Орла
Области
Компаний
Пользователи
Галерея
Фиксированные новости
Орла
Отзывы о фирмах
Тарифы
Пользователи
Области
Банкоматы
Торговые точки
Доска объявлений
Курсы валют
Скидки
организации Орла
организации области
товары
сайты
сайты Орел
Данные
Разделы
Поиск
Поиск запросы
Статистика
Показы каталога организаций
Статистика клиенты
Пользователи
Сайты
Управление сайтом
Анкета
Аптеки
Афиша
Афиша новая
Баннеры
Бизнес >
Викторина
Голосование
Гость на сайте
Истории
Календарь событий
Каталоги >
Конкурс красоты
Конкурс аудио
Консультации
Меню
Новое на сайте
Новости >
Организации >
Программа ТВ
Публикации
Разделы сайта
Рассылка
Рестораны
Секрет фирмы >
Сервисы >
Ссылки
Тесты
Файловый менеджер
Форум
Фотогалерея
Обратная связь
Недвижимость
Новый год
Тексты
Пользователи
Юридический рейтинг
Отзывы на товары
Бан пользователей
Жалобы
Новые тесты
Коронавирус
Файловый менеджер
Имя файла
check_user_privileges.lib.php
Содержимое
<?php /* vim: set expandtab sw=4 ts=4 sts=4: */ /** * Get user's global privileges and some db-specific privileges * ($controllink and $userlink are links to MySQL defined in the "common.inc.php" library) * Note: if no controluser is defined, $controllink contains $userlink * * @version $Id$ */ if (! defined('PHPMYADMIN')) { exit; } /** * */ $is_create_db_priv = false; $is_process_priv = true; $is_reload_priv = false; $db_to_create = ''; $dbs_where_create_table_allowed = array(); // We were trying to find if user if superuser with 'USE mysql' // but users with the global priv CREATE TEMPORARY TABLES or LOCK TABLES // can do a 'USE mysql' (even if they cannot see the tables) $is_superuser = PMA_isSuperuser(); function PMA_analyseShowGrant($rs_usr, &$is_create_db_priv, &$db_to_create, &$is_reload_priv, &$dbs_where_create_table_allowed) { $re0 = '(^|(\\\\\\\\)+|[^\])'; // non-escaped wildcards $re1 = '(^|[^\])(\\\)+'; // escaped wildcards while ($row = PMA_DBI_fetch_row($rs_usr)) { $show_grants_dbname = substr($row[0], strpos($row[0], ' ON ') + 4, (strpos($row[0], '.', strpos($row[0], ' ON ')) - strpos($row[0], ' ON ') - 4)); $show_grants_dbname = ereg_replace('^`(.*)`', '\\1', $show_grants_dbname); $show_grants_str = substr($row[0], 6, (strpos($row[0], ' ON ') - 6)); if ($show_grants_str == 'RELOAD') { $is_reload_priv = true; } /** * @todo if we find CREATE VIEW but not CREATE, do not offer * the create database dialog box */ if (($show_grants_str == 'ALL') || ($show_grants_str == 'ALL PRIVILEGES') || ($show_grants_str == 'CREATE') || strpos($show_grants_str, 'CREATE,') !== false) { if ($show_grants_dbname == '*') { // a global CREATE privilege $is_create_db_priv = true; $is_reload_priv = true; $db_to_create = ''; $dbs_where_create_table_allowed[] = '*'; break; } else { // this array may contain wildcards $dbs_where_create_table_allowed[] = $show_grants_dbname; // before MySQL 4.1.0, we cannot use backquotes around a dbname // for the USE command, so the USE will fail if the dbname contains // a "-" and we cannot detect if such a db already exists; // since 4.1.0, we need to use backquotes if the dbname contains a "-" // in a USE command if (PMA_MYSQL_INT_VERSION > 40100) { $dbname_to_test = PMA_backquote($show_grants_dbname); } else { $dbname_to_test = $show_grants_dbname; } if ((ereg($re0 . '%|_', $show_grants_dbname) && !ereg('\\\\%|\\\\_', $show_grants_dbname)) // does this db exist? || (!PMA_DBI_try_query('USE ' . ereg_replace($re1 .'