JFIFHH(ICC_PROFILE0mntrRGB XYZ acsp- desctrXYZdgXYZxbXYZrTRC(gTRC(bTRC(wtptcprtiPSP Вpu9b"PH+MC<žϓItu'b=o8vӆDD.Gh jLDf@S)"xp\xdD޸@q0^Ks(>ϛd? @5ARA((A(]|N-7<78qr>}7ΩrWvϋ>+gI&!4Qxsf:?9(mɦdy9$נTVm[x3X&$eg]9^tihkhٹj>@"`f}no0773 l^9DcWt!>>:Kwa>OJuvSo %3Ughvò"ݦ-22HHpu^6.=)J$'DuV㎾>ZN$m\R :o1RU.Z}NăTb '!׌_FŢBjg]5Ź a@(yяj) 6 H5%=THU|qSfΏC[s?qk7ĤD&P]>z@[³$|\=ܜ2|ݏƽd5StQ(uVINi:W5ﱏ珔WAS\{4V6w8תm9  ?f+voͧξyK˒ɉQqglq?kYqbj=O`d3JO_6oի>ӜY33$ U /c^(e )TmMar,/}O_)>qvQĝEL^2z*%d:|64Tcvms9h5l<ö !kSdLLINivZyxlЍd5K`IϮ5m=_n~G@n`yqol?6՗ˏRcz}(w%HYMsMqt9nmueovEI9qсa[s{O& wzd\Ua%L")T)fL`^ټQ$"} a59"ddE5;Z8"`zC7ayz "~om~iMeO]ʢG0c|_k'Љ_rGSfk,)ɘ@?9vc]9齛v9 #87|vr]uU_'W4 "@҃LV dwjEd@+7[ven3r%Eq?VD6ti{nO"I@'1C,i\}=k;g/~7LnGI[_z-%;f%lsItTxɛK ʊ_VnB^95Žnr|h>~?>n0R*GGnng鳓KI[^a2/]QTuT0+U|56v j-^yt^+/m%3T10._?f5[7ygezHl~>~8v5Y59+B&(.5ٿw/Nd.w~M5L܏FNl8v'n#3TmC" )*`|sg>D-J ^GERVIrf1ϩOGݠ>^+nC< vfF7ǢMK՜_M}W0v:rv :Nϰf8*\ h \kqar :+ߛMW̕;XP*ژY7iomOi4^€γ7_vnRq=\t(s}0C_5oC'vf4ٳ2S.٘N 3Kjߘ!*4Э6pc_1,;gܧ%t=ǒvYSm8s`wcl?73cN3}{rOյ `g'g.L/}uҚns&:`GW\Hy?uY|ֆaMB` H4t˳} oե Un="-MU`*Onse^^hYZJЙ>o6;Λ`k t$"*E_1a欳tmn1L𢘘g}[9ו)4.0hϗ(5Ao\h#B$dͽ>UX&$DQbgٰ|ys*&`8Cz~or,- "@M%<Ӝlc(7>4xRay"IW6=0UH_FNGJML)Ni}6mU ){x?4;s!+SP5'?0+bgE`P)-gζVzx Lt wg$T"21\ި]Պ " ]FNqBSʝWq]|'<_sB^DA0L ;筬s?Ek:p @zsKZ &Q`Bk<޾dSWI3YC۳9;Gug_s:[ 4gsҼZpl3;1wG^NXlk1Pcƀ}sKSUC:wS JIo l^w: o CW&OLMomr7Vb>L /dLT/.=.Vu[+J'?dK btRzji@Đ r#b¯K)Νqi"2+1k\*3,vpKةIqaS3L %drV\+LуsSD$OW/5(K+B>TѬ2bI&RiqG%J Igǫ6Ec6yEbXL\wzm~(}kkى+X==KN8gvhR3goa #n (_^ME*Qؾ^K.F= J}drH"7;?*"ejw BJc|QJS̜VN(`;ms$~sccTCc?SOY<ޜD:ow!kܞLDWčfsT }&ip䋛ݘg蒻҃>σ007: &QM_-U1y< lk"> .A&Y:h*t7"{|_I{xV125:st'XeE嶐aN5vWIo/o#[Ґ.y-\qF7:srΔ\反$h@szFY'<=.u)sUjvsv[)#gZSO7pwѦh`|#ljPهK4)ڜ+$j1֊1Pq #liZۄSzHM.ƻV͏[#C9.hqǬ]J>:xr˂&"*DMuG+}V(l \ʆ&ܟl_cy ydC&MLY6TUA4ac&#YUB),ʡj;aD߮']i>h$&*4]0fe˨('*+V#`La\y-zhdPrE_ѓ-ƹ N` lnbͰ_O\vfIe|JkPՋ"DreM],74_Q+[FY˖'`!d~M..74F$*~`b'ˏ ?CƯ%Ӯ[8U{ӿGiKYEѡm\yQ<_?܈xTE.or=qF&ٱgƱx6t:uob}tN٢ ܥ_IK/bpW6Ƌ-,֤Wl_.~ aN~NҸL[&%/Uߞ.#.oGzH-k]`M)gؖ 061f/eR{SgL:-4z(fDFҞl7iQ>k<=액a~ЅbM1zH^'N(7@xyb| -g),IVKYh`}8nʏWYGO?aat H!nPŒ)f,'UmbעxȆ2!*֮ӧEUi0Pͨ .<<*PwK7$&R]_jiЉ[}?.sw~}}tgV%jtPlj=-xK=hkcuv-E\vYbu#9z}ʝM|q> E܌6dı+Umaɐ?ؓ ;ȭ6&6wFׂC쫌iCGa[#w[xN|4=%!z$2}.Eig ʽcJ?dd2snO .&HtO"OMN囸=EӬ2:?4}Й ǗS"r&*[MkKA6@wƿvp&! ˭\y,+ Da~HmfpđJ*$sRHf7Pj6d(K\!CMؐoOr74v;<\1L](.;c?Z ,t.X=biKvjUGLIC,UF'qMbZ≩VJI\z]w s~PL,࿬Lj9sFvq*r$X_Zw\ K4}f~IȽ\3p60-[~B|!H5pZ38f7tsn5 ^KzCU6u@ޯf +=C u$ކf_mrXW&jT~]YsTofq}@sTΜ)~Ywh]sμ\\ OKXHfZ||ijdEx1+F0=@JyL&Ze4{.>Ҡ}yHW"6 XBZP3o/#ǐ4-4s}Zr:l"KBr4(L Ak'f'iIbXw 6䞬Rpb}Nj9gQgI2Z5ʅFiŵYm^|[UUe,1kJj`g<_g Og=Gi kslwfgLi\q1FGD-?}JcJ NNV7OcYkR8_~D3&.fv`!C1(\nbnjJr[\ѝ9ϒ9Թk= e}U{&85U5 % ֹ }Jҵ~]MW\`ޤrΞ \웝,gv;&'.9mU.6&W)RnK~))5kD<.7-/VCŘxiz>ʭG!͑k \&)Ha4xodncSp)jc+&kί.[+84L:Sd,XEX E$}bH77;Q4N>Xbl1U囕ڽYv'56s4n'+F(|v?ϏϏD{C6*nk`0pu:7`KjJ݂Jd<'4۵r+9|S;w|dHh\ ETUq,n"Zl2$¢~f),*/"x<{Eoq3QZ,>BlLh )I4v>*vҊ8D||7Ό\LM,ڵ8zSlHz {B1`M!u#ƹL_aj58*md>g)V';WG+do:u:v&*MT>>^/Jl{3a.uφwNcy՛@`{x2&ctmUUaM*fA9"t;Jt;čULV/hc"`5a*{1YkSbk9=mTgh61٧_=Vݽ鎲bhU}6Pv7B~(xlԓږKѿgQΣ^Mv ,h?Z߽~gMUij}Gۀ~/gS"$b)LushGQIog:߽Ɨa.7;OL?OvuMiu{piZ0>+(KiMJ9SjXhoب-@@ܮ7R6XQU=ZL$H36rqVNV1IddD:r+"H]9ywf|85D5M#9ֻ_fd琜H-ssi;b\7?\?\? !"1AQa #023@qrBPRb$4sC?f QZ+}d.]c]KT2#t]+]˸g컆{.˸g컆{.˺ok!h<W1iXo1~v$OhDаi" `y" 9?*4$oF?