| 123456789101112131415161718192021222324252627 |
- <?php
- include($_SERVER['DOCUMENT_ROOT'] . "/Authorization/script/php/permission/connect_sql.php");
- session_start();
- $href = 'http://' . $_SERVER['HTTP_HOST'] . '/Front-Page/pages-signin.html';
- //Can't come in without logged in
- if (!isset($_SESSION['loggedin'])) {
- header('Location:' . $href);
- exit;
- }
- $sql = "SELECT [RightID],[GroupName] FROM [UserGroup]
- LEFT JOIN [GroupRight] ON [GroupRight].[GroupID] = [UserGroup].[GroupID]
- LEFT JOIN [Group] ON [GroupRight].[GroupID] = [Group].[GroupID]
- WHERE [PgroupID] = (SELECT [PgroupID] FROM [WebPage] WHERE [PageID] = ? ) AND [UserGroup].UserID = ?";
- $stmt = sqlsrv_query($conn, $sql, array(strtok($_SERVER["REQUEST_URI"], '?'), $_SESSION['UserID']));
- $right = -1;
- while ($row = sqlsrv_fetch_array($stmt, SQLSRV_FETCH_ASSOC)) {
- if ($row["RightID"] > $right) {
- $groupName = $row["GroupName"];
- $right = $row["RightID"];
- }
- }
- //Can't come in without right
- if ($right < 0) {
- $url = 'http://' . $_SERVER['HTTP_HOST'] . '/Front-Page/home.php';
- header('Location: ' . $url);
- exit;
- }
|