admin.php 9.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211
  1. <?php
  2. session_start();
  3. require_once 'config.php';
  4. require_once 'db_config.php';
  5. // --- 1. LOGIN / LOGOUT SCHUTZ ---
  6. if (isset($_GET['logout'])) { session_destroy(); header("Location: admin.php"); exit; }
  7. $show_login = true;
  8. if (isset($_SESSION['admin_auth']) && $_SESSION['admin_auth'] === true) { $show_login = false; }
  9. if (isset($_POST['login_auth'])) {
  10. if ($_POST['pw'] === ADMIN_PASSWORD) {
  11. $_SESSION['admin_auth'] = true;
  12. $show_login = false;
  13. } else { $login_error = "Falsches Passwort!"; }
  14. }
  15. if ($show_login):
  16. ?>
  17. <!DOCTYPE html>
  18. <html lang="de">
  19. <head>
  20. <meta charset="UTF-8">
  21. <title>Admin Login</title>
  22. <style>
  23. body { font-family: 'Segoe UI', sans-serif; background: #121212; color: white; display: flex; justify-content: center; align-items: center; height: 100vh; margin: 0; }
  24. .login-box { background: #1e1e1e; padding: 40px; border-radius: 12px; border: 1px solid #e67e22; text-align: center; width: 300px; }
  25. input { width: 100%; padding: 12px; margin: 15px 0; border-radius: 5px; border: 1px solid #444; background: #2a2a2a; color: white; box-sizing: border-box; }
  26. button { background: #e67e22; color: white; border: none; padding: 12px; border-radius: 5px; cursor: pointer; width: 100%; font-weight: bold; }
  27. .error { color: #e74c3c; font-size: 0.9em; }
  28. </style>
  29. </head>
  30. <body>
  31. <div class="login-box">
  32. <h2>🔐 Admin Login</h2>
  33. <?php if(isset($login_error)) echo "<div class='error'>$login_error</div>"; ?>
  34. <form method="POST">
  35. <input type="password" name="pw" placeholder="Passwort" autofocus required>
  36. <button type="submit" name="login_auth">Einloggen</button>
  37. </form>
  38. </div>
  39. </body>
  40. </html>
  41. <?php exit; endif; ?>
  42. <?php
  43. // --- 2. DATENBANK LOGIK ---
  44. $msg = "";
  45. $msg_type = "success";
  46. // Spiel hinzufügen
  47. if (isset($_POST['add_new_game'])) {
  48. $ean = trim($_POST['new_ean']);
  49. $titel = trim($_POST['new_titel']);
  50. $level = (empty($_POST['new_level']) || $_POST['new_level'] == 'Unknown') ? 'Unknown' : $_POST['new_level'];
  51. $typ_id = ($_POST['new_typ_id'] == '0') ? null : (int)$_POST['new_typ_id'];
  52. try {
  53. $stmt = $pdo->prepare("INSERT INTO spiele (titel, typ_id, ean, level, bild_url) VALUES (?, ?, ?, ?, ?)");
  54. $stmt->execute([$titel, $typ_id, $ean, $level, "https://via.placeholder.com/60?text=Scan"]);
  55. $msg = "✅ Spiel erfolgreich angelegt!";
  56. } catch (PDOException $e) {
  57. if ($e->getCode() == 23000) {
  58. $msg = "❌ Fehler: Die EAN $ean existiert bereits!";
  59. $msg_type = "error";
  60. } else { $msg = "Fehler: " . $e->getMessage(); }
  61. }
  62. }
  63. // Spiel aktualisieren
  64. if (isset($_POST['update_game'])) {
  65. $stmt = $pdo->prepare("UPDATE spiele SET titel = ?, typ_id = ?, ean = ?, level = ? WHERE id = ?");
  66. $stmt->execute([$_POST['titel'], ($_POST['typ_id'] == '0' ? null : (int)$_POST['typ_id']), $_POST['ean'], $_POST['level'], (int)$_POST['spiel_id']]);
  67. $msg = "💾 Änderungen gespeichert!";
  68. }
  69. // Löschen
  70. if (isset($_POST['delete_game'])) {
  71. $pdo->prepare("DELETE FROM spiele WHERE id = ?")->execute([(int)$_POST['spiel_id']]);
  72. $msg = "🗑 Spiel gelöscht!";
  73. }
  74. // Daten abrufen
  75. $spiele = $pdo->query("SELECT s.*, t.bezeichnung as typ_name FROM spiele s LEFT JOIN game_typen t ON s.typ_id = t.id ORDER BY s.id DESC")->fetchAll();
  76. $typen = $pdo->query("SELECT * FROM game_typen ORDER BY bezeichnung ASC")->fetchAll();
  77. ?>
  78. <!DOCTYPE html>
  79. <html lang="de">
  80. <head>
  81. <meta charset="UTF-8">
  82. <title>EXIT Admin - Stammdaten</title>
  83. <style>
  84. body { font-family: 'Segoe UI', sans-serif; background: #f4f7f6; padding: 20px; }
  85. .container { max-width: 1200px; margin: 0 auto; }
  86. .alert { padding: 15px; border-radius: 8px; margin-bottom: 20px; font-weight: bold; text-align: center; }
  87. .alert-success { background: #27ae60; color: white; }
  88. .alert-error { background: #e74c3c; color: white; }
  89. .admin-card { background: white; padding: 20px; border-radius: 12px; box-shadow: 0 4px 15px rgba(0,0,0,0.05); margin-bottom: 30px; }
  90. table { width: 100%; border-collapse: collapse; margin-top: 20px; }
