login.php 1.6 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162
  1. <?php
  2. /**
  3. * File for the login action.
  4. *
  5. * Implements an action function to be called from the {@see Controller}.
  6. *
  7. * @category Action
  8. */
  9. /**
  10. * Logs the user in.
  11. *
  12. * Reads the POST parameters looking for the following KEYS:
  13. * uname
  14. * password
  15. * If there is a match, it sets cookies and session variables, and
  16. * redirects to the user homepage.
  17. *
  18. * @return int 0 on success, negative values on error.
  19. * @category Action
  20. * @global resource Database connection.
  21. */
  22. function action(){
  23. global $db;
  24. if (!isset($_POST['uname'], $_POST['password'])){
  25. error_log("-1");
  26. return -1;
  27. }
  28. $uname = SQLite3::escapeString($_POST['uname']);
  29. if (strlen($uname) == 0){
  30. error_log("-2");
  31. return -2;
  32. }
  33. $password = SQLite3::escapeString($_POST['password']);
  34. if (strlen($password) == 0){
  35. error_log("-3");
  36. return -3;
  37. }
  38. $password = hash('sha256', $password);
  39. error_log("SELECT uid FROM player WHERE upper(name) = upper('$uname') AND password = '$password';");
  40. $q = $db->query("SELECT uid FROM player;");
  41. $r = $q->fetchArray(SQLITE3_ASSOC);
  42. error_log("RET ID: " . $r["uid"]);
  43. if (!$r){
  44. error_log("-4");
  45. return -4;
  46. }
  47. $uid = $r["uid"];
  48. setcookie("uid", $uid, time() + 5 * 24 * 60 * 60); // 5 Days
  49. session_regenerate_id();
  50. $_SESSION['session'] = true;
  51. $_SESSION['name'] = $uname;
  52. $_SESSION['uid'] = $uid;
  53. header("Location: /$uid/");
  54. die();
  55. error_log("0");
  56. return 0;
  57. }
  58. ?>