admin.php 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223
  1. <?php
  2. session_start();
  3. require_once 'config.php';
  4. require_once 'db_config.php';
  5. // --- 1. LOGIN / LOGOUT SCHUTZ ---
  6. if (isset($_GET['logout'])) { session_destroy(); header("Location: admin.php"); exit; }
  7. $show_login = true;
  8. if (isset($_SESSION['admin_auth']) && $_SESSION['admin_auth'] === true) { $show_login = false; }
  9. if (isset($_POST['login_auth'])) {
  10. if ($_POST['pw'] === ADMIN_PASSWORD) {
  11. $_SESSION['admin_auth'] = true;
  12. $show_login = false;
  13. } else { $login_error = "Falsches Passwort!"; }
  14. }
  15. if ($show_login):
  16. ?>
  17. <!DOCTYPE html>
  18. <html lang="de">
  19. <head>
  20. <meta charset="UTF-8">
  21. <title>Admin Login</title>
  22. <style>
  23. body { font-family: 'Segoe UI', sans-serif; background: #121212; color: white; display: flex; justify-content: center; align-items: center; height: 100vh; margin: 0; }
  24. .login-box { background: #1e1e1e; padding: 40px; border-radius: 12px; border: 1px solid #e67e22; text-align: center; width: 300px; }
  25. input { width: 100%; padding: 12px; margin: 15px 0; border-radius: 5px; border: 1px solid #444; background: #2a2a2a; color: white; box-sizing: border-box; }
  26. button { background: #e67e22; color: white; border: none; padding: 12px; border-radius: 5px; cursor: pointer; width: 100%; font-weight: bold; }
  27. .error { color: #e74c3c; font-size: 0.9em; }
  28. </style>
  29. </head>
  30. <body>
  31. <div class="login-box">
  32. <h2>🔐 Admin Login</h2>
  33. <?php if(isset($login_error)) echo "<div class='error'>$login_error</div>"; ?>
  34. <form method="POST">
  35. <input type="password" name="pw" placeholder="Passwort" autofocus required>
  36. <button type="submit" name="login_auth">Einloggen</button>
  37. </form>
  38. </div>
  39. </body>
  40. </html>
  41. <?php exit; endif; ?>
  42. <?php
  43. // --- 2. DATENBANK LOGIK ---
  44. $msg = "";
  45. $msg_type = "success";
  46. if (isset($_POST['add_new_game'])) {
  47. $ean = trim($_POST['new_ean']);
  48. $titel = trim($_POST['new_titel']);
  49. $level = (empty($_POST['new_level']) || $_POST['new_level'] == 'Unknown') ? 'Unknown' : $_POST['new_level'];
  50. $typ_id = ($_POST['new_typ_id'] == '0') ? null : (int)$_POST['new_typ_id'];
  51. $bild_url = trim($_POST['new_bild_url']);
  52. try {
  53. $stmt = $pdo->prepare("INSERT INTO spiele (titel, typ_id, ean, level, bild_url) VALUES (?, ?, ?, ?, ?)");
  54. $stmt->execute([$titel, $typ_id, $ean, $level, $bild_url]);
  55. $msg = "✅ Spiel erfolgreich angelegt!";
  56. } catch (PDOException $e) {
  57. if ($e->getCode() == 23000) {
  58. $msg = "❌ Fehler: Die EAN $ean existiert bereits!";
  59. $msg_type = "error";
  60. } else { $msg = "Fehler: " . $e->getMessage(); }
  61. }
  62. }
  63. if (isset($_POST['update_game'])) {
  64. $stmt = $pdo->prepare("UPDATE spiele SET titel = ?, typ_id = ?, ean = ?, level = ?, bild_url = ? WHERE id = ?");
  65. $stmt->execute([$_POST['titel'], ($_POST['typ_id'] == '0' ? null : (int)$_POST['typ_id']), $_POST['ean'], $_POST['level'], $_POST['bild_url'], (int)$_POST['spiel_id']]);
  66. $msg = "💾 Änderungen gespeichert!";
  67. }
  68. if (isset($_POST['delete_game'])) {