$ԮkNWYOh4Ǐh(Gf^o2k^]+4{"&F#)L:EA{ hZ&nWE:'o84 aSYMkEqM%ycmZرm|teV0'uZxRu_oZ9 ӽiAUžeSYhuXPhg×^W>LQt\T< (*k0jfF`a`~kV}~h;*.7hoi4'LHWa PuCM&ϺAyKPv_,@9 ᥗzV=gVm/LیM/z4oDxGÞ=ylFK#wp/jM }HT疸T95:zkM߸1[ QxCx qWhdv՛2rS3܁oCD2J|:']ţ(]Z&"trL{u#)d;IMdMj `mX<,(V=L^]At~-Uc+Z޿P +Bu'I]PԺ:#`=:Gq<|hhܩRQ!0rn%?6?%E# .Aֻt1- . BM*dHSi07 Lbv`2phF+5LjgԁiʁuPGukoUQu70d:`[8sݨ! պچ:j4#~.3ѼnY ]H-(1retUU<˹ 7Mi ^衮m6[SG`vVޗx]/P5;1]uF{'cA5Ȭ70d v6+nZWn5FW#8Iem˸zS^ "*N*ʹ;B=ۢTzXWa+84Pk{:>.sܒz |Pzrd?rK5T{Mx"&WZ {Y[sm>J1mUKu(pt`qFhU@2"#=u555%70[9/bӛ9As8-8VNrcrsw - h:(ܫg/e? 1t!_B6Y #PVu(21S|J}8dvkM6;m9<^<v -]3/In]/*2^sj'@]5WNI=O> &pDDN݅V{W9RoZK!"2tr-._SK!r\Fڃ!A4emo6䥄sh`wsQ^̺ڳbw6*]]/U{.j[q] G("F4GzgfY@A/gO$|9)JXش#kWmv֕`a] K 96J mQV]GeĮۗl9\]1+N6RX8sHv!W镎fP[tm#'g?g.s\G;z TE><ƆIx%O>OW:hΛ!Y $o/l 9d2FGfGe Nʹdj=cϟx3$4'y*i|OKw2F&5;"FguVkv)=I˜m bn8^ Nkf gY\Un0) _(s^;~~Y n,ӝ[| n>Yطuָ96@r|S&IR`!O^YQ suأvW'D! Zj…>,-u_4UՎGo/nW,iUS-taW8p,i8sŊՖF?TSZU.&F7eP81b GPŮOwgUHSdVnvZJ]6?$]̲Vs$ .*( '6 mM~y }IX捃ÈS&qrfe5kvix&=h0~+#,*쎐S g\TlTҦj Wh؅6VZc6kn &y{]NM)| EH7d{tBȀ/7Lk56'hOaܟ&I]\"9;5uEFʝAP wҿcZu]Vt:S;'z#`)r{;S#jk@Yǰ7z0vGE+P4]=£\0̲#3E5Pc Hu9ta\ 1%7VYT_!NY0+h릉T1 Gr|8xp;0Zcv@ Cڥam cote5ԺI ,u!vl5KiqִTU6BiThb1j sgۓ#9Uf{);:7XY1^qNtN e_ 5g,Ԣc-v js̒l:pMjH:Bm$ڢc9'-D#L׊ ~Ѯ+j{i8dJ5X]VU3UDG iޜHsgg4=Z(n,Xf]jӒ\WpWuEL+7Fó(v0rhNqED|KyD-ɘVz*^h‰(G7ZllS@mLhE5tJ0>,SchTDRc>+ie|/-6k1hplg=To%i׷⢒'PXbdD6FI1'bGHfp4viLv\ݹK4۩9c:mMnͩt5},} .g>g-6ѷS$v* ~~~~sm__TZ˜.e+AUI@ܳձdHތb[+`FeԳ7 e5Z_G9 Þc{AXL_$`X.!B5UvGHS5f,f&66 J IݢFW&5FAءtoZ[A|5]x}N jڻZ(kt{eȲ,{nrN:C,|X;Ʊ)ON*ZB 'j+Cv2MAߏA9|&]ӣ~/o7Ɣ-'='SP4BhnK+=MA51D6@e$ari5,@oV9 wcGWnNKgei;Pk@aɢ8|ήa63qƇTJ0TWd]cIMT 97/Vsx;矐2Vat:..[b6Lu$#iGk - v[y ։`t;B)FkQ1* tl89wRXS FEZN(GꍆLbl/;َo. #=u r:|MkGu\q=;%Ƨ;_]EI;cAP a]j~LASl`~"3HH~XB6d.GYS:+;S_Umnޯ3qwǘִ]]F+_!hBmvjެ^qlNE5?,֚ɉ,A:s$'Ce4j$K{+=8q (,q\P9 ^*]+E$D/ 6aߵHܱǼs.7~mz3BVHAn[7a̼@9)%!Xc9S)<^F8MMOηѼ6Ѧo-xd@М YOJ_4N_mŝ۽F'uWLoC(.;rvý?;3CۚvMai|Ra&Z]`pnq#I拕M1q~ZL"7.Nc{M.J3iڣjowh5gikpj[vګr8(so{a'Z1%:Kk (,y&fh~LB*ڳ\JlKPYm(O/5S'|2Vv)8Q>/H9ׂuѬj; {Ne3_&vIuZ1690ҡ_/D,:Ykow_ZmY蛝{.t$e/Wqج68978_L;(,g\xTW>W'5p :aG21&55*WZI5+/D,1示nVg6yG:զ^RJUY,9<]t g9@cuVEIe*ie5v)U4y|TX=R`Κ!^?+)([g 2+75plS OlnIpڬV@)`9ZT7z؀WkōcxNDSx,Lbu#eٯ6@2 sU$-}RJ`Br U,=%s'Tyjg*:!<./eNjjq .˝~IOHNz&5w:栲btRհtsEx$9^yF’unDY5]'+<͖Pk=gSP1TDDRQ<үiR()|ܢseűK£Y5^CNmRe=ʕRT=#IS'6.2@ fxX3T(1(e Iq{/n= ȓSmir.q+s(1_bWƾR+W+S騆]Fٕ 4*/ILy’l Ik)P+k.cuh2w\A RoAX八nemJ,\te.%|Ŏl&4ZPOP*J5E] jk?1s/ #4g`uők%?/uBM/u7fBŴVb^!8*q #Ḫ՘q.PŊ<,ԛ׽s( P[M1z+db]w.eAC s`^U)\U Y^5% :.ff^dL?M vрUަfa\Zŝ-ݫ/8RU,(<0iϼ?D;KqeRP*B 7KWvp̰ؕT%؏<T`.4fF,8,/P% ҜkA J^mߖŮW%sy3DQ9sd6a'"+D*[oP"b\FħTlXH qYakp}fSf G )wc7+r)Mڢb KX] ya&4_]՛ aWCGHrLO(7ŸEW2\(VML vA"T45־%LK+9\鮲!AM.x"5):N1 [ v$mEthgXOXd;KL5 r~iZ8*Ð*=ʋ~#DW"3Ys$[kY{"8++;o96)*13/g0MV3̸(xA0h*^tOO"V| pQB3"Ζ ijޓʈO1:W9]MʇyOHRPJ j튅klW8ex`+\yZɘ@yJ `0s6^L ZE0][d8 |Y&^(Pd ʕFM[K0@ıe_뾑^/L`KKG}gP@eiFdeO^vo-CRA F5ӭzC6L|0W>LF%wN" T5B̿X)~%M9Jx7)3q"CeVN.,5qXkuqkVVgbj:7=yh3 +YC뼯H^)@8j$ &Jp۝̰r@qϩ7cqd`&"?MܪTcO#r+;iuR9Ȩ#s0k+5JӆLacmY^X) Zd^͜ʬ0Ua4!tu?MJR#p6`xVT۫VU`0MEsؔN)L P6!a+ \wA/W3B]"U͸|BKKtUrVz?]<@by7ӂ-eߘ5 %5WɼӖ\>qYq~\VzL.Rm(͡4/ >Ie^(XIG%`lRk|GWc_(0:~))7XQ9_ Ls f厠Z5ǘs=w.a)v?' >hf-(-0d;ϤY*لS5uP~aX]3R K--Qfc"8B/ 5|Sfpp&WPNI:L@ԓJr_V9uK{)7U`ԻSq>OUg%LepկzC&WAPe[)T+PJTqcIC65~gβmyk(zV[ΥHq%^-|)Hu,Kʫ-֯1!XcD-c*]^XaGw@Iml[2"lO0 h2xY +YPVեi bnX9ŀo81Yc> =8%W:ћ?iJ^#(XX}lѯ_ĵ74 lֳKjmAhqUĤ~ĺW _&h$e gF#*J kT);DkUn{lI+1/&!J"d/kCNᆉYw;V[FE, WjiL$NzDoE_TRgPjXP@Vc$WiI5a3o2e˄Ae0-k7-+i]I~1[+2Q޶BjRd }9f^:djO']"g7r]FqNaįq/%R70ڇ*@FY6ܔE'(_SY~gJ$ JJa 7^0htt`9 Д2k_XU{3./aYU&,R+Ŵ.IN΍ftT/#﹃'bQҶѓHE&kE\dL2ʘ# b/$Db[=w ѫ.n7B=%VBḶGg9|rtzL^gaz?DjVaFHajU`_Vko#<2KHO,ɞ%а~}ٔؖ` 4(lrvt8@C_NLxZOLjZ06R(&wH-Nzq(t#$f%Rc3C=&`˕N" `(⨚\ fVE N#ec1jK@4%@8d/dC`!fUD (5O2ʇct-8k]حN~Ve"^?k0*c}eLeu W*U˶JRw,MNJE}ϡj*2XT-QymnwfkRbRsq&ȡ `L8~Ɏ1F>F `$Vx.hyc-M~= b=w}q _OHKK!5}'[ P,ɧ~]$iR_kU/,_Z M|4ҵ,'jlgw|Լc5ĵ(^ d^' ^yLh]p^jkeі|lͧU#yr.