[ Mini Kiebo ]
Server: Windows NT AKFAR_SERVER 10.0 build 26200 (Windows 10) AMD64
Path:
D:
/
xampp
/
htdocs
/
campus_repo
/
public
/
[
Home
]
File: admin.php
<?php if (session_status() === PHP_SESSION_NONE) { session_start(); } require_once __DIR__ . '/../config/config.php'; require_once __DIR__ . '/../src/Database.php'; require_once __DIR__ . '/../src/Utils.php'; require_once __DIR__ . '/../src/auth.php'; requireRole(['admin','editor']); // Hanya admin/editor yang boleh masuk if (!isset($_SESSION['user']) || !in_array($_SESSION['user']['role'], ['admin','editor'])) { header("Location: login.php?msg=unauthorized"); exit; } $pdo = Database::getConnection(); $message = ''; // Proses approve/reject if ($_SERVER['REQUEST_METHOD'] === 'POST' && isset($_POST['doc_id'], $_POST['action'])) { $docId = intval($_POST['doc_id']); $action = $_POST['action'] === 'approve' ? 'approved' : 'rejected'; $stmt = $pdo->prepare("UPDATE documents SET status = ? WHERE id = ?"); if ($stmt->execute([$action, $docId])) { $message = "✅ Dokumen ID $docId berhasil diubah menjadi $action."; } else { $message = "❌ Gagal memperbarui status dokumen."; } } // Ambil dokumen submitted $stmt = $pdo->query("SELECT id, title, authors, year, subject_area, file_path FROM documents WHERE status = 'submitted' ORDER BY created_at DESC"); $docs = $stmt->fetchAll(PDO::FETCH_ASSOC); ?> <?php include 'header.php'; ?> <h2>Panel Admin / Editor</h2> <?php if ($message): ?> <div style="color:green;"><?= Utils::sanitize($message) ?></div> <?php endif; ?> <table border="1" cellpadding="8" cellspacing="0" style="margin-top:20px; width:100%;"> <thead> <tr style="background-color:#eee;"> <th>ID</th> <th>Judul</th> <th>Penulis</th> <th>Tahun</th> <th>Bidang</th> <th>File</th> <th>Aksi</th> </tr> </thead> <tbody> <?php if (count($docs) > 0): ?> <?php foreach ($docs as $doc): ?> <tr> <td><?= $doc['id'] ?></td> <td><?= Utils::sanitize($doc['title']) ?></td> <td><?= Utils::sanitize($doc['authors']) ?></td> <td><?= Utils::sanitize($doc['year']) ?></td> <td><?= Utils::sanitize($doc['subject_area']) ?></td> <td><a href="uploads/<?= Utils::sanitize($doc['file_path']) ?>" target="_blank">Download</a></td> <td> <form method="post" style="display:inline;"> <input type="hidden" name="doc_id" value="<?= $doc['id'] ?>"> <button type="submit" name="action" value="approve">Approve</button> </form> <form method="post" style="display:inline;"> <input type="hidden" name="doc_id" value="<?= $doc['id'] ?>"> <button type="submit" name="action" value="reject">Reject</button> </form> </td> </tr> <?php endforeach; ?> <?php else: ?> <tr><td colspan="7">Tidak ada dokumen menunggu verifikasi.</td></tr> <?php endif; ?> </tbody> </table> <?php include 'footer.php'; ?>