login.php 1.5 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455
  1. <?php
  2. /**
  3. * File for the login action.
  4. *
  5. * Implements an action function to be called from the {@see Controller}.
  6. *
  7. * @category Action
  8. */
  9. /**
  10. * Logs the user in.
  11. *
  12. * Reads the POST parameters looking for the following KEYS:
  13. * uname
  14. * password
  15. * If there is a match, it sets cookies and session variables, and
  16. * redirects to the user homepage.
  17. *
  18. * @return int 0 on success, negative values on error.
  19. * @category Action
  20. * @global resource Database connection.
  21. */
  22. function action(){
  23. global $db;
  24. if (!isset($_POST['uname'], $_POST['password'])){
  25. return -1;
  26. }
  27. $uname = SQLite3::escapeString($_POST['uname']);
  28. if (strlen($uname) == 0){
  29. return -2;
  30. }
  31. $password = SQLite3::escapeString($_POST['password']);
  32. if (strlen($password) == 0){
  33. return -3;
  34. }
  35. $password = hash('sha256', $password);
  36. $q = $db->query("SELECT uid FROM player WHERE upper(name) = upper('$uname') AND password = '$password';");
  37. $r = $q->fetchArray(SQLITE3_ASSOC);
  38. if (!$r){
  39. return -4;
  40. }
  41. $uid = $r["uid"];
  42. setcookie("uid", $uid, time() + 5 * 24 * 60 * 60); // 5 Days
  43. session_regenerate_id();
  44. $_SESSION['session'] = true;
  45. $_SESSION['name'] = $uname;
  46. $_SESSION['uid'] = $uid;
  47. header("Location: /$uid/");
  48. die();
  49. return 0;
  50. }
  51. ?>