2026-02-24 21:02:41 +03:00
|
|
|
<?php
|
|
|
|
|
|
|
|
|
|
/**
|
2026-03-07 21:53:45 +03:00
|
|
|
* BaseAdminController — базовый контроллер для admin-страниц.
|
2026-02-24 21:02:41 +03:00
|
|
|
*
|
|
|
|
|
* Инкапсулирует общий render-flow:
|
|
|
|
|
* 1. renderUnifiedLayoutHeader('admin')
|
|
|
|
|
* 2. require Views/admin/{view}.php — HTML-контент
|
|
|
|
|
* 3. renderUnifiedLayoutFooter('admin')
|
|
|
|
|
* 4. require Views/admin/{view}.scripts.php — page-specific JS
|
|
|
|
|
*
|
|
|
|
|
* Контроллер-наследник:
|
|
|
|
|
* - Вызывает requirePermission() для проверки доступа
|
|
|
|
|
* - Устанавливает setTitle() для $_TITLE
|
|
|
|
|
* - Вызывает render('view_name', $data) для отрисовки
|
|
|
|
|
*
|
2026-02-28 18:47:56 +03:00
|
|
|
* @see public/Views/layouts/admin.php — renderUnifiedLayoutHeader()
|
|
|
|
|
* @see public/Views/layouts/footer.php — renderUnifiedLayoutFooter()
|
2026-02-24 21:02:41 +03:00
|
|
|
* @see core/Http/Router.php — callHandler() → new Controller()->method()
|
2026-04-05 22:38:36 +03:00
|
|
|
*
|
|
|
|
|
* @package XC_VM_Public_Controllers_Admin
|
|
|
|
|
* @author Divarion_D <https://github.com/Divarion-D>
|
|
|
|
|
* @copyright 2025-2026 Vateron Media
|
|
|
|
|
* @link https://github.com/Vateron-Media/XC_VM
|
|
|
|
|
* @license AGPL-3.0 https://www.gnu.org/licenses/agpl-3.0.html
|
2026-02-24 21:02:41 +03:00
|
|
|
*/
|
2026-04-05 22:38:36 +03:00
|
|
|
|
2026-02-24 21:02:41 +03:00
|
|
|
class BaseAdminController
|
|
|
|
|
{
|
|
|
|
|
/** @var string Scope: 'admin' или 'reseller' */
|
|
|
|
|
protected $scope = 'admin';
|
|
|
|
|
|
|
|
|
|
/** @var string Заголовок страницы */
|
|
|
|
|
protected $title = '';
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* Установить заголовок страницы ($_TITLE для legacy header).
|
|
|
|
|
*/
|
|
|
|
|
protected function setTitle($title)
|
|
|
|
|
{
|
|
|
|
|
$this->title = $title;
|
|
|
|
|
$GLOBALS['_TITLE'] = $title;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/**
|
2026-04-09 21:24:48 +03:00
|
|
|
* Проверка общих прав доступа.
|
|
|
|
|
* При отказе — redirect на главную + exit.
|
2026-02-24 21:02:41 +03:00
|
|
|
*/
|
|
|
|
|
protected function requirePermission()
|
|
|
|
|
{
|
2026-04-09 21:24:48 +03:00
|
|
|
if (!PageAuthorization::checkPermissions()) {
|
|
|
|
|
AdminHelpers::goHome();
|
2026-02-24 21:02:41 +03:00
|
|
|
exit;
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* Проверка расширенных прав (hasPermissions).
|
2026-04-09 21:24:48 +03:00
|
|
|
* При отказе — redirect на главную + exit.
|
2026-02-24 21:02:41 +03:00
|
|
|
*
|
|
|
|
|
* @param string $type Тип прав ('adv' и т.д.)
|
|
|
|
|
* @param string $key Ключ прав ('edit_user' и т.д.)
