admin_roles($user_data)]); http_response_code(403); die('You do not have permission to access this admin module.'); } // A nav entry that points somewhere else on the site is a link, not a page. if ($acp_module !== null && !empty($acp_module['url'])) { header('Location: ' . $acp_module['url']); exit; } // A POST larger than post_max_size reaches PHP with $_POST and $_FILES both // emptied, which would otherwise look like a forged request. if ($_SERVER['REQUEST_METHOD'] === 'POST' && !$_POST && !$_FILES && (int)($_SERVER['CONTENT_LENGTH'] ?? 0) > 0 ) { http_response_code(413); die('That upload was larger than post_max_size in php.ini, so PHP discarded it. Raise post_max_size and upload_max_filesize, then try again.'); } if ($_SERVER['REQUEST_METHOD'] === 'POST' && !acp_verify_csrf()) { acp_log('security.csrf_rejected', $acp_page); http_response_code(400); die('Invalid CSRF token. Reload the page and try again.'); } ob_start(); if ($acp_module !== null) { include $acp_module['file']; } else { acp_empty('No admin modules are installed in admin/modules/.', 'fa-plug'); } $acp_content = ob_get_clean(); include ACP_ROOT . '/layout/shell.php';