<?php

session_start();
if(!$_SESSION['researcher_id'] || !$_SESSION['admin']) {
    header("Location: login.php");
    exit;
}

require_once 'db.function.php';
$db = getDB();
if(isset($_POST['approved'])) {
    $db->query("update researcher set approved = 1 where researcher_id in (".join(',', $_POST['approved']).")");
    $appr_email = $db->getCol("select email from researcher where researcher_id in (".join(',', $_POST['approved']).")");
    foreach($appr_email as $appr) {
        mail($appr, "Your DASR account is approved", "Your DASR account is approved. Please visit\n\nhttp://$_SERVER[SERVER_ADDR]/DASR_2011\n\nBest,\nDASR Team", "From: DASR <phao@bu.edu>");
    }
    $db->commit();
}
$rsc = $db->query("select researcher_id, firstname, lastname, email from researcher where approved = 0");

$title = "Login";
require_once 'header.inc.php';
?>
<h3>Approve new users:</h3>
<form method="post">
<table>
<?php
$header = false;
while($r = $rsc->fetchRow()) {
    if(!$header) {
        print "<tr><th></th><th>" . join("</th><th>", array_keys($r)) . "</th></tr>\n";
        $header = true;
    }
    print "<tr><td><input type=\"checkbox\" name=\"approved[]\" value=\"$r[researcher_id]\"</td>";
    print "<td>" . join("</td><td>", $r) . "</td></tr>\n";
}
?>
<tr><td></td><td><input type="submit" value=" OK " name="submit"/></td></tr>
</table>
</form>
<?php
require_once 'footer.inc.php';
?>