`ʭ*K:K")PrJ[U؃iOįͫ,&4:^y 紻.W~OȔ}qݒ.D)K*u+!Q,{VeoGL(]T+ Ff(yHmp4h*q7nR*v_],Ϭ'q/ ZiQVz̷[#jj1iBXN Bn^5pJa~HѨ%y>=}Q'Uu'6XuXr`^W>%o_YM)܂]:k E(]*ڡ~f@DU[zb}aԳQQwi01 R^`Žl>DeeY#SjuȯSG,Uhx{|?UH>(U&/'ٳ -u0~F2T#lB-:b6jo,a?k􋮔kqkww:~̲1UoX Y.%z=ҩqat,Z*_ \P@T>42IOIrpG\.+Dcz!^j@]K+F+eDT05ObL -A*9BPA ,rBJVp`G>]8WOEW*Z:NV. G$tm9&$rR``2~:fu-PDq.KPT@s Vʭ˂3N}F@_q *1a3ct9HX~&FWaTqnmǤmu׷,q@ ܗ%t?앇.9r..B[2VuEx0%:qbU&NOU5l26}wnSc'H8l=t6TRhX$K`9E8Ԍd.j'~k ]- %.o2)j"V.xs:rH QXX+tیn!5,Az D@U  p [ PRd yp*/]& #njkʭbWƯdԫKUCFY11'tzs+߬pRJlU]J'*5r&!6JRK*Kxū+ng2P}zCf ӿ00}ADfb,T['P{H>эoL>A C@T)z͝ZV~mX@x2S0xo ua}ɼoQ=.UG)(Zk?[q/:1"$nTŀ^~zW]:ࠚ{D4+E]=%uT8kP4<ĚW*u7ŇM5CN :T̺c JԱk2È%SJ-X@4YtBiw)ŇopV^ПQei2ܪ[2WHX%bxo8ot\J87QoE͸"5`[]EFPk89˗_1,m[̰M싧NUj80,B_bħ. -Ǚ-<@F3 dUxn 6UzBf`t޼·fc6y31+F-+s)Ɇ1p:b`-\6*cQRgDD{?o_ D~+˺+EgJV>ī4/@z*v"!g[Q %-YP+w6gLbqedlѷ04( 3g)ܭpx q6q|6SQ'5~ X&e&7EơRw|8|  mc"ݯx͊ll%>^.RfUjXݼ4,dFxjw_Hr}%ޏ.؃,扏TЃS(HU5WUxDMӋ7)F_\7xf,Yg̩Dd Pj;ITInƉtH(_kbVe)+h]C`qw$7Pٺ\0eƹD`(.syCWbN/Q~56u>u&,Z 5xZ{0^>ﴧl@IuezƱOXa+q.u\b+]5 \Q87>r6p [WKl4+DifP]krXv@ > _ڈi=eJ\CqH\u.NY+*>O̯NL~fw:K*=Pyb^R(/ʽo2ooIҷ>;ݛ+/ ̗s1]bS"cM3wg1pkDQ`\ܳL;le2BKnwToW4\b W07bg\u~f_<ž>x. :p@Qj#U4<3(Tl\ ˵tXb= \Or]7kkyc. ׯˆ(7ȗܹo-}NW>}j-zsW-z?h+9\K6Rm|W[j5t.~!qrcψc(IeGP" % e\GBQaetp,eE.B995.3U7Ի+@ *EZ{+cd,-X1YwOܠuw*WdUBKbq-ŴW!).*U0t.̙ S,V[Kss :L}Ro JT,h}xٌT+/ouk-nlM}c_Joq #0T.epמ˰n vn\ਯɿk 梱%^b!Gw/k(i|5&iԾ7=fAo`㧤jU{̳@ƍ? HJ`ӤB+~PWi*jy֤~HYsu4OǒPPo8 0-)3 kZ;@_v 4cOn엚)U3ؚ1Eem9T\X63.p1po:!g5vM7wz3ԩaR1V헧ya4 n7 Ш,j{6_Z8qbWw,hkdA=)$__'T)NtFu!׃yP? /9GRv>z}'VD-3PUW/7 tǀvnR=}lҁ=Sl<4ޯr$Y1*mOX-~ѝLi~%$" 8`57-U+O4dvC-ea8䶾"Hp`y]0FB2pr F|meUa7䣝U-_O("b?>%sYV#T1SĽ Zp=V6~?| Eec[L܅+0-?+ן,=۫s&jɨM!u\TIXK0bUPxG2,l><be ޥ&}" !c5]nitjZ*tmgGfL%XN+Cn)}-4Vz_1KbR3 h\ʜ# %*(ssDz%ץȱЪgKsi=D\xɄU똬Z#*.s@Qk-l%k LX@*1)Ү/ G pAR@ @B @ `@ $ рE  #\Zd=C'ē8,Z| D/yV H4QpS[?)6#()*kߕ d<LJّ1S ֖'UeFD"Ze)Ѝ ?y43E=/`ҙ挾mw`Њ2`r3QD`4墂|1ITZ fw&:ʐkdj$&Wdfe@`l/Ѭ͊x \+KϥJ:87/NfW\S,iB3:^aAz-ZB)1p(ZЅ2+9cahQ0"Q i!] (Z4:s9,=F 4bx֞a^_}9F3hy͠1/W  d00]4 3v9a+mB% P6/ ೸plw{Qh"&Woǡ _4E=>"H:>V01}W(Ŝ L,ŀ2~ FE!%mC^L|S7p 5iK!`XkPn .C 0- 񨕓QY_`({ PCwW#F+f097a5FCPW([7 1'605!@a,^?߉妀`x`\F/# fm Mn9- ,q30R! W-+.Ee3VEL[FĀlSJw\|_2e&d>xzThz9=LC'U@by@/#/fiD ˜)r -r,珈$6-RkPFAhF?C+j 2#dJ7w/DAd ? һ!Vur^{T*#EGM/t-f~MYhDNG'GCP#9 A}&ǰ Tq8b7'`+z]Z$n܊ > 8 qq7B+D&~5f}Z3 t(&퍑 -@b:y$N#O\ |) ))aZ `z;V$wJ`umCr!{ {WŖS'V\#k@XӜaK4H^ąBɸSűZ o2-_0 p=U7P#:DQ1: 3/A|ElPf$Sncerd,'@Fb_d:y,x1M2JWU; T9\M&Rl.TD/[S Pk`1b4$0\)4nP&+1A1W2 qСm0я0G$?1BfMsо14;RݥK/pҺѸ1`S* Y m? Fa~s~ޖYE@/U/I;ơpM45 z%j 2W͑.yV VB(8E#vi#ă2D(d:2 Xކ R5RHe n^ @1!7QA^>}|N;4Bg#C&7@>â, E$)Z~!Xof} ׁ UlrH2ĀML/̅- 1i-y';$7}_"21IjMa}fm2ގ;LJ?-nWȿ>pZO|2|sw5Fك؅ŘL% ̔@KK| 2(=/lX}_k h H6CR*8x~8Q ]A57=ADi;b3.6MBɣ' (ZauJ U H@TRfS@LA05 .%ȃf e(z&sV4Jf[& 8xZIJ ;kDU2#AW#hRQ& px&onǨOZ=N\ۘ, {y2C+rB A^}e!9*:?V RW d]~bXzBZRU ޥJ'zT Rz(sY7o1$9gHJpJB@nHDg#x+p!JVQ?ߢ#c&#_֢ !K]#C"NEJqBІM_(ad::OC% )x/=t& +P7K;V ) \8YYH3UkT ģl8Ax#C 5`s1 @:?$(\n!