thinkPHP后台生成专题非法操作

解决方案 »

  1.   

    tp的RBAC问题你把你代码部分也弄出来瞅瞅
      

  2.   

    <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
    <html xmlns="http://www.w3.org/1999/xhtml">
    <head>
    <title>后台用户管理</title>
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
    <link rel='stylesheet' type='text/css' href='__PUBLIC__/css/admin-style.css' />
    <script language="JavaScript" type="text/javascript" charset="utf-8" src="__PUBLIC__/jquery/jquery-1.7.2.min.js"></script>
    <script language="JavaScript" type="text/javascript" charset="utf-8" src="__PUBLIC__/js/admin.js"></script>
    <script language="javascript">
    var resizediv = function() { 
    $leftwidth = $(window).width()/2-120;
    $('.jqmWindow').css({ left: $leftwidth});
    }
    $(document).ready(function(){
    $feifeicms.show.table();
    $(window).resize(resizediv);
    resizediv();
    });
    function createhtml(id){
    var offset = $("#html_"+id).offset();
    var left = (offset.left/2)+50;
    var top = offset.top+15;
    var html = $.ajax({
    url: '?s=Admin-Create-specialid-id-'+id,
    async: false
    }).responseText;
    $("#htmltags").html(html);
    $("#htmltags").css({left:left,top:top,display:""});
    window.setTimeout(function(){
    $("#htmltags").hide();
    },1000);
    }
    </script>
    </head>
    <body class="body">
    <!--生成静态预览框-->
    <div id="htmltags" style="position:absolute;display:none;" class="htmltags"></div>
    <!--背景灰色变暗-->
    <div id="showbg" style="position:absolute;left:0px;top:0px;filter:Alpha(Opacity=0);opacity:0.0;background-color:#fff;z-index:8;"></div>
    <form action="?s=Admin-Special-Show" method="post" name="myform" id="myform">
    <table border="0" cellpadding="0" cellspacing="0" class="table">
      <thead>
        <tr class="ct">
          <th class="l" width="40">ID <eq name="orders" value="special_id desc"><a href="?s=Admin-Special-Show-type-id-order-asc"><img src="__PUBLIC__/images/admin/up.gif" border="0" alt="点击按ID升序排列"></a><else /><a href="?s=Admin-Special-Show-type-id-order-desc"><img src="__PUBLIC__/images/admin/down.gif" border="0" alt="点击按ID降序排列"></a></eq></th>
          <th class="l" >专题名称</th>
          <th class="l" width="60">人气<eq name="orders" value="special_hits desc"><a href="?s=Admin-Special-Show-type-hits-order-asc"><img src="__PUBLIC__/images/admin/up.gif" border="0" alt="点击按人气升序排列"></a><else /><a href="?s=Admin-Special-Show-type-hits-order-desc"><img src="__PUBLIC__/images/admin/down.gif" border="0" alt="点击按人气降序排列"></a></eq></th>
          <th class="l" width="90">更新时间<eq name="orders" value="special_addtime desc"><a href="?s=Admin-Special-Show-type-addtime-order-asc"><img src="__PUBLIC__/images/admin/up.gif" border="0" alt="点击按时间升序排列"></a><else /><a href="?s=Admin-Special-Show-type-addtime-order-desc"><img src="__PUBLIC__/images/admin/down.gif" border="0" alt="点击按时间降序排列"></a></eq></th>
          <th class="l" width="80">专题权重</th>
          <th class="l" width="80">收录影视</th>
          <th class="l" width="80">收录资讯</th>
          <th class="r" width="100">相关操作</th>
        </tr>
      </thead>
      <volist name="list" id="ppvod">
      <tbody>
      <tr>
        <td class="l pd"><input name='ids[]' type='checkbox' value='{$ppvod.special_id}' class="noborder" checked>{$ppvod.special_id}</td>
        <td class="l pd"><if condition="C('url_html') gt 0"><a href="javascript:createhtml('{$ppvod.special_id}');" id="html_{$ppvod.special_id}"><font color="green">生成</font></a></if> <a href="{$ppvod.special_url}" target="_blank">{$ppvod.special_name}</a></td>
        <td class="l ct">{$ppvod.special_hits}</td>
        <td class="l ct">{$ppvod.special_addtime|date='Y-m-d',###}</td>
        <td class="l ct"><volist name="ppvod['special_starsarr']" id="ajaxstar"><img src="__PUBLIC__/images/admin/star{$ajaxstar}.gif" onClick="setstars('Special',{$ppvod.special_id},{$i});" id="star_{$ppvod.special_id}_{$i}" class="navpoint"></volist></td>
        <td class="l ct"><a href="javascript:void(0)" onclick="divwindow('?s=Admin-Vod-Show-tid-{$ppvod.special_id}','添加专题到专题');">影视({:count($array_count['1-'.$ppvod['special_id']])})部</a></td>
        <td class="l ct"><a href="javascript:void(0)" onclick="divwindow('?s=Admin-News-Show-tid-{$ppvod.special_id}','添加专题到专题');">资讯({:count($array_count['2-'.$ppvod['special_id']])})篇</a></td>
        <td class="r ct"><a href="?s=Admin-Special-Add-id-{$ppvod.special_id}" title="点击修改专题">编辑</a> <a href="?s=Admin-Special-Del-id-{$ppvod.special_id}" onClick="return confirm('确定删除该专题吗?')" title="点击删除专题">删除</a>  <eq name="ppvod.special_status" value="1"><a href="?s=Admin-Special-Status-id-{$ppvod.special_id}-sid-0" title="点击隐藏专题">隐藏</a><else /><a href="?s=Admin-Special-Status-id-{$ppvod.special_id}-sid-1" title="点击显示专题"><font color="red">显示</font></a></eq></td>
      </tr>
      </tbody>
      </volist>
        <tr>
          <td colspan="10" class="r pages">{$pages}</td>
        </tr>  
      <tfoot>
        <tr>
          <td colspan="10" class="r"><input type="button" value="全选" class="submit" onClick="checkall('all');"> <input name="" type="button" value="反选" class="submit" onClick="checkall();"> <eq name="Think.config.url_html" value="1"><input type="button" value="生成静态" name="createhtml" id="createhtml" class="submit" onClick="post('?s=Admin-Special-Create');"/></eq> <input type="button" value="批量删除" class="submit" onClick="if(confirm('删除后将无法还原,确定要删除吗?')){post('?s=Admin-Special-Delall');}else{return false;}"></td>
        </tr>  
      </tfoot>
    </table>
    </form>
    <include file="./Public/system/plus_jqmodal.html" />
    <style>
    #dia_title{height:25px;line-height:25px}
    .jqmWindow{height:500px;width:800px;top:10px;left:310px;overflow:hidden}
    </style>
    <include file="./Public/system/footer.html" />
    </body>
    </html>上面是生成专题页面的代码,大神瞅瞅啊,谢谢啊。
      

  3.   

    我的服务器是windows啊,目录都有权限啊。