(%|_)', '\\1\\3', $dbname_to_test), null, PMA_DBI_QUERY_STORE) && substr(PMA_DBI_getError(), 1, 4) != 1044) ) { $db_to_create = ereg_replace($re0 . '%', '\\1...', ereg_replace($re0 . '_', '\\1?', $show_grants_dbname)); $db_to_create = ereg_replace($re1 . '(%|_)', '\\1\\3', $db_to_create); $is_create_db_priv = true; /** * @todo collect $db_to_create into an array, to display a * drop-down in the "Create new database" dialog */ // we don't break, we want all possible databases //break; } // end if } // end elseif } // end if } // end while } // end function // Detection for some CREATE privilege. // Since MySQL 4.1.2, we can easily detect current user's grants // using $userlink (no control user needed) // and we don't have to try any other method for detection if (PMA_MYSQL_INT_VERSION >= 40102) { $rs_usr = PMA_DBI_try_query('SHOW GRANTS', $userlink, PMA_DBI_QUERY_STORE); if ($rs_usr) { PMA_analyseShowGrant($rs_usr, $is_create_db_priv, $db_to_create, $is_reload_priv, $dbs_where_create_table_allowed); PMA_DBI_free_result($rs_usr); unset($rs_usr); } } else { // Before MySQL 4.1.2, we first try to find a priv in mysql.user. Hopefuly // the controluser is correctly defined; but here, $controllink could contain // $userlink so maybe the SELECT will fail if (!$is_create_db_priv) { $res = PMA_DBI_query('SELECT USER();', null, PMA_DBI_QUERY_STORE); list($mysql_cur_user_and_host) = PMA_DBI_fetch_row($res); $mysql_cur_user = substr($mysql_cur_user_and_host, 0, strrpos($mysql_cur_user_and_host, '@')); $local_query = 'SELECT Create_priv, Reload_priv FROM mysql.user WHERE ' . PMA_convert_using('User') . ' = ' . PMA_convert_using(PMA_sqlAddslashes($mysql_cur_user), 'quoted') . ' OR ' . PMA_convert_using('User') . ' = ' . PMA_convert_using('', 'quoted') . ';'; $rs_usr = PMA_DBI_try_query($local_query, $controllink, PMA_DBI_QUERY_STORE); // Debug: or PMA_mysqlDie('', $local_query, false); if ($rs_usr) { while ($result_usr = PMA_DBI_fetch_assoc($rs_usr)) { if (!$is_create_db_priv) { $is_create_db_priv = ($result_usr['Create_priv'] == 'Y'); } if (!$is_reload_priv) { $is_reload_priv = ($result_usr['Reload_priv'] == 'Y'); } } // end while PMA_DBI_free_result($rs_usr); unset($rs_usr, $result_usr); if ($is_create_db_priv) { $dbs_where_create_table_allowed[] = '*'; } } // end if } // end if // If the user has Create priv on a inexistant db, show him in the dialog // the first inexistant db name that we find, in most cases it's probably // the one he just dropped :) if (!$is_create_db_priv) { $local_query = 'SELECT DISTINCT Db FROM mysql.db WHERE ' . PMA_convert_using('Create_priv') . ' = ' . PMA_convert_using('Y', 'quoted') . ' AND (' . PMA_convert_using('User') . ' = ' .PMA_convert_using(PMA_sqlAddslashes($mysql_cur_user), 'quoted') . ' OR ' . PMA_convert_using('User') . ' = ' . PMA_convert_using('', 'quoted') . ');'; $rs_usr = PMA_DBI_try_query($local_query, $controllink, PMA_DBI_QUERY_STORE); if ($rs_usr) { $re0 = '(^|(\\\\\\\\)+|[^\])'; // non-escaped wildcards $re1 = '(^|[^\])(\\\)+'; // escaped wildcards while ($row = PMA_DBI_fetch_assoc($rs_usr)) { $dbs_where_create_table_allowed[] = $row['Db']; if (ereg($re0 . '(%|_)', $row['Db']) || (!PMA_DBI_try_query('USE ' . ereg_replace($re1 . '(%|_)', '\\1\\3', $row['Db'])) && substr(PMA_DBI_getError(), 1, 4) != 1044)) { $db_to_create = ereg_replace($re0 . '%', '\\1...', ereg_replace($re0 . '_', '\\1?', $row['Db'])); $db_to_create = ereg_replace($re1 . '(%|_)', '\\1\\3', $db_to_create); $is_create_db_priv = true; break; } // end if } // end while PMA_DBI_free_result($rs_usr); unset($rs_usr, $row, $re0, $re1); } else { // Finally, let's try to get the user's privileges by using SHOW // GRANTS... // Maybe we'll find a little CREATE priv there :) $rs_usr = PMA_DBI_try_query('SHOW GRANTS FOR ' . $mysql_cur_user_and_host . ';', $controllink, PMA_DBI_QUERY_STORE); if (!$rs_usr) { // OK, now we'd have to guess the user's hostname, but we // only try out the 'username'@'%' case. $rs_usr = PMA_DBI_try_query('SHOW GRANTS FOR ' . PMA_convert_using(PMA_sqlAddslashes($mysql_cur_user), 'quoted') . ';', $controllink, PMA_DBI_QUERY_STORE); } unset($local_query); if ($rs_usr) { PMA_analyseShowGrant($rs_usr, $is_create_db_priv, $db_to_create, $is_reload_priv, $dbs_where_create_table_allowed); PMA_DBI_free_result($rs_usr); unset($rs_usr); } // end if } // end elseif } // end if } // end else (MySQL < 4.1.2) // If disabled, don't show it if (!$cfg['SuggestDBName']) { $db_to_create = ''; } ?>
/admin/myadmin2/libraries/
Имя
Дата
Размер
..