_B\;'1#apO'FK4k%`Acm GlQP^ci̘0`[JVj>'ymgS3 eH<L#hAExױD*,~d c * 3-f`{#]cR v 4偩5ɞ.D ۈ dbu4xzP:ŝ6wC]o7Tr3$8J \1J^rFLe`hA`QKf2+G:xq$=#]m+*@827 0LX /Bk ;1-iiL= A&MƫD*ڴ#K"̫&w0kc~ *qTk ~8M- ۆ%H;v 8.?Kv6@Z0AE2hZt@h!T E&nO3etOd^f N@kH8iPyzJa3ZbY␖+’l0`%M S.$gY%B6fA@Vŋ ő J87 :dX!Ì6, { P*UҎk*'ĹqӢ%?Bsi?,%Vq1q]G/(\ϤS328E ?NF5Fb}Qp\MO!dH/J+Y|I.D>e%gX޹xoQFKvxi>$bD(UJkd/|CTڊu&!`U^騾#/ ¡ad_TTegvR #Uxt[T؄5 Q +,|h*W S+ȕ'YBLm{?pK 藭b5L 58Rh*1[C ':l{29p&) dJ @Njٓ *AK Ҵq*g&ZN M 3(rIY |!l;CbJTo#f|D,%[3qQ)h@@GDwyp$?f8fyK}YZL,p(?!N6j2&1^Rsq"Ό-a, fzp**S!U=(I./<ǺvAI>@XAH|gq#kvI]BV50 Fx0#E 00xxNQ5K*_ _-ԈU(F%ec yCd 94fMo >2T6<#d@טjTN qXF%@9FA]#˴U>f b_p25'Cc¡-A >ȵgFGy _16l!cLr*K&֡VLXV~ȽL>D?.,;=gҵEpC. 0^U 9Y*ɐL"r7*JLK gE6sR8oh!a4ՉFv jSP(l$Rҹ+T0T 9ԍoɆ!BP3(002,\nDe.*:u/D+7(#1kV v@9hEE.{Xq6дRa>2Ή1/ T6hP!  McipJHrgz/:/ntiv0!0wN 7^m. [$HW(\V^Ⴀ\FʆIW#,/09(/tH"k&|,N 7xB͹_R0QRt E !`{b_}?@D $4A%CM0@RWB+P ihb"KC e. op >60y*Ѕ_PWemXOd+(0~}3)1yz579rǑ!/B5.ed1Ph"⥉r0;,7Fc*u!AB1f(C˞U@#=NljS.LT9N}zIr;ܩи}'S6죄(ѿ' i 1gs%̧ᣓl"+W;0Oyh)pD\I ǢRaKQc0l{!2}(&_dindmF6ΓHb6wH2kX\`2 bC_ a*1mÔvVZ0b AxB G ?bsFbgw.>R^` ۳Rph> +DT_tC5Y8)"PJ`Qaj8[~1H!>]C(KĶf;%Z͙q~$x*z29 E@[Bx! AY/8hXЀIM L9)Ћ %Q%-9Z2,̖{ Ն!LlįRTE tВ҈W0!]QTц@$7p-6F0?vҵzF^E@^9x"\LE03~"Ҡ@_nVgGl̼#W~}E>R]}4zJƱƠji/= e|[,T[abʳfp*L+Aي$ͩ/b¶TTxFq<ӶyHxQ )Eҗa⡀0jF@D0| 'N-&­yRkd56kIx|SBMWuV&?yQ_N%'Kaw~6Ig{C(ou6 ji ɿR\żs ϔ ?zKQE3'Vb,U'}!']jk4-=*qK5CrXE 6Qu31r˱Ȋ@KT+vL%tq^&B&> #OHAL0K h 0, й#CB4ݲ#mw7[༊~?*r9HspO)~ N >yzTL. ߸ qx@; çdcP80D'غ9;6QnWC6-ziuϖLv>^;tr[H(\(]($J\2+Fr  Cmȳn4i6١$ybzC{eѭ>qcI12t\'$ظY  |ueBy8_ Qʧ,Qp_YIU lqtiU .No aݓ3Ca?҂!`'ȴd3^s2Rr{ pHKe؎n;qG,yTRG<eLJHe]'0q꺬Գ%GD f6$Gd% f7ά{su73rAUظ+55Z|h>?a WTMb-XfSɎʕ kݜԽF!)KtH!d:*(ckvHd= > Default page
  • Your IP: 216.73.216.84
  • Server IP: 13.204.207.56
  • Server: Linux ip-172-31-43-243 5.15.0-1084-aws #91~20.04.1-Ubuntu SMP Fri May 2 06:59:36 UTC 2025 x86_64
  • Server Software: Apache/2.4.41 (Ubuntu)
  • PHP Version: 7.4.33
  • Buat File | Buat Folder
Edit File: Privileges.php
'; return array($title, $export); } /** * Get HTML for display Add userfieldset * * @param string $db the database * @param string $table the table name * * @return string html output */ public static function getAddUserHtmlFieldset($db = '', $table = '') { if (!$GLOBALS['is_createuser']) { return ''; } $rel_params = array(); $url_params = array( 'adduser' => 1 ); if (!empty($db)) { $url_params['dbname'] = $rel_params['checkprivsdb'] = $db; } if (!empty($table)) { $url_params['tablename'] = $rel_params['checkprivstable'] = $table; } return Template::get('privileges/add_user_fieldset') ->render( array( 'url_params' => $url_params, 'rel_params' => $rel_params ) ); } /** * Get HTML header for display User's properties * * @param boolean $dbname_is_wildcard whether database name is wildcard or not * @param string $url_dbname url database name that urlencode() string * @param string $dbname database name * @param string $username username * @param string $hostname host name * @param string $entity_name entity (table or routine) name * @param string $entity_type optional, type of entity ('table' or 'routine') * * @return string $html_output */ public static function getHtmlHeaderForUserProperties( $dbname_is_wildcard, $url_dbname, $dbname, $username, $hostname, $entity_name, $entity_type='table' ) { $html_output = '

