diff --git a/htdocs/user/fiche.php b/htdocs/user/fiche.php index 32cb99c766d..cd5712a802e 100644 --- a/htdocs/user/fiche.php +++ b/htdocs/user/fiche.php @@ -24,16 +24,16 @@ require("./pre.inc.php"); $form = new Form($db); -if ($subaction == 'addrights' && $user->admin) +if ($_GET["subaction"] == 'addrights' && $user->admin) { - $edituser = new User($db,$id); - $edituser->addrights($rights); + $edituser = new User($db,$_GET["id"]); + $edituser->addrights($_GET["rights"]); } -if ($subaction == 'delrights' && $user->admin) +if ($_GET["subaction"] == 'delrights' && $user->admin) { - $edituser = new User($db,$id); - $edituser->delrights($rights); + $edituser = new User($db,$_GET["id"]); + $edituser->delrights($_GET["rights"]); } if ($HTTP_POST_VARS["action"] == 'confirm_delete' && $HTTP_POST_VARS["confirm"] == "yes") @@ -158,16 +158,16 @@ if ($action == 'create') /* ************************************************************************** */ else { - if ($id) + if ($_GET["id"]) { - $fuser = new User($db, $id); + $fuser = new User($db, $_GET["id"]); $fuser->fetch(); print_fiche_titre("Fiche utilisateur",$message); if ($request == 'delete') { - print '