diff --git a/admin/committees.php b/admin/committees.php index 06b5d60..b497759 100644 --- a/admin/committees.php +++ b/admin/committees.php @@ -166,6 +166,10 @@ if($_POST['add_member']) if($_POST['save']) { + //FIXME: deal with what the user can actually do based on their own permissions + if($_POST['access_admin']=="Y") $a_admin='Y'; else $a_admin='N'; + if($_POST['access_config']=="Y") $a_config='Y'; else $a_config='N'; + if($_POST['access_super']=="Y") $a_super='Y'; else $a_super='N'; mysql_query("UPDATE committees_members SET ". "name='".$_POST['name']."', ". "organization='".$_POST['organization']."', ". @@ -175,6 +179,9 @@ if($_POST['save']) "phonework='".$_POST['phonework']."', ". "phonecell='".$_POST['phonecell']."', ". "fax='".$_POST['fax']."', ". + "access_admin='$a_admin', ". + "access_config='$a_config', ". + "access_super='$a_super', ". "displayemail='".$_POST['displayemail']."' ". " WHERE id='".$_POST['save']."'"); @@ -224,31 +231,30 @@ if($_GET['edit'] || $edit) $e=$edit; $q=mysql_query("SELECT * FROM committees_members WHERE id='$e'"); $r=mysql_fetch_object($q); - echo "