user.php (4607B)
1 <?php 2 class ModelUserUser extends Model { 3 public function addUser($data) { 4 $this->db->query("INSERT INTO `" . DB_PREFIX . "user` SET username = '" . $this->db->escape($data['username']) . "', user_group_id = '" . (int)$data['user_group_id'] . "', salt = '" . $this->db->escape($salt = token(9)) . "', password = '" . $this->db->escape(sha1($salt . sha1($salt . sha1($data['password'])))) . "', firstname = '" . $this->db->escape($data['firstname']) . "', lastname = '" . $this->db->escape($data['lastname']) . "', email = '" . $this->db->escape($data['email']) . "', image = '" . $this->db->escape($data['image']) . "', status = '" . (int)$data['status'] . "', date_added = NOW()"); 5 6 return $this->db->getLastId(); 7 } 8 9 public function editUser($user_id, $data) { 10 $this->db->query("UPDATE `" . DB_PREFIX . "user` SET username = '" . $this->db->escape($data['username']) . "', user_group_id = '" . (int)$data['user_group_id'] . "', firstname = '" . $this->db->escape($data['firstname']) . "', lastname = '" . $this->db->escape($data['lastname']) . "', email = '" . $this->db->escape($data['email']) . "', image = '" . $this->db->escape($data['image']) . "', status = '" . (int)$data['status'] . "' WHERE user_id = '" . (int)$user_id . "'"); 11 12 if ($data['password']) { 13 $this->db->query("UPDATE `" . DB_PREFIX . "user` SET salt = '" . $this->db->escape($salt = token(9)) . "', password = '" . $this->db->escape(sha1($salt . sha1($salt . sha1($data['password'])))) . "' WHERE user_id = '" . (int)$user_id . "'"); 14 } 15 } 16 17 public function editPassword($user_id, $password) { 18 $this->db->query("UPDATE `" . DB_PREFIX . "user` SET salt = '" . $this->db->escape($salt = token(9)) . "', password = '" . $this->db->escape(sha1($salt . sha1($salt . sha1($password)))) . "', code = '' WHERE user_id = '" . (int)$user_id . "'"); 19 } 20 21 public function editCode($email, $code) { 22 $this->db->query("UPDATE `" . DB_PREFIX . "user` SET code = '" . $this->db->escape($code) . "' WHERE LCASE(email) = '" . $this->db->escape(utf8_strtolower($email)) . "'"); 23 } 24 25 public function deleteUser($user_id) { 26 $this->db->query("DELETE FROM `" . DB_PREFIX . "user` WHERE user_id = '" . (int)$user_id . "'"); 27 } 28 29 public function getUser($user_id) { 30 $query = $this->db->query("SELECT *, (SELECT ug.name FROM `" . DB_PREFIX . "user_group` ug WHERE ug.user_group_id = u.user_group_id) AS user_group FROM `" . DB_PREFIX . "user` u WHERE u.user_id = '" . (int)$user_id . "'"); 31 32 return $query->row; 33 } 34 35 public function getUserByUsername($username) { 36 $query = $this->db->query("SELECT * FROM `" . DB_PREFIX . "user` WHERE username = '" . $this->db->escape($username) . "'"); 37 38 return $query->row; 39 } 40 41 public function getUserByEmail($email) { 42 $query = $this->db->query("SELECT DISTINCT * FROM `" . DB_PREFIX . "user` WHERE LCASE(email) = '" . $this->db->escape(utf8_strtolower($email)) . "'"); 43 44 return $query->row; 45 } 46 47 public function getUserByCode($code) { 48 $query = $this->db->query("SELECT * FROM `" . DB_PREFIX . "user` WHERE code = '" . $this->db->escape($code) . "' AND code != ''"); 49 50 return $query->row; 51 } 52 53 public function getUsers($data = array()) { 54 $sql = "SELECT * FROM `" . DB_PREFIX . "user`"; 55 56 $sort_data = array( 57 'username', 58 'status', 59 'date_added' 60 ); 61 62 if (isset($data['sort']) && in_array($data['sort'], $sort_data)) { 63 $sql .= " ORDER BY " . $data['sort']; 64 } else { 65 $sql .= " ORDER BY username"; 66 } 67 68 if (isset($data['order']) && ($data['order'] == 'DESC')) { 69 $sql .= " DESC"; 70 } else { 71 $sql .= " ASC"; 72 } 73 74 if (isset($data['start']) || isset($data['limit'])) { 75 if ($data['start'] < 0) { 76 $data['start'] = 0; 77 } 78 79 if ($data['limit'] < 1) { 80 $data['limit'] = 20; 81 } 82 83 $sql .= " LIMIT " . (int)$data['start'] . "," . (int)$data['limit']; 84 } 85 86 $query = $this->db->query($sql); 87 88 return $query->rows; 89 } 90 91 public function getTotalUsers() { 92 $query = $this->db->query("SELECT COUNT(*) AS total FROM `" . DB_PREFIX . "user`"); 93 94 return $query->row['total']; 95 } 96 97 public function getTotalUsersByGroupId($user_group_id) { 98 $query = $this->db->query("SELECT COUNT(*) AS total FROM `" . DB_PREFIX . "user` WHERE user_group_id = '" . (int)$user_group_id . "'"); 99 100 return $query->row['total']; 101 } 102 103 public function getTotalUsersByEmail($email) { 104 $query = $this->db->query("SELECT COUNT(*) AS total FROM `" . DB_PREFIX . "user` WHERE LCASE(email) = '" . $this->db->escape(utf8_strtolower($email)) . "'"); 105 106 return $query->row['total']; 107 } 108 }