' . "\n" . Util::getIcon('b_usredit') . __('Edit privileges:') . ' ' . __('User account'); if (! empty($dbname)) { $html_output .= ' \'' . htmlspecialchars($username) . '\'@\'' . htmlspecialchars($hostname) . '\'' . "\n"; $html_output .= ' - '; $html_output .= ($dbname_is_wildcard || is_array($dbname) && count($dbname) > 1) ? __('Databases') : __('Database'); if (! empty($entity_name) && $entity_type === 'table') { $html_output .= ' ' . htmlspecialchars($dbname) . ''; $html_output .= ' - ' . __('Table') . ' ' . htmlspecialchars($entity_name) . ''; } elseif (! empty($entity_name)) { $html_output .= ' ' . htmlspecialchars($dbname) . ''; $html_output .= ' - ' . __('Routine') . ' ' . htmlspecialchars($entity_name) . ''; } else { if (! is_array($dbname)) { $dbname = array($dbname); } $html_output .= ' ' . htmlspecialchars(implode(', ', $dbname)) . ''; } } else { $html_output .= ' \'' . htmlspecialchars($username) . '\'@\'' . htmlspecialchars($hostname) . '\'' . "\n"; } $html_output .= '

' . "\n"; $cur_user = $GLOBALS['dbi']->getCurrentUser(); $user = $username . '@' . $hostname; // Add a short notice for the user // to remind him that he is editing his own privileges if ($user === $cur_user) { $html_output .= Message::notice( __( 'Note: You are attempting to edit privileges of the ' . 'user with which you are currently logged in.' ) )->getDisplay(); } return $html_output; } /** * Get HTML snippet for display user overview page * * @param string $pmaThemeImage a image source link * @param string $text_dir text directory * * @return string $html_output */ public static function getHtmlForUserOverview($pmaThemeImage, $text_dir) { $html_output = '

' . "\n" . Util::getIcon('b_usrlist') . __('User accounts overview') . "\n" . '

' . "\n"; $password_column = 'Password'; $server_type = Util::getServerType(); $serverVersion = $GLOBALS['dbi']->getVersion(); if (($server_type == 'MySQL' || $server_type == 'Percona Server') && $serverVersion >= 50706 ) { $password_column = 'authentication_string'; } // $sql_query is for the initial-filtered, // $sql_query_all is for counting the total no. of users $sql_query = $sql_query_all = 'SELECT *,' . " IF(`" . $password_column . "` = _latin1 '', 'N', 'Y') AS 'Password'" . ' FROM `mysql`.`user`'; $sql_query .= (isset($_GET['initial']) ? self::rangeOfUsers($_GET['initial']) : ''); $sql_query .= ' ORDER BY `User` ASC, `Host` ASC;'; $sql_query_all .= ' ;'; $res = $GLOBALS['dbi']->tryQuery( $sql_query, DatabaseInterface::CONNECT_USER, DatabaseInterface::QUERY_STORE ); $res_all = $GLOBALS['dbi']->tryQuery( $sql_query_all, DatabaseInterface::CONNECT_USER, DatabaseInterface::QUERY_STORE ); if (! $res) { // the query failed! This may have two reasons: // - the user does not have enough privileges // - the privilege tables use a structure of an earlier version. // so let's try a more simple query $GLOBALS['dbi']->freeResult($res); $GLOBALS['dbi']->freeResult($res_all); $sql_query = 'SELECT * FROM `mysql`.`user`'; $res = $GLOBALS['dbi']->tryQuery( $sql_query, DatabaseInterface::CONNECT_USER, DatabaseInterface::QUERY_STORE ); if (! $res) { $html_output .= self::getHtmlForViewUsersError(); $html_output .= self::getAddUserHtmlFieldset(); } else { // This message is hardcoded because I will replace it by // a automatic repair feature soon. $raw = 'Your privilege table structure seems to be older than' . ' this MySQL version!
