : [$action]".var_export($_REQUEST,true));
html_page_start($theme);
echo "<h2 class=\"warning\">";
echo '<div class=content" style="padding:5%">';
echo "<h1 class=\"title\">";
echo _("Accès interdit");
echo "</h1>";
echo '<span class="warning">';
echo _("Vous n'êtes pas administateur");
echo "</h2>";
echo '</span>';
$reconnect=http_build_query(array("reconnect"=>1,"backurl"=>"admin-noalyss.php?action=upgrade"));
echo '<a href="'.NOALYSS_URL.'/index.php?'.$reconnect.'">';
echo _("Connectez-vous comme administrateur");
echo '<a class="mtitle" style="text-decoration:underline" href="'.NOALYSS_URL.'/index.php?'.$reconnect.'">';
echo _("Cliquez ici pour vous connecter comme administrateur");
echo '</a>';
html_page_stop();
return;
}
$User->audit('SUCCESS',"ADMIN : [$action] ".var_export($_REQUEST,true));
// For a backup , we must avoid to send anything before the
// dump file
if ( $action== 'backup') {

View file

@ -27,15 +27,18 @@ if (!defined('ALLOWED'))
* admin-noalyss.php
* @see admin-noalyss.php ajax_misc.php admin.js
*/
global $g_user;
global $g_user,$audit;
$audit=true;
if ($g_user->isAdmin()==0)
{
$g_user->audit('FAIL',"ADMIN : ".var_export($_REQUEST,true));
die();
}
session_write_close();
set_language();
$http=new HttpInput();
$op=$http->request("op");
$g_user->audit('SUCCESS',"ADMIN : $op");
// From admin, grant the access to a folder to an
// user
if ($op=='folder_add') // operation