|
|
|
|
|
*/
|
|
|
|
|
protected function requireAdvPermission($type, $key)
|
|
|
|
|
{
|
2026-04-09 21:24:48 +03:00
|
|
|
if (!Authorization::check($type, $key)) {
|
|
|
|
|
AdminHelpers::goHome();
|
2026-02-24 21:02:41 +03:00
|
|
|
exit;
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* Render: header → view → footer → scripts.
|
|
|
|
|
*
|
|
|
|
|
* @param string $view Имя view-файла (без .php), напр. 'ips'
|
|
|
|
|
* @param array $data Данные для view (extract'd в scope)
|
|
|
|
|
*/
|
|
|
|
|
protected function render($view, array $data = [])
|
|
|
|
|
{
|
|
|
|
|
// Layout functions
|
2026-02-28 18:47:56 +03:00
|
|
|
require_once MAIN_HOME . 'public/Views/layouts/admin.php';
|
|
|
|
|
require_once MAIN_HOME . 'public/Views/layouts/footer.php';
|
2026-02-24 21:02:41 +03:00
|
|
|
|
2026-02-27 22:32:39 +03:00
|
|
|
// Глобальные переменные, нужные view-шаблонам и legacy-файлам.
|
|
|
|
|
// Полный набор, включая переменные из bootstrap, functions.php
|
|
|
|
|
// и admin_constants.php, чтобы legacy body code мог их использовать.
|
2026-02-24 21:02:41 +03:00
|
|
|
$viewGlobals = [
|
2026-02-27 22:32:39 +03:00
|
|
|
// Core rendering
|
2026-02-24 21:02:41 +03:00
|
|
|
'language', 'db', 'rSettings', 'rMobile', 'rUserInfo',
|
2026-03-08 22:13:35 +03:00
|
|
|
'rPermissions', '_TITLE', '_STATUS', '_PAGE', 'rRequest',
|
2026-02-27 22:32:39 +03:00
|
|
|
// Theme/UI
|
|
|
|
|
'rThemes', 'rHues',
|
|
|
|
|
// Servers
|
|
|
|
|
'rServers', 'allServers', 'rProxyServers',
|
|
|
|
|
'rServerError', 'allServersHealthy', 'updateRequired',
|
|
|
|
|
// Locale/Geo
|
|
|
|
|
'allowedLangs', 'rTMDBLanguages', 'rGeoCountries',
|
|
|
|
|
'rCountryCodes', 'rCountries',
|
|
|
|
|
// Devices & constants
|
|
|
|
|
'rMAGs', 'rTimezones',
|
|
|
|
|
// Status arrays (admin_constants.php)
|
|
|
|
|
'rStatusArray', 'rSearchStatusArray', 'rVODStatusArray',
|
|
|
|
|
'rWatchStatusArray', 'rFailureStatusArray', 'rStreamLogsArray',
|
|
|
|
|
'rResellerActions', 'rClientFilters',
|
|
|
|
|
// Permissions
|
|
|
|
|
'rPermissionKeys', 'rAdvPermissions',
|
|
|
|
|
// Misc from bootstrap
|
|
|
|
|
'rDetect', 'rTimeout', 'rProtocol',
|
2026-03-08 22:13:35 +03:00
|
|
|
// Reseller-specific
|
|
|
|
|
'rGenTrials',
|
2026-02-24 21:02:41 +03:00
|
|
|
];
|
|
|
|
|
foreach ($viewGlobals as $_g) {
|
|
|
|
|
if (array_key_exists($_g, $GLOBALS) && !array_key_exists($_g, $data)) {
|
|
|
|
|
$data[$_g] = $GLOBALS[$_g];
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
unset($_g);
|
|
|
|
|
|
|
|
|
|
extract($data);
|
|
|
|
|
|
2026-02-28 18:47:56 +03:00
|
|
|
$__viewsDir = MAIN_HOME . 'public/Views/' . $this->scope . '/';
|
2026-02-24 21:02:41 +03:00
|
|
|
|
|
|
|
|
// 1. Header
|
|
|
|
|
renderUnifiedLayoutHeader($this->scope);
|
|
|
|
|
|
2026-03-08 22:13:35 +03:00
|
|
|
// Header may define new globals (e.g. reseller header sets rGenTrials)
|
