add.php
来自「通达OA2007SE源代码 非常好的」· PHP 代码 · 共 168 行
PHP
168 行
<?
include_once 'inc/auth.php';
include_once 'inc/utility_all.php';
include_once 'inc/check_type.php';
echo '
<html>
<head>
<title>新建用户</title>
<meta http-equiv="Content-Type" content="text/html; charset=gb2312">
</head>
<body class="bodycolor" topmargin="5">
';
if ((($BIND_IP != '') AND !is_ip ($BIND_IP)))
{
message ('', 'IP地址无效');
button_back ();
exit ();
}
if (($NOT_LOGIN != 'on'))
{
$USER_NUM_CHECK = 1;
}
include 'inc/reg_check.php';
if (($OA_REG_ON != 2008))
{
exit ();
}
if ((strstr ($USER_ID, '\\\'') != false))
{
message ('错误', '用户名中含有非法字符');
button_back ();
exit ();
}
if ((strstr ($BYNAME, '\\\'') != false))
{
message ('错误', '别名中含有非法字符');
button_back ();
exit ();
}
if ((strstr ($PASSWORD, '\\\'') != false))
{
message ('错误', '密码中含有非法字符');
button_back ();
exit ();
}
if ((($BIRTHDAY != '') AND !is_date ($BIRTHDAY)))
{
message ('错误', ('生日格式不合法,应形如:'.date ('Y-m-d', time ())));
button_back ();
exit ();
}
if (($BYNAME == $USER_ID))
{
message ('错误', '用户和别名不能相同已存在');
button_back ();
exit ();
}
$query = (((((''.'select * from USER where USER_ID=\'').$USER_ID).'\' or BYNAME=\'').$USER_ID).'\'');
$cursor = exequery ($connection, $query);
if ($ROW = mysql_fetch_array ($cursor))
{
message ('错误', (('用户名或别名 '.$USER_ID).' 已存在'));
button_back ();
exit ();
}
if (($BYNAME != ''))
{
$query = (((((''.'select * from USER where BYNAME=\'').$BYNAME).'\' or USER_ID=\'').$BYNAME).'\'');
$cursor = exequery ($connection, $query);
if ($ROW = mysql_fetch_array ($cursor))
{
message ('错误', (('用户名或别名 '.$BYNAME).' 已存在'));
button_back ();
exit ();
}
}
if (($USER_NO == ''))
{
$USER_NO = 10;
}
if (!is_number ($USER_NO))
{
message ('错误', '用户排序号应为数字');
button_back ();
exit ();
}
if (($NOT_LOGIN == 'on'))
{
$NOT_LOGIN = 1;
}
else
{
$NOT_LOGIN = 0;
}
if (($NOT_VIEW_USER == 'on'))
{
$NOT_VIEW_USER = 1;
}
else
{
$NOT_VIEW_USER = 0;
}
if (($NOT_VIEW_TABLE == 'on'))
{
$NOT_VIEW_TABLE = 1;
}
else
{
$NOT_VIEW_TABLE = 0;
}
if (($MOBIL_NO_HIDDEN == 'on'))
{
$MOBIL_NO_HIDDEN = '1';
}
else
{
$MOBIL_NO_HIDDEN = '0';
}
if (($USEING_KEY == 'on'))
{
$USEING_KEY = 1;
}
else
{
$USEING_KEY = 0;
}
$EMAIL_CAPACITY = intval ($EMAIL_CAPACITY);
$FOLDER_CAPACITY = intval ($FOLDER_CAPACITY);
if ((($EMAIL_CAPACITY != '') AND (!is_int ($EMAIL_CAPACITY) OR ($EMAIL_CAPACITY < 0))))
{
message ('错误', '内部邮箱容量应为整数!');
button_back ();
exit ();
}
if ((($FOLDER_CAPACITY != '') AND (!is_int ($FOLDER_CAPACITY) OR ($FOLDER_CAPACITY < 0))))
{
message ('错误', '个人文件柜容量应为整数!');
button_back ();
exit ();
}
$PASSWORD = crypt ($PASSWORD);
$query = (((((((((((((((((((((((((((((((((((((((((((((((((((''.'insert into USER (USER_ID,USER_NAME,SEX,PASSWORD,USER_PRIV,POST_PRIV,POST_DEPT,CANBROADCAST,DEPT_ID,AVATAR,CALL_SOUND,DUTY_TYPE,SMS_ON,MENU_HIDE,EMAIL_CAPACITY,FOLDER_CAPACITY,USER_PRIV_OTHER,USER_NO,NOT_LOGIN,NOT_VIEW_USER,NOT_VIEW_TABLE,BYNAME,BIRTHDAY,THEME,MOBIL_NO,MOBIL_NO_HIDDEN,BIND_IP,KEY_SN,USEING_KEY) values (\'').$USER_ID).'\',\'').$USER_NAME).'\',\'').$SEX).'\',\'').$PASSWORD).'\',\'').$USER_PRIV).'\',\'').$POST_PRIV).'\',\'').$TO_ID).'\',\'').$CANBROADCAST).'\',\'').$DEPT_ID).'\',\'1\',\'1\',\'').$DUTY_TYPE).'\',\'1\',\'2\',').$EMAIL_CAPACITY).',').$FOLDER_CAPACITY).',\'').$PRIV_ID).'\',').$USER_NO).',\'').$NOT_LOGIN).'\',\'').$NOT_VIEW_USER).'\',\'').$NOT_VIEW_TABLE).'\',\'').$BYNAME).'\',\'').$BIRTHDAY).'\',\'').$THEME).'\',\'').$MOBIL_NO).'\',\'').$MOBIL_NO_HIDDEN).'\',\'').$BIND_IP).'\',\'').$KEY_SN).'\',\'').$USEING_KEY).'\')');
exequery ($connection, $query);
add_log (6, $USER_ID, $LOGIN_USER_ID);
message ('', '用户增加成功');
echo '
';
echo '<s';
echo 'cript>
opener.parent.user_list.location.reload();
opener.location="user_new.php?DEPT_ID=';
echo $DEPT_ID;
echo '";
</script>
<div align="center">
<input type="button" value="继续新建用户" class="BigButton" title="继续新建用户" onclick="location=\'new.php?DEPT_ID=';
echo $DEPT_ID;
echo '\'">
<input type="button" value="建立档案" class="BigButton" title="建立档案" onclick="location=\'../../hrms/manage/hrms.php?USER_ID=';
echo $USER_ID;
echo '\'">
<input type="button" value="关 闭" class="BigButton" title="关闭窗口" onclick="window.close();">
</div>
</body>
</html>
';
?>
⌨️ 快捷键说明
复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?