' . 'Please run the mysql_upgrade command' . ' that should be included in your MySQL server distribution' . ' to solve this problem!'; $html_output .= Message::rawError($raw)->getDisplay(); } $GLOBALS['dbi']->freeResult($res); } else { $db_rights = self::getDbRightsForUserOverview(); // for all initials, even non A-Z $array_initials = array(); foreach ($db_rights as $right) { foreach ($right as $account) { if (empty($account['User']) && $account['Host'] == 'localhost') { $html_output .= Message::notice( __( 'A user account allowing any user from localhost to ' . 'connect is present. This will prevent other users ' . 'from connecting if the host part of their account ' . 'allows a connection from any (%) host.' ) . Util::showMySQLDocu('problems-connecting') )->getDisplay(); break 2; } } } /** * Displays the initials * Also not necessary if there is less than 20 privileges */ if ($GLOBALS['dbi']->numRows($res_all) > 20) { $html_output .= self::getHtmlForInitials($array_initials); } /** * Display the user overview * (if less than 50 users, display them immediately) */ if (isset($_GET['initial']) || isset($_GET['showall']) || $GLOBALS['dbi']->numRows($res) < 50 ) { $html_output .= self::getUsersOverview( $res, $db_rights, $pmaThemeImage, $text_dir ); } else { $html_output .= self::getAddUserHtmlFieldset(); } // end if (display overview) $response = Response::getInstance(); if (! $response->isAjax() || ! empty($_REQUEST['ajax_page_request']) ) { if ($GLOBALS['is_reload_priv']) { $flushnote = new Message( __( 'Note: phpMyAdmin gets the users’ privileges directly ' . 'from MySQL’s privilege tables. The content of these ' . 'tables may differ from the privileges the server uses, ' . 'if they have been changed manually. In this case, ' . 'you should %sreload the privileges%s before you continue.' ), Message::NOTICE ); $flushnote->addParamHtml( '' ); $flushnote->addParamHtml(''); } else { $flushnote = new Message( __( 'Note: phpMyAdmin gets the users’ privileges directly ' . 'from MySQL’s privilege tables. The content of these ' . 'tables may differ from the privileges the server uses, ' . 'if they have been changed manually. In this case, ' . 'the privileges have to be reloaded but currently, you ' . 'don\'t have the RELOAD privilege.' ) . Util::showMySQLDocu( 'privileges-provided', false, 'priv_reload' ), Message::NOTICE ); } $html_output .= $flushnote->getDisplay(); } } return $html_output; } /** * Get HTML snippet for display user properties * * @param boolean $dbname_is_wildcard whether database name is wildcard or not * @param string $url_dbname url database name that urlencode() string * @param string $username username * @param string $hostname host name * @param string $dbname database name * @param string $tablename table name * * @return string $html_output */ public static function getHtmlForUserProperties($dbname_is_wildcard, $url_dbname, $username, $hostname, $dbname, $tablename ) { $html_output = '
'; $html_output .= self::getHtmlHeaderForUserProperties( $dbname_is_wildcard, $url_dbname, $dbname, $username, $hostname, $tablename, 'table' ); $sql = "SELECT '1' FROM `mysql`.`user`" . " WHERE `User` = '" . $GLOBALS['dbi']->escapeString($username) . "'" . " AND `Host` = '" . $GLOBALS['dbi']->escapeString($hostname) . "';"; $user_does_not_exists = (bool) ! $GLOBALS['dbi']->fetchValue($sql); if ($user_does_not_exists) { $html_output .= Message::error( __('The selected user was not found in the privilege table.') )->getDisplay(); $html_output .= self::getHtmlForLoginInformationFields(); } $_params = array( 'username' => $username, 'hostname' => $hostname, ); if (! is_array($dbname) && strlen($dbname) > 0) { $_params['dbname'] = $dbname; if (strlen($tablename) > 0) { $_params['tablename'] = $tablename; } } else { $_params['dbname'] = $dbname; } $html_output .= '' . "\n"; $html_output .= Url::getHiddenInputs($_params); $html_output .= self::getHtmlToDisplayPrivilegesTable( // If $dbname is an array, pass any one db as all have same privs. Core::ifSetOr($dbname, (is_array($dbname)) ? $dbname[0] : '*', 'length'), Core::ifSetOr($tablename, '*', 'length') ); $html_output .= '' . "\n"; if (! is_array($dbname) && strlen($tablename) === 0 && empty($dbname_is_wildcard) ) { // no table name was given, display all table specific rights // but only if $dbname contains no wildcards if (strlen($dbname) === 0) { $html_output .= self::getHtmlForAllTableSpecificRights( $username, $hostname, 'database' ); } else { // unescape wildcards in dbname at table level $unescaped_db = Util::unescapeMysqlWildcards($dbname); $html_output .= self::getHtmlForAllTableSpecificRights( $username, $hostname, 'table', $unescaped_db ); $html_output .= self::getHtmlForAllTableSpecificRights( $username, $hostname, 'routine', $unescaped_db ); } } // Provide a line with links to the relevant database and table if (! is_array($dbname) && strlen($dbname) > 0 && empty($dbname_is_wildcard)) { $html_output .= self::getLinkToDbAndTable($url_dbname, $dbname, $tablename); } if (! is_array($dbname) && strlen($dbname) === 0 && ! $user_does_not_exists) { //change login information $html_output .= ChangePassword::getHtml( 'edit_other', $username, $hostname ); $html_output .= self::getChangeLoginInformationHtmlForm($username, $hostname); } $html_output .= '
'; return $html_output; } /** * Get queries for Table privileges to change or copy user * * @param string $user_host_condition user host condition to * select relevant table privileges * @param array $queries queries array * @param string $username username * @param string $hostname host name * * @return array $queries */ public static function getTablePrivsQueriesForChangeOrCopyUser($user_host_condition, array $queries, $username, $hostname ) { $res = $GLOBALS['dbi']->query( 'SELECT `Db`, `Table_name`, `Table_priv` FROM `mysql`.`tables_priv`' . $user_host_condition, DatabaseInterface::CONNECT_USER, DatabaseInterface::QUERY_STORE ); while ($row = $GLOBALS['dbi']->fetchAssoc($res)) { $res2 = $GLOBALS['dbi']->query( 'SELECT `Column_name`, `Column_priv`' . ' FROM `mysql`.