<?php
    require 'Mysql.php';

    $cookie = isset($_COOKIE[Settings::cookie_name]) ? $_COOKIE[Settings::cookie_name] : '';
    $mode = isset($_GET['mode']) ? $_GET['mode'] : 'active';
    $action = isset($_GET['action']) ? $_GET['action'] : '';
    $id = isset($_GET['id']) ? $_GET['id'] : '';
    
    if (strcmp($cookie, Settings::admin_pass) == 0) { // authenticated
        if ($mode == 'logout') {
            setcookie(Settings::cookie_name, '', time() - 3600);
            $page = "admin logout";
            include 'assets/header.php';
            echo '<meta http-equiv="refresh" content="5">';
            echo '<center>Successfully logged out.<br>';
            echo 'Please wait to be redirected.</center>';
        } else {
            if (strlen($action) > 0) {
                $mysql = new Mysql();
                $mysql->connect();
                $mysql->setDatabase(Settings::mysql_database);
                $id = $mysql->escape(urldecode($id));
                
                if ($action == 'markpaid') {
                    $mysql->executeQuery("UPDATE ".Settings::mysql_table." SET Payment_sent=1 WHERE Invoice='$id'");
                }
                if ($action == 'markunpaid') {
                    $mysql->executeQuery("UPDATE ".Settings::mysql_table." SET Payment_sent=0 WHERE Invoice='$id'");
                }
                if ($action == 'invalidate') {
                    $mysql->executeQuery("UPDATE ".Settings::mysql_table." SET Active=0 WHERE Invoice='$id'");
                }
                if ($action == 'validate') {
                    $mysql->executeQuery("UPDATE ".Settings::mysql_table." SET Active=1 WHERE Invoice='$id'");
                }
                
                
                
                $mysql->close();
            }
            
            $page = "admin";
            include 'assets/header.php';
            echo '<center>';
            
            if ($mode == 'all') {
                echo '<div class="page-header"><h1 id="tables">All transactions</h1></div>';
                
                $mysql = new Mysql();
                $mysql->connect();
                $mysql->setDatabase(Settings::mysql_database);
                
                $query = $mysql->executeQuery("SELECT transactions.*
													, currencies.currency AS currency
												 FROM transactions LEFT JOIN currencies ON transactions.currency_id = currencies.id");
                echo '<div class="bs-docs-section"><div class="row"><div class="col-lg-12"><table class="table table-striped table-bordered table-hover">';
                echo '<thead><tr>';
                echo '<th>Time</th><th>Invoice</th><th>Request Amount</th><th>Email address</th><th>Input address</th><th>USD</th>';
                echo '<th>Payment Method</th><th>Payment Received</th><th>Payment sent</th><th>Active</th><th>Actions</th></tr></thead>';
                for ($i = 0; $i < @mysql_num_rows($query); $i++) {
                    
                    echo '<tr>';
                    echo '<td>'.mysql_result($query, $i, 'Time').'</td>';
                    echo '<td>'.mysql_result($query, $i, 'Invoice').'</td>';
                    echo '<td>'.mysql_result($query, $i, 'currency').' '.mysql_result($query, $i, 'amount').'</td>';
                    echo '<td>'.mysql_result($query, $i, 'Email_address').'</td>';
                    echo '<td>'.mysql_result($query, $i, 'Input_address').'</td>';
                    echo '<td>'.mysql_result($query, $i, 'Usd').'</td>';
					
					$payment_method = mysql_result($query, $i, 'Payment_method');
					
                    echo '<td><a href="javascript:void(0)" class="link-popover" data-placement="left" data-toggle="popover" title="'.$payment_method.'" data-content="';
					
					switch($payment_method){
						case 'Paypal':
							echo "Paypal: " . mysql_result($query, $i, 'Paypal_address');
							break;
						case 'Bank Transfer':
							echo "Bank Name: " . mysql_result($query, $i, 'banktransfer_bank_name') . '<br />';
							echo "Bank Address: " . mysql_result($query, $i, 'banktransfer_bank_address') . '<br />';
							echo "Swift Code: " . mysql_result($query, $i, 'banktransfer_swift_code') . '<br />';
							echo "Routing Number: " . mysql_result($query, $i, 'banktransfer_account_routing_number') . '<br />';
							echo "Account Name: " . mysql_result($query, $i, 'banktransfer_account_name') . '<br />';
							echo "Account Number: " . mysql_result($query, $i, 'banktransfer_account_number') . '<br />';
							break;
						case 'Moneypak':
							echo "Phone: " . mysql_result($query, $i, 'moneypak_phone') . '<br />';
							echo "Address: " . mysql_result($query, $i, 'moneypak_address') . '<br />';
							break;
						case 'Western Union':
							echo "Name: " . mysql_result($query, $i, 'westernunion_name') . '<br />';
							echo "City: " . mysql_result($query, $i, 'westernunion_city') . '<br />';
							echo "Country: " . Settings::$countries[mysql_result($query, $i, 'westernunion_country')] . '<br />';
							break;
						default:			
					}
					