  91. th, td { padding: 12px; border-bottom: 1px solid #eee; text-align: left; }
  92. input, select { padding: 10px; border: 1px solid #ddd; border-radius: 6px; width: 100%; box-sizing: border-box; }
  93. /* Unbekannt Styling */
  94. .lvl-unknown { background: #f39c12 !important; color: white; }
  95. .btn { padding: 10px 20px; border: none; border-radius: 6px; cursor: pointer; font-weight: bold; color: white; text-decoration: none; display: inline-block; }
  96. .btn-add { background: #27ae60; width: 100%; margin-top: 10px; }
  97. .btn-save { background: #2980b9; }
  98. .btn-del { background: #e74c3c; }
  99. .btn-nav { background: #e67e22; }
  100. </style>
  101. </head>
  102. <body>
  103. <div class="container">
  104. <div style="display:flex; justify-content: space-between; align-items: center;">
  105. <h1>🛠 Stammdaten Verwaltung</h1>
  106. <div>
  107. <a href="index.php" class="btn btn-nav">Dashboard</a>
  108. <a href="admin.php?logout=1" class="btn btn-del">Logout</a>
  109. </div>
  110. </div>
  111. <?php if ($msg): ?>
  112. <div class="alert alert-<?= $msg_type ?>" id="msg-box"><?= $msg ?></div>
  113. <?php endif; ?>
  114. <div class="admin-card">
  115. <h3>🆕 Neues Spiel hinzufügen</h3>
  116. <form method="POST">
  117. <div style="display: grid; grid-template-columns: 2fr 1.5fr 1.5fr 1.5fr; gap: 15px;">
  118. <input type="text" name="new_titel" placeholder="Spieltitel" required>
  119. <input type="text" name="new_ean" placeholder="EAN Scannen" required>
  120. <select name="new_typ_id">
  121. <option value="0">-- Typ: Unbekannt --</option>
  122. <?php foreach($typen as $t): ?>
  123. <option value="<?= $t['id'] ?>"><?= htmlspecialchars($t['bezeichnung']) ?></option>
  124. <?php endforeach; ?>
  125. </select>
  126. <select name="new_level">
  127. <option value="Unknown" selected>-- Level: Unbekannt --</option>
  128. <option value="Einsteiger">Einsteiger</option>
  129. <option value="Fortgeschrittene">Fortgeschrittene</option>
  130. <option value="Profi">Profi</option>
  131. </select>
  132. </div>
  133. <button type="submit" name="add_new_game" class="btn btn-add">Spiel in Datenbank speichern</button>
  134. </form>
  135. </div>
  136. <div class="admin-card">
  137. <h3>📋 Aktueller Bestand</h3>
  138. <table>
  139. <thead>
  140. <tr>
  141. <th>Titel</th>
  142. <th>EAN</th>
  143. <th>Typ</th>
  144. <th>Level</th>
  145. <th>Aktion</th>
  146. </tr>
  147. </thead>
  148. <tbody>
  149. <?php foreach ($spiele as $sp):
  150. $is_unknown = ($sp['level'] == 'Unknown' || empty($sp['level']));
  151. ?>
  152. <tr>
  153. <form method="POST">
  154. <input type="hidden" name="spiel_id" value="<?= $sp['id'] ?>">
  155. <td><input type="text" name="titel" value="<?= htmlspecialchars($sp['titel']) ?>"></td>
  156. <td><input type="text" name="ean" value="<?= htmlspecialchars($sp['ean']) ?>"></td>
  157. <td>
  158. <select name="typ_id">
  159. <option value="0">-- Unbekannt --</option>
  160. <?php foreach($typen as $t): ?>
  161. <option value="<?= $t['id'] ?>" <?= ($sp['typ_id']==$t['id'])?'selected':'' ?>><?= htmlspecialchars($t['bezeichnung']) ?></option>
  162. <?php endforeach; ?>
  163. </select>
  164. </td>
  165. <td>
  166. <select name="level" class="<?= $is_unknown ? 'lvl-unknown' : '' ?>" onchange="this.className=this.value=='Unknown'?'lvl-unknown':''">
  167. <option value="Unknown" <?= $is_unknown ? 'selected' : '' ?>>Unbekannt</option>
  168. <option value="Einsteiger" <?= $sp['level']=='Einsteiger'?'selected':'' ?>>Einsteiger</option>
  169. <option value="Fortgeschrittene" <?= $sp['level']=='Fortgeschrittene'?'selected':'' ?>>Fortgeschrittene</option>
  170. <option value="Profi" <?= $sp['level']=='Profi'?'selected':'' ?>>Profi</option>
  171. </select>
  172. </td>
  173. <td style="white-space:nowrap;">
  174. <button type="submit" name="update_game" class="btn btn-save">💾</button>
  175. <button type="submit" name="delete_game" class="btn btn-del" onclick="return confirm('Wirklich löschen?')">🗑</button>
  176. </td>
  177. </form>
  178. </tr>
  179. <?php endforeach; ?>
  180. </tbody>
  181. </table>
  182. </div>
  183. </div>
  184. <script>
  185. // Nachricht nach 3 Sek ausblenden
  186. setTimeout(() => {
  187. const msg = document.getElementById('msg-box');
  188. if(msg) msg.style.display = 'none';
  189. }, 3000);
  190. </script>
  191. </body>
  192. </html>