1<?php
2/**
3 * ZnoteX Admin Control Panel - single entry point.
4 */
5
6define('ACP_ROOT', __DIR__);
7
8chdir(dirname(__DIR__));
9
10require_once 'engine/init.php';
11
12if (user_logged_in() !== true) {
13 header('Location: ../protected.php');
14 exit;
15}
16
17if (!has_admin_panel_access($user_data ?? null)) {
18 acp_log('access.panel_denied', (string)($_GET['p'] ?? 'dashboard'));
19 header('Location: ../myaccount.php');
20 exit;
21}
22
23if (znote2fa_setup_incomplete((int)$session_user_id, true)) {
24 header('Location: ../twofa.php');
25 exit;
26}
27
28require_once ACP_ROOT . '/bootstrap.php';
29
30$acp_modules = acp_modules();
31
32$acp_page = (string)($_GET['p'] ?? 'dashboard');
33if (!isset($acp_modules[$acp_page])) {
34 $acp_page = isset($acp_modules['dashboard'])
35 ? 'dashboard'
36 : (string)(array_key_first($acp_modules) ?? '');
37}
38
39$acp_module = $acp_modules[$acp_page] ?? null;
40
41if ($acp_module !== null && !acp_can_module($acp_page)) {
42 acp_log('access.module_denied', $acp_page, ['roles' => admin_roles($user_data)]);
43 http_response_code(403);
44 die('You do not have permission to access this admin module.');
45}
46
47// A nav entry that points somewhere else on the site is a link, not a page.
48if ($acp_module !== null && !empty($acp_module['url'])) {
49 header('Location: ' . $acp_module['url']);
50 exit;
51}
52
53// A POST larger than post_max_size reaches PHP with $_POST and $_FILES both
54// emptied, which would otherwise look like a forged request.
55if ($_SERVER['REQUEST_METHOD'] === 'POST'
56 && !$_POST && !$_FILES
57 && (int)($_SERVER['CONTENT_LENGTH'] ?? 0) > 0
58) {
59 http_response_code(413);
60 die('That upload was larger than post_max_size in php.ini, so PHP discarded it. Raise post_max_size and upload_max_filesize, then try again.');
61}
62
63if ($_SERVER['REQUEST_METHOD'] === 'POST' && !acp_verify_csrf()) {
64 acp_log('security.csrf_rejected', $acp_page);
65 http_response_code(400);
66 die('Invalid CSRF token. Reload the page and try again.');
67}
68
69ob_start();
70if ($acp_module !== null) {
71 include $acp_module['file'];
72} else {
73 acp_empty('No admin modules are installed in admin/modules/.', 'fa-plug');
74}
75$acp_content = ob_get_clean();
76
77include ACP_ROOT . '/layout/shell.php';
78