					echo '">'.mysql_result($query, $i, 'Payment_method').'</a></td>';
                    echo '<td>'.mysql_result($query, $i, 'currency').' '.mysql_result($query, $i, 'Btc_received').'</td>';
                    echo '<td>'.mysql_result($query, $i, 'Payment_sent').'</td>';
                    echo '<td>'.mysql_result($query, $i, 'Active').'</td>';
                    echo '<td><form method="get" action="admin.php">';
                    echo '<input type="hidden" name="mode" value="all">';
                    if (mysql_result($query, $i, 'Payment_sent') == 1) {
                        echo '<input type="hidden" name="action" value="markunpaid">';
                        echo '<input type="hidden" name="id" value="'.mysql_result($query, $i, 'Invoice').'">';
                        echo '<input type="submit" class="btn btn-primary btn-sm btn-warning" value="Mark unpaid"> <br><br>';
                    } else {
                        echo '<input type="hidden" name="action" value="markpaid">';
                        echo '<input type="hidden" name="id" value="'.mysql_result($query, $i, 'Invoice').'">';
                        echo '<input type="submit" class="btn btn-primary btn-sm btn-success" value="Mark paid">  <br><br>';
                    }
                    echo '</form>';
                    echo '<form method="get" action="admin.php">';
                    echo '<input type="hidden" name="mode" value="all">';
                    if (mysql_result($query, $i, 'Active') == 1) {
                        echo '<input type="hidden" name="action" value="invalidate">';
                        echo '<input type="hidden" name="id" value="'.mysql_result($query, $i, 'Invoice').'">';
                        echo '<input type="submit" class="btn btn-primary btn-sm btn-danger" value="Invalidate">';
                    } else {
                        echo '<input type="hidden" name="action" value="validate">';
                        echo '<input type="hidden" name="id" value="'.mysql_result($query, $i, 'Invoice').'">';
                        echo '<input type="submit" class="btn btn-primary btn-sm btn-info" value="Validate">';
                    }
                    echo '</form>';
                    echo '</td>';
                    echo '</tr>';
                    
                }
                echo '</table></div></div></div>';
                $mysql->close();
            }
            if ($mode == 'active') {
                echo '<div class="page-header"><h1 id="tables">Confirmed transactions awaiting payment</h1></div>';
                
                $mysql = new Mysql();
                $mysql->connect();
                $mysql->setDatabase(Settings::mysql_database);
                
                $query = $mysql->executeQuery("SELECT transactions.*
													, currencies.currency AS currency 
												FROM transactions LEFT JOIN currencies ON transactions.currency_id = currencies.id 
												WHERE transactions.Active=1 
													AND transactions.Payment_sent=0 
													AND transactions.amount <= transactions.Btc_received");
                echo '<div class="bs-docs-section"><div class="row"><div class="col-lg-12"><table class="table table-striped table-bordered table-hover">';
                echo '<thead><tr>';
                echo '<th>Time</th><th>Invoice</th><th>Request Amount</th><th>Email address</th><th>Input address</th><th>USD</th>';
                echo '<th>Payment Methods</th><th>Payment Received</th><th>Payment sent</th><th>Active</th><th>Actions</th></tr></thead>';
                for ($i = 0; $i < @mysql_num_rows($query); $i++) {
                    
                    echo '<tr>';
                    echo '<td>'.mysql_result($query, $i, 'Time').'</td>';
                    echo '<td>'.mysql_result($query, $i, 'Invoice').'</td>';
                    echo '<td>'.mysql_result($query, $i, 'currency').' '.mysql_result($query, $i, 'amount').'</td>';
                    echo '<td>'.mysql_result($query, $i, 'Email_address').'</td>';
                    echo '<td>'.mysql_result($query, $i, 'Input_address').'</td>';
                    echo '<td>'.mysql_result($query, $i, 'Usd').'</td>';
                    