`columns_priv`' . ' WHERE `User`' . ' = \'' . $GLOBALS['dbi']->escapeString($_POST['old_username']) . "'" . ' AND `Host`' . ' = \'' . $GLOBALS['dbi']->escapeString($_POST['old_username']) . '\'' . ' AND `Db`' . ' = \'' . $GLOBALS['dbi']->escapeString($row['Db']) . "'" . ' AND `Table_name`' . ' = \'' . $GLOBALS['dbi']->escapeString($row['Table_name']) . "'" . ';', DatabaseInterface::CONNECT_USER, DatabaseInterface::QUERY_STORE ); $tmp_privs1 = self::extractPrivInfo($row); $tmp_privs2 = array( 'Select' => array(), 'Insert' => array(), 'Update' => array(), 'References' => array() ); while ($row2 = $GLOBALS['dbi']->fetchAssoc($res2)) { $tmp_array = explode(',', $row2['Column_priv']); if (in_array('Select', $tmp_array)) { $tmp_privs2['Select'][] = $row2['Column_name']; } if (in_array('Insert', $tmp_array)) { $tmp_privs2['Insert'][] = $row2['Column_name']; } if (in_array('Update', $tmp_array)) { $tmp_privs2['Update'][] = $row2['Column_name']; } if (in_array('References', $tmp_array)) { $tmp_privs2['References'][] = $row2['Column_name']; } } if (count($tmp_privs2['Select']) > 0 && ! in_array('SELECT', $tmp_privs1)) { $tmp_privs1[] = 'SELECT (`' . join('`, `', $tmp_privs2['Select']) . '`)'; } if (count($tmp_privs2['Insert']) > 0 && ! in_array('INSERT', $tmp_privs1)) { $tmp_privs1[] = 'INSERT (`' . join('`, `', $tmp_privs2['Insert']) . '`)'; } if (count($tmp_privs2['Update']) > 0 && ! in_array('UPDATE', $tmp_privs1)) { $tmp_privs1[] = 'UPDATE (`' . join('`, `', $tmp_privs2['Update']) . '`)'; } if (count($tmp_privs2['References']) > 0 && ! in_array('REFERENCES', $tmp_privs1) ) { $tmp_privs1[] = 'REFERENCES (`' . join('`, `', $tmp_privs2['References']) . '`)'; } $queries[] = 'GRANT ' . join(', ', $tmp_privs1) . ' ON ' . Util::backquote($row['Db']) . '.' . Util::backquote($row['Table_name']) . ' TO \'' . $GLOBALS['dbi']->escapeString($username) . '\'@\'' . $GLOBALS['dbi']->escapeString($hostname) . '\'' . (in_array('Grant', explode(',', $row['Table_priv'])) ? ' WITH GRANT OPTION;' : ';'); } return $queries; } /** * Get queries for database specific privileges for change or copy user * * @param array $queries queries array with string * @param string $username username * @param string $hostname host name * * @return array $queries */ public static function getDbSpecificPrivsQueriesForChangeOrCopyUser( array $queries, $username, $hostname ) { $user_host_condition = ' WHERE `User`' . ' = \'' . $GLOBALS['dbi']->escapeString($_POST['old_username']) . "'" . ' AND `Host`' . ' = \'' . $GLOBALS['dbi']->escapeString($_POST['old_hostname']) . '\';'; $res = $GLOBALS['dbi']->query( 'SELECT * FROM `mysql`.`db`' . $user_host_condition ); while ($row = $GLOBALS['dbi']->fetchAssoc($res)) { $queries[] = 'GRANT ' . join(', ', self::extractPrivInfo($row)) . ' ON ' . Util::backquote($row['Db']) . '.*' . ' TO \'' . $GLOBALS['dbi']->escapeString($username) . '\'@\'' . $GLOBALS['dbi']->escapeString($hostname) . '\'' . ($row['Grant_priv'] == 'Y' ? ' WITH GRANT OPTION;' : ';'); } $GLOBALS['dbi']->freeResult($res); $queries = self::getTablePrivsQueriesForChangeOrCopyUser( $user_host_condition, $queries, $username, $hostname ); return $queries; } /** * Prepares queries for adding users and * also create database and return query and message * * @param boolean $_error whether user create or not * @param string $real_sql_query SQL query for add a user * @param string $sql_query SQL query to be displayed * @param string $username username * @param string $hostname host name * @param string $dbname database name * @param string $alter_real_sql_query SQL query for ALTER USER * @param string $alter_sql_query SQL query for ALTER USER to be displayed * * @return array $sql_query, $message */ public static function addUserAndCreateDatabase( $_error, $real_sql_query, $sql_query, $username, $hostname, $dbname, $alter_real_sql_query, $alter_sql_query ) { if ($_error || (!empty($real_sql_query) && !$GLOBALS['dbi']->tryQuery($real_sql_query)) ) { $_POST['createdb-1'] = $_POST['createdb-2'] = $_POST['createdb-3'] = null; $message = Message::rawError($GLOBALS['dbi']->getError()); } elseif ($alter_real_sql_query !== '' && !$GLOBALS['dbi']->tryQuery($alter_real_sql_query)) { $_POST['createdb-1'] = $_POST['createdb-2'] = $_POST['createdb-3'] = null; $message = Message::rawError($GLOBALS['dbi']->getError()); } else { $sql_query .= $alter_sql_query; $message = Message::success(__('You have added a new user.')); } if (isset($_POST['createdb-1'])) { // Create database with same name and grant all privileges $q = 'CREATE DATABASE IF NOT EXISTS ' . Util::backquote( $GLOBALS['dbi']->escapeString($username) ) . ';'; $sql_query .= $q; if (! $GLOBALS['dbi']->tryQuery($q)) { $message = Message::rawError($GLOBALS['dbi']->getError()); } /** * Reload the navigation */ $GLOBALS['reload'] = true; $GLOBALS['db'] = $username; $q = 'GRANT ALL PRIVILEGES ON ' . Util::backquote( Util::escapeMysqlWildcards( $GLOBALS['dbi']->escapeString($username) ) ) . '.* TO \'' . $GLOBALS['dbi']->escapeString($username) . '\'@\'' . $GLOBALS['dbi']->escapeString($hostname) . '\';'; $sql_query .= $q; if (! $GLOBALS['dbi']->tryQuery($q)) { $message = Message::rawError($GLOBALS['dbi']->getError()); } } if (isset($_POST['createdb-2'])) { // Grant all privileges on wildcard name (username\_%) $q = 'GRANT ALL PRIVILEGES ON ' . Util::backquote( Util::escapeMysqlWildcards( $GLOBALS['dbi']->escapeString($username) ) . '\_%' ) . '.* TO \'' . $GLOBALS['dbi']->escapeString($username) . '\'@\'' . $GLOBALS['dbi']->escapeString($hostname) . '\';'; $sql_query .= $q; if (! $GLOBALS['dbi']->tryQuery($q)) { $message = Message::rawError($GLOBALS['dbi']->getError()); } } if (isset($_POST['createdb-3'])) { // Grant all privileges on the specified database to the new user $q = 'GRANT ALL PRIVILEGES ON ' . Util::backquote( $GLOBALS['dbi']->escapeString($dbname) ) . '.* TO \'' . $GLOBALS['dbi']->escapeString($username) . '\'@\'' . $GLOBALS['dbi']->escapeString($hostname) . '\';'; $sql_query .= $q; if (! $GLOBALS['dbi']->tryQuery($q)) { $message = Message::rawError($GLOBALS['dbi']->getError()); } } return array($sql_query, $message); } /** * Get the hashed string for password * * @param string $password password * * @return string $hashedPassword */ public static function getHashedPassword($password) { $password = $GLOBALS['dbi']->escapeString($password); $result = $GLOBALS['dbi']->fetchSingleRow( "SELECT PASSWORD('" . $password . "') AS `password`;" ); $hashedPassword = $result['password']; return $hashedPassword; } /** * Check if MariaDB's 'simple_password_check' * OR 'cracklib_password_check' is ACTIVE * * @return boolean if atleast one of the plugins is ACTIVE */ public static function checkIfMariaDBPwdCheckPluginActive() { $serverVersion = $GLOBALS['dbi']->getVersion(); if (!