]> andersk Git - sql-web.git/blobdiff - tpl/menu.php
Fix CSRF vulnerabilities
[sql-web.git] / tpl / menu.php
index 572e0d0b739414c55505770e030cb1279040a973..2bd5a09328a039b39f6505c9967140ed48bc10b6 100644 (file)
@@ -1,12 +1,36 @@
-<div id="content1">
+                               <div id="hnav">
+                                       <ul id="navlist">
 <?php if (isLoggedIn()): ?>
-<div style="float:left">
-<a href="logout">Logout</a>
-</div>&nbsp;
-Logged in as <em><?=$Username?></em> on <?=DBHOST?>
+<div style="float:left;">
+<li><a href="do/main?refresh">Databases</a></li>
+<li><a href="do/setup">Account</a></li>
+<?php if (isAdmin()) { ?>
+<li><a href="do/admin/main">Admin</a></li>
+<?php } ?>
+<li><a href="do/logout">Logout</a></li>
+</div>
+<?php
+       $loggedInText = $Login->getUsername();
+       if (isImpersonating()) {
+               $loggedInText = '<li><a href="do/admin/main?impersonate">'.$loggedInText.'</a></li>';
+       }
+?>
+<div style="text-align: right;">
+Logged in: <em><?=$loggedInText?>@<?=DBHOST?></em>&nbsp;
+</div>
 <?php else: ?>
-<div style="float:left">
-<a href="signup">Signup</a> | Login via <a href="login?ssl=0">SQL</a> or <a href="login?ssl=1">SSL</a>
-</div>&nbsp;
-<?php endif; ?>
+<div style="float:left;">
+<li><a href="http://scripts.mit.edu/faq/27">Sign up</a></li>
+<li><a href="https://scripts.mit.edu/~sql/phpMyAdmin/" target="_blank">phpMyAdmin</a></li>
+<?php if (DEBUG) { ?>
+<li><a href="do/index">Home</a></li>
+<?php } else { ?>
+<li><a href="http://sql.mit.edu/">Home</a></li>
+<?php } ?>
 </div>
+<div style="text-align: right;">
+Login via: <li><a href="do/login?ssl=0">SQL Password</a></li><li><a href="do/login?ssl=1">MIT Certificate</a></li>
+</div>
+<?php endif; ?>
+                                       </ul>
+                               </div>
This page took 0.026907 seconds and 4 git commands to generate.