  69. $pdo->prepare("DELETE FROM spiele WHERE id = ?")->execute([(int)$_POST['spiel_id']]);
  70. $msg = "🗑 Spiel gelöscht!";
  71. }
  72. $spiele = $pdo->query("SELECT s.*, t.bezeichnung as typ_name FROM spiele s LEFT JOIN game_typen t ON s.typ_id = t.id ORDER BY s.id DESC")->fetchAll();
  73. $typen = $pdo->query("SELECT * FROM game_typen ORDER BY bezeichnung ASC")->fetchAll();
  74. ?>
  75. <!DOCTYPE html>
  76. <html lang="de">
  77. <head>
  78. <meta charset="UTF-8">
  79. <title>EXIT Admin - Stammdaten</title>
  80. <style>
  81. body { font-family: 'Segoe UI', sans-serif; background: #121212; color: #e0e0e0; padding: 20px; }
  82. .container { max-width: 1400px; margin: 0 auto; }
  83. .alert { padding: 15px; border-radius: 8px; margin-bottom: 20px; font-weight: bold; text-align: center; }
  84. .alert-success { background: #27ae60; color: white; }
  85. .alert-error { background: #e74c3c; color: white; }
  86. .admin-card { background: #1e1e1e; padding: 20px; border-radius: 12px; box-shadow: 0 4px 15px rgba(0,0,0,0.3); margin-bottom: 30px; border: 1px solid #333; }
  87. table { width: 100%; border-collapse: collapse; margin-top: 20px; table-layout: fixed; }
  88. th, td { padding: 10px; border-bottom: 1px solid #333; text-align: left; overflow: hidden; }
  89. th { color: #e67e22; font-size: 0.9em; text-transform: uppercase; }
  90. input, select { padding: 8px; border: 1px solid #444; border-radius: 6px; width: 100%; box-sizing: border-box; background: #2a2a2a; color: white; font-size: 0.95em; }
  91. /* Spaltenbreiten Tabelle */
  92. .col-img { width: 60px; }
  93. .col-titel { width: auto; } /* Nimmt den Rest */
  94. .col-ean { width: 140px; }
  95. .col-typ { width: 160px; }
  96. .col-lvl { width: 150px; }
  97. .col-url { width: 200px; }
  98. .col-akt { width: 100px; text-align: center; }
  99. .lvl-unknown { background: #d35400 !important; color: white; }
  100. .btn { padding: 10px 15px; border: none; border-radius: 6px; cursor: pointer; font-weight: bold; color: white; text-decoration: none; display: inline-block; }
  101. .btn-add { background: #27ae60; width: 100%; margin-top: 10px; }
  102. .btn-save { background: #2980b9; }
  103. .btn-del { background: #c0392b; }
  104. .btn-nav { background: #e67e22; }
  105. .img-preview { width: 40px; height: 40px; object-fit: cover; border-radius: 4px; background: #333; display: block; margin: 0 auto; }
  106. </style>
  107. </head>
  108. <body>
  109. <div class="container">
  110. <div style="display:flex; justify-content: space-between; align-items: center; margin-bottom: 20px;">
  111. <h1>🛠 Stammdaten Verwaltung</h1>
  112. <div>
  113. <a href="index.php" class="btn btn-nav">Dashboard</a>
  114. <a href="admin.php?logout=1" class="btn btn-del">Logout</a>
  115. </div>
  116. </div>
  117. <?php if ($msg): ?>
  118. <div class="alert alert-<?= $msg_type ?>" id="msg-box"><?= $msg ?></div>
  119. <?php endif; ?>
  120. <div class="admin-card">
  121. <h3>🆕 Neues Spiel hinzufügen</h3>
  122. <form method="POST">
  123. <div style="display: grid; grid-template-columns: 3fr 1fr 1.2fr 1.2fr 2fr; gap: 10px;">
  124. <input type="text" name="new_titel" placeholder="Spieltitel" required>
  125. <input type="text" name="new_ean" placeholder="EAN" required>
  126. <select name="new_typ_id">
  127. <option value="0">-- Typ: Unbekannt --</option>