(Util::getServerType() == 'MariaDB' && $serverVersion >= 100002)) { return false; } $result = $GLOBALS['dbi']->tryQuery( 'SHOW PLUGINS SONAME LIKE \'%_password_check%\'' ); /* Plugins are not working, for example directory does not exists */ if ($result === false) { return false; } while ($row = $GLOBALS['dbi']->fetchAssoc($result)) { if ($row['Status'] === 'ACTIVE') { return true; } } return false; } /** * Get SQL queries for Display and Add user * * @param string $username username * @param string $hostname host name * @param string $password password * * @return array ($create_user_real, $create_user_show, $real_sql_query, $sql_query * $password_set_real, $password_set_show, $alter_real_sql_query, $alter_sql_query) */ public static function getSqlQueriesForDisplayAndAddUser($username, $hostname, $password) { $slashedUsername = $GLOBALS['dbi']->escapeString($username); $slashedHostname = $GLOBALS['dbi']->escapeString($hostname); $slashedPassword = $GLOBALS['dbi']->escapeString($password); $serverType = Util::getServerType(); $serverVersion = $GLOBALS['dbi']->getVersion(); $create_user_stmt = sprintf( 'CREATE USER \'%s\'@\'%s\'', $slashedUsername, $slashedHostname ); $isMariaDBPwdPluginActive = self::checkIfMariaDBPwdCheckPluginActive(); // See https://github.com/phpmyadmin/phpmyadmin/pull/11560#issuecomment-147158219 // for details regarding details of syntax usage for various versions // 'IDENTIFIED WITH auth_plugin' // is supported by MySQL 5.5.7+ if (($serverType == 'MySQL' || $serverType == 'Percona Server') && $serverVersion >= 50507 && isset($_POST['authentication_plugin']) ) { $create_user_stmt .= ' IDENTIFIED WITH ' . $_POST['authentication_plugin']; } // 'IDENTIFIED VIA auth_plugin' // is supported by MariaDB 5.2+ if ($serverType == 'MariaDB' && $serverVersion >= 50200 && isset($_POST['authentication_plugin']) && ! $isMariaDBPwdPluginActive ) { $create_user_stmt .= ' IDENTIFIED VIA ' . $_POST['authentication_plugin']; } $create_user_real = $create_user_show = $create_user_stmt; $password_set_stmt = 'SET PASSWORD FOR \'%s\'@\'%s\' = \'%s\''; $password_set_show = sprintf( $password_set_stmt, $slashedUsername, $slashedHostname, '***' ); $sql_query_stmt = sprintf( 'GRANT %s ON *.* TO \'%s\'@\'%s\'', join(', ', self::extractPrivInfo()), $slashedUsername, $slashedHostname ); $real_sql_query = $sql_query = $sql_query_stmt; // Set the proper hashing method if (isset($_POST['authentication_plugin'])) { self::setProperPasswordHashing( $_POST['authentication_plugin'] ); } // Use 'CREATE USER ... WITH ... AS ..' syntax for // newer MySQL versions // and 'CREATE USER ... VIA .. USING ..' syntax for // newer MariaDB versions if ((($serverType == 'MySQL' || $serverType == 'Percona Server') && $serverVersion >= 50706) || ($serverType == 'MariaDB' && $serverVersion >= 50200) ) { $password_set_real = null; // Required for binding '%' with '%s' $create_user_stmt = str_replace( '%', '%%', $create_user_stmt ); // MariaDB uses 'USING' whereas MySQL uses 'AS' // but MariaDB with validation plugin needs cleartext password if ($serverType == 'MariaDB' && ! $isMariaDBPwdPluginActive ) { $create_user_stmt .= ' USING \'%s\''; } elseif ($serverType == 'MariaDB') { $create_user_stmt .= ' IDENTIFIED BY \'%s\''; } elseif (($serverType == 'MySQL' || $serverType == 'Percona Server') && $serverVersion >= 80011) { $create_user_stmt .= ' BY \'%s\''; } else { $create_user_stmt .= ' AS \'%s\''; } if ($_POST['pred_password'] == 'keep') { $create_user_real = sprintf( $create_user_stmt, $slashedPassword ); $create_user_show = sprintf( $create_user_stmt, '***' ); } elseif ($_POST['pred_password'] == 'none') { $create_user_real = sprintf( $create_user_stmt, null ); $create_user_show = sprintf( $create_user_stmt, '***' ); } else { if (! (($serverType == 'MariaDB' && $isMariaDBPwdPluginActive) || ($serverType == 'MySQL' || $serverType == 'Percona Server') && $serverVersion >= 80011)) { $hashedPassword = self::getHashedPassword($_POST['pma_pw']); } else { // MariaDB with validation plugin needs cleartext password $hashedPassword = $_POST['pma_pw']; } $create_user_real = sprintf( $create_user_stmt, $hashedPassword ); $create_user_show = sprintf( $create_user_stmt, '***' ); } } else { // Use 'SET PASSWORD' syntax for pre-5.7.6 MySQL versions // and pre-5.2.0 MariaDB versions if ($_POST['pred_password'] == 'keep') { $password_set_real = sprintf( $password_set_stmt, $slashedUsername, $slashedHostname, $slashedPassword ); } elseif ($_POST['pred_password'] == 'none') { $password_set_real = sprintf( $password_set_stmt, $slashedUsername, $slashedHostname, null ); } else { $hashedPassword = self::getHashedPassword($_POST['pma_pw']); $password_set_real = sprintf( $password_set_stmt, $slashedUsername, $slashedHostname, $hashedPassword ); } } $alter_real_sql_query = ''; $alter_sql_query = ''; if (($serverType == 'MySQL' || $serverType == 'Percona Server') && $serverVersion >= 80011) { $sql_query_stmt = ''; if ((isset($_POST['Grant_priv']) && $_POST['Grant_priv'] == 'Y') || (isset($GLOBALS['Grant_priv']) && $GLOBALS['Grant_priv'] == 'Y') ) { $sql_query_stmt = ' WITH GRANT OPTION'; } $real_sql_query .= $sql_query_stmt; $sql_query .= $sql_query_stmt; $alter_sql_query_stmt = sprintf( 'ALTER USER \'%s\'@\'%s\'', $slashedUsername, $slashedHostname ); $alter_real_sql_query = $alter_sql_query_stmt; $alter_sql_query = $alter_sql_query_stmt; } // add REQUIRE clause $require_clause = self::getRequireClause(); $with_clause = self::getWithClauseForAddUserAndUpdatePrivs(); if (($serverType == 'MySQL' || $serverType == 'Percona Server') && $serverVersion >= 80011) { $alter_real_sql_query .= $require_clause; $alter_sql_query .= $require_clause; $alter_real_sql_query .= $with_clause; $alter_sql_query .= $with_clause; } else { $real_sql_query .= $require_clause; $sql_query .= $require_clause; $real_sql_query .= $with_clause; $sql_query .= $with_clause; } if (isset($create_user_real)) { $create_user_real .= ';'; $create_user_show .= ';'; } if ($alter_real_sql_query !== '') { $alter_real_sql_query .= ';'; $alter_sql_query .= ';'; } $real_sql_query .= ';'; $sql_query .= ';'; // No Global GRANT_OPTION privilege if (!$GLOBALS['is_grantuser']) { $real_sql_query = ''; $sql_query = ''; } // Use 'SET PASSWORD' for pre-5.7.6 MySQL versions // and pre-5.2.0 MariaDB if (($serverType == 'MySQL' && $serverVersion >= 50706) || ($serverType == 'MariaDB' && $serverVersion >= 50200) ) { $password_set_real = null; $password_set_show = null; } else { if ($password_set_real !== null) { $password_set_real .= ";"; } $password_set_show .= ";"; } return array( $create_user_real, $create_user_show, $real_sql_query, $sql_query, $password_set_real, $password_set_show, $alter_real_sql_query, $alter_sql_query ); } /** * Returns the type ('PROCEDURE' or 'FUNCTION') of the routine * * @param string $dbname database * @param string $routineName routine * * @return string type */ public static function getRoutineType($dbname, $routineName) { $routineData = $GLOBALS['dbi']->getRoutines($dbname); foreach ($routineData as $routine) { if ($routine['name'] === $routineName) { return $routine['type']; } } return ''; } }