Developer Documentation

See Release Notes

  • Bug fixes for general core bugs in 3.10.x will end 8 November 2021 (12 months).
  • Bug fixes for security issues in 3.10.x will end 9 May 2022 (18 months).
  • PHP version: minimum PHP 7.2.0 Note: minimum PHP version has increased since Moodle 3.8. PHP 7.3.x and 7.4.x are supported too.
// This file is part of Moodle -
// Moodle is free software: you can redistribute it and/or modify
// it under the terms of the GNU General Public License as published by
// the Free Software Foundation, either version 3 of the License, or
// (at your option) any later version.
// Moodle is distributed in the hope that it will be useful,
// but WITHOUT ANY WARRANTY; without even the implied warranty of
// GNU General Public License for more details.
// You should have received a copy of the GNU General Public License
// along with Moodle.  If not, see <>.

 * Select site administrators.
 * @package    core_role
 * @copyright  2010 Petr Skoda {@link}
 * @license GNU GPL v3 or later

require_once(__DIR__ . '/../../config.php');

< $confirmadd = optional_param('confirmadd', 0, PARAM_INT); < $confirmdel = optional_param('confirmdel', 0, PARAM_INT);
> $addusersaction = optional_param('add', false, PARAM_BOOL); > $addusers = optional_param('addusers', '', PARAM_SEQUENCE); > $removeusersaction = optional_param('remove', false, PARAM_BOOL); > $removeusers = optional_param('removeusers', '', PARAM_SEQUENCE);
$PAGE->set_url('/admin/roles/admins.php'); admin_externalpage_setup('admins'); if (!is_siteadmin()) { die; } $admisselector = new core_role_admins_existing_selector(); $potentialadmisselector = new core_role_admins_potential_selector();
< if (optional_param('add', false, PARAM_BOOL) and confirm_sesskey()) {
> if ($addusersaction) {
if ($userstoadd = $potentialadmisselector->get_selected_users()) {
< $user = reset($userstoadd); < $username = $potentialadmisselector->output_user($user);
> $usernames = array_map(static function(stdClass $user) use ($potentialadmisselector): string { > return $potentialadmisselector->output_user($user); > }, $userstoadd); > > $userids = implode(',', array_keys($usernames)); >
echo $OUTPUT->header();
< $yesurl = new moodle_url('/admin/roles/admins.php', array('confirmadd'=>$user->id, 'sesskey'=>sesskey())); < echo $OUTPUT->confirm(get_string('confirmaddadmin', 'core_role', $username), $yesurl, $PAGE->url);
> echo $OUTPUT->confirm(get_string('confirmaddadmins', 'core_role') . html_writer::alist($usernames), > new moodle_url('/admin/roles/admins.php', ['addusers' => $userids, 'sesskey' => sesskey()]), $PAGE->url);
echo $OUTPUT->footer(); die; }
< } else if (optional_param('remove', false, PARAM_BOOL) and confirm_sesskey()) {
> } else if ($removeusersaction) {
if ($userstoremove = $admisselector->get_selected_users()) {
< $user = reset($userstoremove); < if ($USER->id == $user->id) {
// Can not remove self.
< } else { < $username = $admisselector->output_user($user);
> $userstoremove = array_filter($userstoremove, static function(int $userid): bool { > global $USER; > return $userid != $USER->id; > }, ARRAY_FILTER_USE_KEY); > > if ($userstoremove) { > $usernames = array_map(static function(stdClass $user) use ($admisselector): string { > return $admisselector->output_user($user); > }, $userstoremove); > > $userids = implode(',', array_keys($usernames)); >
echo $OUTPUT->header();
< $yesurl = new moodle_url('/admin/roles/admins.php', array('confirmdel'=>$user->id, 'sesskey'=>sesskey())); < echo $OUTPUT->confirm(get_string('confirmdeladmin', 'core_role', $username), $yesurl, $PAGE->url);
