implemented session assignment.

This commit is contained in:
Joshua Ashton
2025-02-09 16:53:31 -07:00
parent 6068d8ac45
commit 43b296635e
15 changed files with 524 additions and 0 deletions
+27
View File
@@ -0,0 +1,27 @@
<?php
session_start();
if ($_SESSION['access'] !== true)
header('Location: .');
include_once ('functions.php');
echo '<h1>Account</h1>';
if (isset($_POST['password1']) && isset($_POST['password2'])) {
if ($_POST['password1'] == $_POST['password2']) {
update_user_pw($_POST['password1']);
} else {
$_GET['error'] = true;
}
}
echo '<div id="account-content">
<img src="' . get_user_image() . '" />
<form method="post" id="update-pw">
<input name="password1" type="password" placeholder="New Password">
<input name="password2" type="password" placeholder="Retype New Password">
<button>Submit</button>
</form>
</div>';
?>
+1
View File
@@ -0,0 +1 @@
skinner,gatekeeper||>><<||csm,alien||>><<||dana,skeptic||>><<||fox,believer
+155
View File
@@ -0,0 +1,155 @@
<?php
// Use environment variables for the database password and IP address.
$db_pass = $_ENV['DATABASE_PASSWORD'];
$ip_addr = $_ENV['IP_ADDRESS'];
// Make some constants
if ($_SERVER['HTTP_HOST'] == 'localhost') {
define('HOST', 'localhost');
define('USER', 'root');
define('PASS', $db_pass);
define('DB', 'session');
} else {
define('HOST', $ip_addr);
define('USER', 'root');
define('PASS', $db_pass);
define('DB', 'session');
}
function getHome()
{
echo '<h1>View Confidential Information</h1>';
if ($_SESSION['access'] !== true) {
if (isset($_GET['error']) && $_GET['error'] === true) {
echo '
<div class="card error">
<h5 class="error">Access Denied.</h5>
<p class="error">Invalid username or password.</p>
</div>
';
}
echo '
<form method="post">
<div class="row">
<input name="username" type="text" placeholder="username">
<input name="password" type="password" placeholder="password">
</div>
<div class="row">
<button>Submit</button>
<button type="reset" class="reset">Reset</button>
</div>
</form>
';
} else if (isset($_GET['file']) && isset($_SESSION['access'])) {
echo '
<div class="card success">
<h5 class="success">Access Granted.</h5>
</div>
<form method="get">
<div class="row">
<button name="file" value="includes/fbi.txt">FBI</button>
<button name="file" value="includes/spies.txt">Spies</button>
</div>
</form>
';
fileRead($_GET['file']);
}
}
function fileRead($file)
{
$fs = fopen($file, 'r');
$string = fread($fs, filesize($file));
$values = explode('||>><<||', $string);
echo '
<table>
<tr>
<th>Agent</th>
<th>Codename</th>
</tr>
';
foreach ($values as $v) {
list($a, $b) = explode(',', $v);
echo '
<tr>
<td>' . ucfirst($a) . '</td>
<td>' . ucwords($b) . '</td>
</tr>
';
}
echo '</table>';
}
function authUser()
{
if (isset($_POST['username']) && isset($_POST['password'])) {
$username = $_POST['username'];
$password = $_POST['password'];
// Connect to the DB
$conn = mysqli_connect(HOST, USER, PASS, DB);
// Write a DB query
$sql = 'SELECT password FROM users WHERE username = "' . $username . ' ";';
// Run DB query
$results = mysqli_query($conn, $sql);
if (mysqli_num_rows($results) == 0) {
$_GET['error'] = true;
} else {
$row = mysqli_fetch_assoc($results);
if ($row['password'] == $password) {
$_SESSION['access'] = true;
$_GET['file'] = 'includes/fbi.txt';
$_SESSION['username'] = $username;
} else {
$_GET['error'] = true;
}
}
}
}
function get_user_image()
{
// Connect to the DB
$conn = mysqli_connect(HOST, USER, PASS, DB);
// Write a DB query
$sql = 'SELECT image_path FROM users WHERE username = "' . $_SESSION['username'] . ' ";';
// Run DB query
$results = mysqli_query($conn, $sql);
$row = mysqli_fetch_assoc($results);
return $row['image_path'];
}
function update_user_pw($password)
{
// Connect to the DB
$conn = mysqli_connect(HOST, USER, PASS, DB);
// Write a DB query
$sql = 'UPDATE users SET password = "' . $password . '" WHERE username = "' . $_SESSION['username'] . ' ";';
// Run DB query
$result = mysqli_query($conn, $sql);
if ($result) {
echo '
<div class="card success">
<h5 class="success">Password Updated!</h5>
</div>';
} else {
echo '
<div class="card error">
<h5 class="error">Password update failed!</h5>
<p class="error">Something went wrong in the server...</p>
</div>
';
}
}
?>
+24
View File
@@ -0,0 +1,24 @@
<?php
session_start();
echo '
<form method="get" id="nav">
<button name="page" value="account">Account</button>
<button name="page" value="home">Home</button>
<button name="page" value="video">Video</button>
' . getLogoutButton() . '
</form>
';
function getLogoutButton()
{
if ($_SESSION['access'] === true)
return '<button name="logout" value="true" class="reset">Logout</button>';
}
if (isset($_GET['logout'])) {
$_SESSION['access'] = false;
session_destroy();
header('Location: .');
}
?>
+1
View File
@@ -0,0 +1 @@
dale,the government||>><<||bill,the barber||>><<||hank,the texan||>><<||boomhauer,the marshall
+11
View File
@@ -0,0 +1,11 @@
<?php
session_start();
if ($_SESSION['access'] !== true)
header('Location: .');
echo '<h1>YouTube Video</h1>';
echo '
<iframe width="560" height="315" src="https://www.youtube.com/embed/8BIcAZxFfrc?si=DMccopjQMFNs361I" title="YouTube video player" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen></iframe>
';
?>