					$payment_method = mysql_result($query, $i, 'Payment_method');
					
                    echo '<td><a href="javascript:void(0)" class="link-popover" data-placement="left" data-toggle="popover" title="'.$payment_method.'" data-content="';
					
					switch($payment_method){
						case 'Paypal':
							echo "Paypal: " . mysql_result($query, $i, 'Paypal_address');
							break;
						case 'Bank Transfer':
							echo "Bank Name: " . mysql_result($query, $i, 'banktransfer_bank_name') . '<br />';
							echo "Bank Address: " . mysql_result($query, $i, 'banktransfer_bank_address') . '<br />';
							echo "Swift Code: " . mysql_result($query, $i, 'banktransfer_swift_code') . '<br />';
							echo "Routing Number: " . mysql_result($query, $i, 'banktransfer_account_routing_number') . '<br />';
							echo "Account Name: " . mysql_result($query, $i, 'banktransfer_account_name') . '<br />';
							echo "Account Number: " . mysql_result($query, $i, 'banktransfer_account_number') . '<br />';
							break;
						case 'Moneypak':
							echo "Phone: " . mysql_result($query, $i, 'moneypak_phone') . '<br />';
							echo "Address: " . mysql_result($query, $i, 'moneypak_address') . '<br />';
							break;
						case 'Western Union':
							echo "Name: " . mysql_result($query, $i, 'westernunion_name') . '<br />';
							echo "City: " . mysql_result($query, $i, 'westernunion_city') . '<br />';
							echo "Country: " . Settings::$countries[mysql_result($query, $i, 'westernunion_country')] . '<br />';
							break;
						default:			
					}
					
					echo '">'.mysql_result($query, $i, 'Payment_method').'</a></td>';
                    echo '<td>'.mysql_result($query, $i, 'currency').' '.mysql_result($query, $i, 'Btc_received').'</td>';
                    echo '<td>'.mysql_result($query, $i, 'Payment_sent').'</td>';
                    echo '<td>'.mysql_result($query, $i, 'Active').'</td>';
                    echo '<td><form method="get" action="admin.php">';
                    echo '<input type="hidden" name="mode" value="active">';
                    if (mysql_result($query, $i, 'Payment_sent') == 1) {
                        echo '<input type="hidden" name="action" value="markunpaid">';
                        echo '<input type="hidden" name="id" value="'.mysql_result($query, $i, 'Invoice').'">';
                        echo '<input type="submit" class="btn btn-primary btn-sm btn-warning" value="Mark unpaid">';
                    } else {
                        echo '<input type="hidden" name="action" value="markpaid">';
                        echo '<input type="hidden" name="id" value="'.mysql_result($query, $i, 'Invoice').'">';
                        echo '<input type="submit" class="btn btn-primary btn-sm btn-success" value="Mark paid">';
                    }
                    echo '</form>';
                    echo '<form method="get" action="admin.php">';
                    echo '<input type="hidden" name="mode" value="active">';
                    if (mysql_result($query, $i, 'Active') == 1) {
                        echo '<input type="hidden" name="action" value="invalidate">';
                        echo '<input type="hidden" name="id" value="'.mysql_result($query, $i, 'Invoice').'">';
                        echo '<input type="submit" class="btn btn-primary btn-sm btn-danger" value="Invalidate">';
                    } else {
                        echo '<input type="hidden" name="action" value="validate">';
                        echo '<input type="hidden" name="id" value="'.mysql_result($query, $i, 'Invoice').'">';
                        echo '<input type="submit" class="btn btn-primary btn-sm btn-info" value="Validate">';
                    }
                    echo '</form>';
                    echo '</td>';
                    echo '</tr>';
                    
                }
                echo '</table></div></div></div>';
                
                
                echo '<br><br><br>';
                echo '<div class="page-header"><h1 id="tables">Pending transactions</h1></div>';
                $query = $mysql->executeQuery("SELECT transactions.*
													, currencies.currency AS currency 
												FROM transactions LEFT JOIN currencies ON transactions.currency_id = currencies.id 
												WHERE transactions.Active=1 
													AND transactions.Payment_sent=0 
													AND transactions.amount > transactions.Btc_received 
													AND transactions.Time_long > ".(time() - (Settings::timeout_duration * 60)));
                echo '<div class="bs-docs-section"><div class="row"><div class="col-lg-12"><table class="table table-striped table-bordered table-hover">';
                echo '<thead><tr>';
                echo '<th>Time</th><th>Invoice</th><th>Request Amount</th><th>Email address</th><th>Input address</th><th>USD</th>';
                echo '<th>Payment Method</th><th>Payment Received</th><th>Payment sent</th><th>Active</th><th>Actions</th></tr></thead>';
                for ($i = 0; $i < @mysql_num_rows($query); $i++) {
                    