|
|
|
|
foreach ($viewGlobals as $_g) {
|
|
|
|
|
if (!isset($$_g) && array_key_exists($_g, $GLOBALS)) {
|
|
|
|
|
$$_g = $GLOBALS[$_g];
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
unset($_g);
|
|
|
|
|
|
2026-02-24 21:02:41 +03:00
|
|
|
// 2. View content
|
2026-02-27 22:32:39 +03:00
|
|
|
$__viewFile = $__viewsDir . $view . '.php';
|
|
|
|
|
$__scriptsFile = $__viewsDir . $view . '.scripts.php';
|
|
|
|
|
$__hasScriptsFile = file_exists($__scriptsFile);
|
2026-02-24 21:02:41 +03:00
|
|
|
|
2026-02-27 22:32:39 +03:00
|
|
|
if (file_exists($__viewFile)) {
|
2026-03-11 19:46:02 +03:00
|
|
|
$__viewMode = true;
|
2026-02-27 22:32:39 +03:00
|
|
|
require $__viewFile;
|
2026-02-24 21:02:41 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// Split mode: separate .scripts.php exists → footer + scripts handled here.
|
2026-03-08 22:13:35 +03:00
|
|
|
// Clean mode: no .scripts.php + no $__viewMode → controller renders footer.
|
|
|
|
|
// Unified (proxy) mode: no .scripts.php + $__viewMode set → proxy view handles footer itself.
|
2026-02-27 22:32:39 +03:00
|
|
|
if ($__hasScriptsFile) {
|
2026-02-24 21:02:41 +03:00
|
|
|
renderUnifiedLayoutFooter($this->scope);
|
2026-02-27 22:32:39 +03:00
|
|
|
require $__scriptsFile;
|
2026-03-08 22:13:35 +03:00
|
|
|
} elseif (!isset($__viewMode)) {
|
|
|
|
|
renderUnifiedLayoutFooter($this->scope);
|
2026-02-24 21:02:41 +03:00
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* JSON-ответ.
|
|
|
|
|
*/
|
|
|
|
|
protected function json(array $data, $code = 200)
|
|
|
|
|
{
|
|
|
|
|
http_response_code($code);
|
|
|
|
|
header('Content-Type: application/json');
|
|
|
|
|
echo json_encode($data);
|
|
|
|
|
exit;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* Редирект.
|
|
|
|
|
*/
|
|
|
|
|
protected function redirect($url)
|
|
|
|
|
{
|
|
|
|
|
header('Location: ' . $url);
|
|
|
|
|
exit;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/**
|
2026-03-07 21:53:45 +03:00
|
|
|
* Получить параметр запроса (GET/POST/RequestManager::getAll()).
|
2026-02-24 21:02:41 +03:00
|
|
|
*
|
|
|
|
|
* @param string $key
|
|
|
|
|
* @param mixed $default
|
|
|
|
|
* @return mixed
|
|
|
|
|
*/
|
|
|
|
|
protected function input($key, $default = null)
|
|
|
|
|
{
|
2026-03-07 21:53:45 +03:00
|
|
|
// Приоритет: RequestManager → $_REQUEST
|
|
|
|
|
if (isset(RequestManager::getAll()[$key])) {
|
|
|
|
|
return RequestManager::getAll()[$key];
|
2026-02-24 21:02:41 +03:00
|
|
|
}
|
|
|
|
|
return isset($_REQUEST[$key]) ? $_REQUEST[$key] : $default;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* Получить текущий статус из запроса (?status=...).
|
|
|
|
|
*
|
|
|
|
|
* @return mixed|null
|
|
|
|
|
*/
|
|
|
|
|
protected function getStatus()
|
|
|
|
|
{
|
|
|
|
|
return isset($GLOBALS['_STATUS']) ? $GLOBALS['_STATUS'] : $this->input('status');
|
|
|
|
|
}
|
|
|
|
|
}
|