> echo $OUTPUT->confirm(get_string('confirmremoveadmins', 'core_role') . html_writer::alist($usernames), > new moodle_url('/admin/roles/admins.php', ['removeusers' => $userids, 'sesskey' => sesskey()]), $PAGE->url);
echo $OUTPUT->footer(); die; } }
< } else if (optional_param('main', false, PARAM_BOOL) and confirm_sesskey()) {
> } else if (optional_param('main', false, PARAM_BOOL) && confirm_sesskey()) { > // Setting main administrator will choose the first selected user in the case of multiple selections.
if ($newmain = $admisselector->get_selected_users()) { $newmain = reset($newmain); $newmain = $newmain->id; $admins = array(); foreach (explode(',', $CFG->siteadmins) as $admin) { $admin = (int)$admin; if ($admin) { $admins[$admin] = $admin; } } if (isset($admins[$newmain])) { $logstringold = implode(', ', $admins); unset($admins[$newmain]); array_unshift($admins, $newmain); $logstringnew = implode(', ', $admins); set_config('siteadmins', implode(',', $admins)); add_to_config_log('siteadmins', $logstringold, $logstringnew, null); redirect($PAGE->url); } }
< } else if ($confirmadd and confirm_sesskey()) {
> } else if ($addusers && confirm_sesskey()) {
$admins = array(); foreach (explode(',', $CFG->siteadmins) as $admin) { $admin = (int)$admin; if ($admin) { $admins[$admin] = $admin; } } $logstringold = implode(', ', $admins);
< $admins[$confirmadd] = $confirmadd;
> foreach (explode(',', $addusers) as $userid) { > $admins[$userid] = $userid; > }
$logstringnew = implode(', ', $admins); set_config('siteadmins', implode(',', $admins)); add_to_config_log('siteadmins', $logstringold, $logstringnew, 'core'); redirect($PAGE->url);
< } else if ($confirmdel and confirm_sesskey() and $confirmdel != $USER->id) {
> } else if ($removeusers && confirm_sesskey()) {
$admins = array(); foreach (explode(',', $CFG->siteadmins) as $admin) { $admin = (int)$admin; if ($admin) { $admins[$admin] = $admin; } } $logstringold = implode(', ', $admins);
< unset($admins[$confirmdel]);
> // Can not remove self. > foreach (explode(',', $removeusers) as $userid) { > if ($userid != $USER->id) { > unset($admins[$userid]); > } > }
$logstringnew = implode(', ', $admins); set_config('siteadmins', implode(',', $admins)); add_to_config_log('siteadmins', $logstringold, $logstringnew, 'core'); redirect($PAGE->url); } // Print header. echo $OUTPUT->header(); ?> <div id="addadmisform"> <h3 class="main"><?php print_string('manageadmins', 'core_role'); ?></h3> <form id="assignform" method="post" action="<?php echo $PAGE->url ?>"> <div> <input type="hidden" name="sesskey" value="<?php p(sesskey()); ?>" /> <table class="generaltable generalbox groupmanagementtable boxaligncenter" summary=""> <tr> <td id='existingcell'> <p> <label for="removeselect"><?php print_string('existingadmins', 'core_role'); ?></label> </p> <?php $admisselector->display(); ?> </td> <td id="buttonscell"> <p class="arrow_button"> <input name="add" id="add" type="submit" value="<?php echo $OUTPUT->larrow().'&nbsp;'.get_string('add'); ?>" title="<?php print_string('add'); ?>" class="btn btn-secondary"/><br /> <input name="remove" id="remove" type="submit" value="<?php echo get_string('remove').'&nbsp;'.$OUTPUT->rarrow(); ?>" title="<?php print_string('remove'); ?>" class="btn btn-secondary"/><br /> <input name="main" id="main" type="submit" value="<?php echo get_string('mainadminset', 'core_role'); ?>" title="<?php print_string('mainadminset', 'core_role'); ?>" class="btn btn-secondary"/> </p> </td> <td id="potentialcell"> <p> <label for="addselect"><?php print_string('users'); ?></label> </p> <?php $potentialadmisselector->display(); ?> </td> </tr> </table> </div> </form> </div> <?php echo $OUTPUT->footer();