                    echo '<tr>';
                    echo '<td>'.mysql_result($query, $i, 'Time').'</td>';
                    echo '<td>'.mysql_result($query, $i, 'Invoice').'</td>';
                    echo '<td>'.mysql_result($query, $i, 'currency').' '.mysql_result($query, $i, 'amount').'</td>';
                    echo '<td>'.mysql_result($query, $i, 'Email_address').'</td>';
                    echo '<td>'.mysql_result($query, $i, 'Input_address').'</td>';
                    echo '<td>'.mysql_result($query, $i, 'Usd').'</td>';
                   
				   	$payment_method = mysql_result($query, $i, 'Payment_method');
					
                    echo '<td><a href="javascript:void(0)" class="link-popover" data-placement="left" data-toggle="popover" title="'.$payment_method.'" data-content="';
					
					switch($payment_method){
						case 'Paypal':
							echo "Paypal: " . mysql_result($query, $i, 'Paypal_address');
							break;
						case 'Bank Transfer':
							echo "Bank Name: " . mysql_result($query, $i, 'banktransfer_bank_name') . '<br />';
							echo "Bank Address: " . mysql_result($query, $i, 'banktransfer_bank_address') . '<br />';
							echo "Swift Code: " . mysql_result($query, $i, 'banktransfer_swift_code') . '<br />';
							echo "Routing Number: " . mysql_result($query, $i, 'banktransfer_account_routing_number') . '<br />';
							echo "Account Name: " . mysql_result($query, $i, 'banktransfer_account_name') . '<br />';
							echo "Account Number: " . mysql_result($query, $i, 'banktransfer_account_number') . '<br />';
							break;
						case 'Moneypak':
							echo "Phone: " . mysql_result($query, $i, 'moneypak_phone') . '<br />';
							echo "Address: " . mysql_result($query, $i, 'moneypak_address') . '<br />';
							break;
						case 'Western Union':
							echo "Name: " . mysql_result($query, $i, 'westernunion_name') . '<br />';
							echo "City: " . mysql_result($query, $i, 'westernunion_city') . '<br />';
							echo "Country: " . Settings::$countries[mysql_result($query, $i, 'westernunion_country')] . '<br />';
							break;
						default:			
					}
				   
				    echo '">'.mysql_result($query, $i, 'Payment_method').'</a></td>';
                    echo '<td>'.mysql_result($query, $i, 'currency').' '.mysql_result($query, $i, 'Btc_received').'</td>';
                    echo '<td>'.mysql_result($query, $i, 'Payment_sent').'</td>';
                    echo '<td>'.mysql_result($query, $i, 'Active').'</td>';
                    echo '<td><form method="get" action="admin.php">';
                    echo '<input type="hidden" name="mode" value="active">';
                    if (mysql_result($query, $i, 'Payment_sent') == 1) {
                        echo '<input type="hidden" name="action" value="markunpaid">';
                        echo '<input type="hidden" name="id" value="'.mysql_result($query, $i, 'Invoice').'">';
                        echo '<input type="submit" class="btn btn-primary btn-sm btn-warning" value="Mark unpaid"><br><br>';
                    } else {
                        echo '<input type="hidden" name="action" value="markpaid">';
                        echo '<input type="hidden" name="id" value="'.mysql_result($query, $i, 'Invoice').'">';
                        echo '<input type="submit" class="btn btn-primary btn-sm btn-success" value="Mark paid"><br><br>';
                    }
                    echo '</form>';
                    echo '<form method="get" action="admin.php">';
                    echo '<input type="hidden" name="mode" value="active">';
                    if (mysql_result($query, $i, 'Active') == 1) {
                        echo '<input type="hidden" name="action" value="invalidate">';
                        echo '<input type="hidden" name="id" value="'.mysql_result($query, $i, 'Invoice').'">';
                        echo '<input type="submit" class="btn btn-primary btn-sm btn-danger" value="Invalidate">';
                    } else {
                        echo '<input type="hidden" name="action" value="validate">';
                        echo '<input type="hidden" name="id" value="'.mysql_result($query, $i, 'Invoice').'">';
                        echo '<input type="submit" class="btn btn-primary btn-sm btn-info" value="Validate">';
                    }
                    echo '</form>';
                    echo '</td>';
                    echo '</tr>';
                    