2013-06-28
auth
2013-06-28
dbg
2013-06-28
dbi
2013-06-28
engines
2013-06-28
export
2013-06-28
import
2013-06-28
tcpdf
2013-06-28
transformations
2013-06-28
.htaccess
2015-04-04
118 байт
Config.class.php
2013-06-28
34 кб.
File.class.php
2013-06-28
25 кб.
List.class.php
2013-06-28
4 кб.
List_Database.class.php
2013-06-28
18 кб.
StorageEngine.class.php
2013-06-28
15 кб.
Table.class.php
2013-06-28
44 кб.
Theme.class.php
2013-06-28
9 кб.
Theme_Manager.class.php
2013-06-28
10 кб.
blowfish.php
2013-06-28
27 кб.
bookmark.lib.php
2013-06-28
6 кб.
charset_conversion.lib.php
2013-06-28
11 кб.
check_user_privileges.lib.php
2013-06-28
8 кб.
cleanup.lib.php
2013-06-28
1 кб.
common.inc.php
2013-06-28
27 кб.
common.lib.php
2013-06-28
80 кб.
config.default.php
2013-06-28
51 кб.
core.lib.php
2013-06-28
18 кб.
database_interface.lib.php
2013-06-28
49 кб.
db_common.inc.php
2013-06-28
2 кб.
db_info.inc.php
2013-06-28
8 кб.
db_links.inc.php
2013-06-28
4 кб.
db_routines.inc.php
2013-06-28
4 кб.
db_table_exists.lib.php
2013-06-28
3 кб.
display_change_password.lib.php
2013-06-28
3 кб.
display_create_database.lib.php
2013-06-28
2 кб.
display_create_table.lib.php
2013-06-28
4 кб.
display_export.lib.php
2013-06-28
9 кб.
display_import.lib.php
2013-06-28
7 кб.
display_select_lang.lib.php
2013-06-28
4 кб.
display_tbl.lib.php
2013-06-28
102 кб.
display_tbl_links.lib.php
2013-06-28
2 кб.
file_listing.php
2013-06-28
2 кб.
footer.inc.php
2013-06-28
6 кб.
get_foreign.lib.php
2013-06-28
3 кб.
grab_globals.lib.php
2013-06-28
4 кб.
header.inc.php
2013-06-28
12 кб.
header_http.inc.php
2013-06-28
740 байт
header_meta_style.inc.php
2013-06-28
2 кб.
header_printview.inc.php
2013-06-28
3 кб.
iconv_wrapper.lib.php
2013-06-28
3 кб.
import.lib.php
2013-06-28
11 кб.
information_schema_relations.lib.php
2013-06-28
4 кб.
ip_allow_deny.lib.php
2013-06-28
5 кб.
js_escape.lib.php
2013-06-28
2 кб.
kanji-encoding.lib.php
2013-06-28
4 кб.
language.lib.php
2013-06-28
354 байт
mcrypt.lib.php
2013-06-28
3 кб.
mult_submits.inc.php
2013-06-28
16 кб.
mysql_charsets.lib.php
2013-06-28
14 кб.
navigation_header.inc.php
2013-06-28
4 кб.
ob.lib.php
2013-06-28
3 кб.
opendocument.lib.php
2013-06-28
8 кб.
parse_analyze.lib.php
2013-06-28
2 кб.
plugin_interface.lib.php
2013-06-28
14 кб.
relation.lib.php
2013-06-28
37 кб.
relation_cleanup.lib.php
2013-06-28
8 кб.
sanitizing.lib.php
2013-06-28
2 кб.
select_lang.lib.php
2013-06-28
22 кб.
select_server.lib.php
2013-06-28
4 кб.
server_common.inc.php
2013-06-28
1 кб.
server_links.inc.php
2013-06-28
2 кб.
session.inc.php
2013-06-28
4 кб.
sql_query_form.lib.php
2013-06-28
21 кб.
sqlparser.data.php
2013-06-28
27 кб.
sqlparser.lib.php
2013-06-28
100 кб.
sqlvalidator.class.php
2013-06-28
13 кб.
sqlvalidator.lib.php
2013-06-28
3 кб.
string.lib.php
2013-06-28
6 кб.
string_mb.lib.php
2013-06-28
2 кб.
string_native.lib.php
2013-06-28
2 кб.
string_type_ctype.lib.php
2013-06-28
3 кб.
string_type_native.lib.php
2013-06-28
4 кб.
tbl_common.php
2013-06-28
1018 байт
tbl_indexes.lib.php
2013-06-28
11 кб.
tbl_info.inc.php
2013-06-28
3 кб.
tbl_links.inc.php
2013-06-28
4 кб.
tbl_properties.inc.php
2013-06-28
30 кб.
tbl_replace_fields.inc.php
2013-06-28
4 кб.
tbl_triggers.lib.php
2013-06-28
2 кб.
transformations.lib.php
2013-06-28
9 кб.
unzip.lib.php
2013-06-28
16 кб.
url_generating.lib.php
2013-06-28
6 кб.
zip.lib.php
2013-06-28
6 кб.
/admin/myadmin2/libraries
Загрузить файлы
Файл 1
Файл 2
Файл 3