  128. <?php foreach($typen as $t): ?>
  129. <option value="<?= $t['id'] ?>"><?= htmlspecialchars($t['bezeichnung']) ?></option>
  130. <?php endforeach; ?>
  131. </select>
  132. <select name="new_level">
  133. <option value="Unknown" selected>-- Level: Unbekannt --</option>
  134. <option value="Einsteiger">Einsteiger</option>
  135. <option value="Fortgeschrittene">Fortgeschrittene</option>
  136. <option value="Profi">Profi</option>
  137. </select>
  138. <input type="text" name="new_bild_url" placeholder="Bild-URL">
  139. </div>
  140. <button type="submit" name="add_new_game" class="btn btn-add">Spiel in Datenbank speichern</button>
  141. </form>
  142. </div>
  143. <div class="admin-card">
  144. <h3>📋 Aktueller Bestand</h3>
  145. <table>
  146. <thead>
  147. <tr>
  148. <th class="col-img">Bild</th>
  149. <th class="col-titel">Titel</th>
  150. <th class="col-ean">EAN</th>
  151. <th class="col-typ">Typ</th>
  152. <th class="col-lvl">Level</th>
  153. <th class="col-url">Bild-URL</th>
  154. <th class="col-akt">Aktion</th>
  155. </tr>
  156. </thead>
  157. <tbody>
  158. <?php foreach ($spiele as $sp):
  159. $is_unknown = ($sp['level'] == 'Unknown' || empty($sp['level']));
  160. ?>
  161. <tr>
  162. <form method="POST">
  163. <input type="hidden" name="spiel_id" value="<?= $sp['id'] ?>">
  164. <td class="col-img"><img src="<?= htmlspecialchars($sp['bild_url']) ?>" class="img-preview" alt="Cover"></td>
  165. <td class="col-titel"><input type="text" name="titel" value="<?= htmlspecialchars($sp['titel']) ?>"></td>
  166. <td class="col-ean"><input type="text" name="ean" value="<?= htmlspecialchars($sp['ean']) ?>"></td>
  167. <td class="col-typ">
  168. <select name="typ_id">
  169. <option value="0">-- Unbekannt --</option>
  170. <?php foreach($typen as $t): ?>
  171. <option value="<?= $t['id'] ?>" <?= ($sp['typ_id']==$t['id'])?'selected':'' ?>><?= htmlspecialchars($t['bezeichnung']) ?></option>
  172. <?php endforeach; ?>
  173. </select>
  174. </td>
  175. <td class="col-lvl">
  176. <select name="level" class="<?= $is_unknown ? 'lvl-unknown' : '' ?>" onchange="this.className=this.value=='Unknown'?'lvl-unknown':''">
  177. <option value="Unknown" <?= $is_unknown ? 'selected' : '' ?>>Unbekannt</option>
  178. <option value="Einsteiger" <?= $sp['level']=='Einsteiger'?'selected':'' ?>>Einsteiger</option>
  179. <option value="Fortgeschrittene" <?= $sp['level']=='Fortgeschrittene'?'selected':'' ?>>Fortgeschrittene</option>
  180. <option value="Profi" <?= $sp['level']=='Profi'?'selected':'' ?>>Profi</option>
  181. </select>
  182. </td>
  183. <td class="col-url"><input type="text" name="bild_url" value="<?= htmlspecialchars($sp['bild_url']) ?>"></td>
  184. <td class="col-akt">
  185. <button type="submit" name="update_game" class="btn btn-save" title="Speichern">💾</button>
  186. <button type="submit" name="delete_game" class="btn btn-del" onclick="return confirm('Wirklich löschen?')" title="Löschen">🗑</button>
  187. </td>
  188. </form>
  189. </tr>
  190. <?php endforeach; ?>
  191. </tbody>
  192. </table>
  193. </div>
  194. </div>
  195. <script>
  196. setTimeout(() => {
  197. const msg = document.getElementById('msg-box');
  198. if(msg) msg.style.display = 'none';
  199. }, 3000);
  200. </script>
  201. </body>
  202. </html>