                }
                echo '</table></div></div></div>';
                $mysql->close();
            }
			
			if ($mode == 'currencies') {
				$mysql = new Mysql();
				$mysql->connect();
				$mysql->setDatabase(Settings::mysql_database);
				
				if(isset($_GET['action']) && !empty($_GET['action'])){
					switch($_GET['action']){
						case 'add':
							$errors = array();
							
							if($_POST){
								if(empty($_POST['currency']) || trim($_POST['currency'])==''){
									$errors['currency'] = 'Required field: currency.';
								}else{
									$str = "SELECT * FROM currencies WHERE currency = '" . $mysql->escape($_POST['currency']) . "'";
									$query = $mysql->executeQuery($str);
									if (@mysql_num_rows($query) != 0) {
										$errors['currency'] = 'Currency already exists.';
									}
								}
								if(empty($_POST['name']) || trim($_POST['name'])==''){
									$errors['name'] = 'Required field: currency name.';
								}
								if(empty($_POST['price']) || trim($_POST['price'])==''){
									$errors['price'] = 'Required field: price.';
								}else if(!is_numeric($_POST['price'])){
									$errors['price'] = 'Invalid price.';
								}
								
								if(count($errors)<=0){
									$args = array (
													"created_datetime" => date('Y-m-d H:i:s', time() + (Settings::timezone_shift * 60 * 60)),
													"currency" => $mysql->escape(trim($_POST['currency'])),
													"name" => $mysql->escape(trim($_POST['name'])),
													"price" => $mysql->escape(trim($_POST['price'])),
													);
									$mysql->insert($args, 'currencies');
									
									header('Location: admin.php?mode=currencies');
									exit();
								}
							}
							
							require('currencies/add.php');	
							break;
						case 'update':
							if(isset($_GET['id']) && !empty($_GET['id'])){
								$str = "SELECT * FROM currencies WHERE id = '" . $mysql->escape($_GET['id']) . "'";
								$query = $mysql->executeQuery($str);
								if (@mysql_num_rows($query) > 0) {
									$errors = array();
									
									$id = $_GET['id'];
									$currency = mysql_result($query, 0, 'currency');
									
									if($_POST){
										$name = $_POST['name'];
										$price = $_POST['price'];
										
										if(empty($_POST['name']) || trim($_POST['name'])==''){
											$errors['name'] = 'Required field: currency name.';
										}
										if(empty($_POST['price']) || trim($_POST['price'])==''){
											$errors['price'] = 'Required field: price.';
										}else if(!is_numeric($_POST['price'])){
											$errors['price'] = 'Invalid price.';
										}
										
										if(count($errors)<=0){
											$mysql->executeQuery("UPDATE currencies 
																	SET name='" . $mysql->escape(trim($_POST['name'])) . "' 
																		, price = '" . $mysql->escape(trim($_POST['price'])) . "'
																		, modified_datetime = '" . date('Y-m-d H:i:s', time() + (Settings::timezone_shift * 60 * 60)) . "'
																	WHERE id='" . $mysql->escape(trim($_GET['id'])) . "'");
											
											header('Location: admin.php?mode=currencies');
											exit();
										}
									}else{
										$name = mysql_result($query, 0, 'name');
										$price = mysql_result($query, 0, 'price');
									}
									
									require('currencies/update.php');	
								}else{
									header('Location: admin.php?mode=currencies');
									exit();
								}
							}else{
								header('Location: admin.php?mode=currencies');
								exit();
							}
							break;	
						case 'remove':
							if(isset($_GET['id']) && !empty($_GET['id'])){
								$str = "DELETE FROM currencies WHERE id = '" . $mysql->escape($_GET['id']) . "'";
								$query = $mysql->executeQuery($str);
							}
							header('Location: admin.php?mode=currencies');
							exit();
							break;
					}
				}else{
					$str = "SELECT * FROM currencies ORDER BY currency, name";
					$query = $mysql->executeQuery($str);
													
					require('currencies/list.php');	
				}
			}
			
			if ($mode == 'walletaddresses') {
				$mysql = new Mysql();
				$mysql->connect();
				$mysql->setDatabase(Settings::mysql_database);
					
				if(isset($_GET['action']) && !empty($_GET['action'])){
					switch($_GET['action']){
						case 'add':
							if($_POST){
								if(empty($_POST['currency_id']) || trim($_POST['currency_id'])==''){
									$errors['currency_id'] = 'Required field: currency.';
								}else{
									$str = "SELECT * FROM currencies WHERE id = '" . $mysql->escape($_POST['currency_id']) . "'";
									$query = $mysql->executeQuery($str);
									if (@mysql_num_rows($query) <= 0) {
										$errors['currency_id'] = 'Currency does not exists.';
									}
								}
								
								if(count($errors)<=0){
									if(!empty($_POST['addresses'])){
										$addresses = explode("\n", $_POST['addresses']);
										// print_r($_addresses);
										if(count($addresses) > 0){
											foreach($addresses as $address){
												// echo $address . "<br/>";
												$address = trim($address);
												
												$str = "SELECT * 
															FROM wallet_addresses 
															WHERE address = '" . $mysql->escape($address) . "'
																AND currency_id = '" . $mysql->escape($_POST['currency_id']) . "'";
												$query = $mysql->executeQuery($str);
												if (@mysql_num_rows($query) == 0) {
													$args = array (
																"created_datetime" => date('Y-m-d H:i:s', time() + (Settings::timezone_shift * 60 * 60)),
																"currency_id" => $mysql->escape($_POST['currency_id']),
																"address" => $mysql->escape($address),
																);
													$mysql->insert($args, 'wallet_addresses');
												}
											}
										}
									}
									
									header('Location: admin.php?mode=walletaddresses');
									exit();
								}
							}
							
							$str = "SELECT * FROM currencies ORDER BY currency, name";
							$queryCurrencies = $mysql->executeQuery($str);
					
							require('walletaddresses/add.php');	
							break;
						case 'remove':
							if(isset($_GET['id']) && !empty($_GET['id'])){
								$str = "DELETE FROM wallet_addresses WHERE id = '" . $mysql->escape($_GET['id']) . "'";
								$query = $mysql->executeQuery($str);
							}
							header('Location: admin.php?mode=btcaddresses');
							exit();
							break;	
						default:
							echo "Invalid Action.";	
					}
				}else{
					// Just display the list of BTC address
					
					$str = "SELECT 
									wallet_addresses.id AS id
									, currencies.currency AS currency
									, wallet_addresses.address AS address 
								FROM wallet_addresses LEFT JOIN currencies ON wallet_addresses.currency_id = currencies.id
								WHERE used!='Y' 
								ORDER BY currencies.currency, wallet_addresses.address";
					$query = $mysql->executeQuery($str);
												
					require('walletaddresses/list.php');	
				}
			}
            
            echo '<br>';
            echo '<form method="get" id="logout" action="admin.php">';
            echo '<input type="hidden" name="mode" value="logout">';
            echo '<input type="submit" class="btn btn-primary btn-lg" value="logout"></form>';
            
            echo '</center>';
        }
    } else {
        $user = isset($_POST['user']) ? $_POST['user'] : '';
        $pass = isset($_POST['pass']) ? $_POST['pass'] : '';
        
        if (strcmp(sha1($user.$pass.Settings::admin_salt), Settings::admin_pass) == 0) {
            setcookie(Settings::cookie_name, sha1($user.$pass.Settings::admin_salt));
            $page = "admin login process";
            include 'assets/header.php';
            echo '<meta http-equiv="refresh" content="5">';
            echo '<center>Please wait, redirecting in 5 seconds.<br>';
            echo '<form method="get" action="admin.php">';
            echo '<input type="submit" value="Click here to proceed immediately."></form></center>';
        } else {
            if (strlen($user) > 0 || strlen($pass) > 0) {
                echo '<p style="color: red;">Incorrect username or password.</p>';
            }
            ?>
            <?php
            $page = "admin login";
            include 'assets/header.php';
            ?>
            <br>
            <div class="row">
                <div class="col-lg-4">
                </div>
                  <div class="col-lg-4">
                    <div class="well">
                      <form method="post" action="admin.php">
                          <legend>Login</legend>
                          <hr>
                          <div class="form-group">
                          <label class="control-label" for="username">Username</label>
                          <input class="form-control" maxlength="20" name="user" id="username" type="text" placeholder="Username">
                        </div>
                        <div class="form-group">
                          <label class="control-label" for="password">Password</label>
                          <input class="form-control" maxlength="20" name="pass" id="password" type="password" placeholder="Password">
                        </div>
                         <div class="form-group">
                            <center>
                              <input type="submit" value="Login" class="btn btn-primary">
                            </center>
                          </div>
                      </form>
                    </div>
                  </div>
                  <div class="col-lg-4">
                  </div>
              </div>
            <div class="container">

            <?php
        }
    }
?>
<?php
    include 'assets/footer.php';
?>