summaryrefslogtreecommitdiff
path: root/signup/verify
diff options
context:
space:
mode:
authorConnor Thomson <blumatrikz@gmail.com>2026-09-19 17:02:13 -0700
committerConnor Thomson <blumatrikz@gmail.com>2026-09-19 17:02:13 -0700
commit3873cad7baf5d2f63b4399b7bfb0ec4d7d66adb9 (patch)
tree32e2b8c18d08f1b891122b503fc0f45bb16594f8 /signup/verify
parent90aab6db1cd794bd582bd6531b732c39846adae8 (diff)
Add signup and other stuff
Diffstat (limited to 'signup/verify')
-rw-r--r--signup/verify/content.html32
l---------signup/verify/index.php1
-rw-r--r--signup/verify/verify.php96
3 files changed, 129 insertions, 0 deletions
diff --git a/signup/verify/content.html b/signup/verify/content.html
new file mode 100644
index 0000000..2ba116b
--- /dev/null
+++ b/signup/verify/content.html
@@ -0,0 +1,32 @@
+<!--
+ -- GNUfault.org - GNUfault's website
+ -- Copyright (C) 2026 Connor Thomson
+ --
+ -- This program is free software: you can redistribute it and/or modify
+ -- it under the terms of the GNU Affero General Public License as published by
+ -- the Free Software Foundation, either version 3 of the License, or
+ -- (at your option) any later version.
+ --
+ -- This program is distributed in the hope that it will be useful,
+ -- but WITHOUT ANY WARRANTY; without even the implied warranty of
+ -- MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ -- GNU Affero General Public License for more details.
+ --
+ -- You should have received a copy of the GNU Affero General Public License
+ -- along with this program. If not, see <https://www.gnu.org/licenses/>.
+ -->
+
+<h2>Verify your GNUfault.org account</h2>
+<hr>
+<p>To prevent spam, an email was sent to you with a 4-digit code from &lt;<a href="mailto:noreply@gnufault.org">noreply@gnufault.org</a>&gt;.</p>
+<p>The email will most likely go to spam due to me using self-hosted email. If it does, please report it as not spam.</p>
+<p>If you need any help, email me at &lt;<a href="mailto:noreply@gnufault.org">connor@gnufault.org</a>&gt; using the same email you signed up with.</p>
+<br>
+<form class="login" action="verify.php" method="POST">
+ <div class="group">
+ <label for="user">Code:</label>
+ <input class="input" type="text" maxlength="4" id="code" name="code" required>
+ </div>
+
+ <button class="button" type="submit">Send</button>
+</form>
diff --git a/signup/verify/index.php b/signup/verify/index.php
new file mode 120000
index 0000000..3e5d98e
--- /dev/null
+++ b/signup/verify/index.php
@@ -0,0 +1 @@
+../../php/index.php \ No newline at end of file
diff --git a/signup/verify/verify.php b/signup/verify/verify.php
new file mode 100644
index 0000000..e5e729f
--- /dev/null
+++ b/signup/verify/verify.php
@@ -0,0 +1,96 @@
+<?php
+/*
+ * GNUfault.org - GNUfault's website
+ * Copyright (C) 2026 Connor Thomson
+ *
+ * This program is free software: you can redistribute it and/or modify
+ * it under the terms of the GNU Affero General Public License as published by
+ * the Free Software Foundation, either version 3 of the License, or
+ * (at your option) any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * GNU Affero General Public License for more details.
+ *
+ * You should have received a copy of the GNU Affero General Public License
+ * along with this program. If not, see <https://www.gnu.org/licenses/>.
+ */
+
+if ($_SERVER["REQUEST_METHOD"] == "POST") {
+ $code = $_POST['code'];
+ $user_id = $_COOKIE['user_id'] ?? null;
+
+ if (!$user_id) {
+ echo "Not logged in.";
+ exit;
+ }
+
+ $host = '127.0.0.1';
+ $db = 'gnufaultdb';
+ $db_user = 'gnufaultdb_user';
+ $pass = trim(file_get_contents('/etc/gnufault.d/password'));
+
+ $charset = 'utf8mb4';
+ $dsn = "mysql:host=$host;dbname=$db;charset=$charset";
+
+ $options = [
+ PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION,
+ PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC,
+ PDO::ATTR_EMULATE_PREPARES => false,
+ ];
+
+ try {
+ $pdo = new PDO($dsn, $db_user, $pass, $options);
+ } catch (\PDOException $e) {
+ throw new \PDOException($e->getMessage(), (int)$e->getCode());
+ }
+
+ try {
+ $sql = "SELECT verification_code FROM users WHERE id = :id";
+ $stmt = $pdo->prepare($sql);
+
+ $stmt->execute(['id' => $user_id]);
+
+ $user = $stmt->fetch();
+ if (!$user) {
+ echo "User not found.";
+ exit;
+ }
+
+ $real_code = $user['verification_code'];
+ } catch (\PDOException $e) {
+ echo "Error: " . $e->getMessage();
+ exit;
+ }
+
+ if ($real_code == '0001') {
+ echo "Account is already verifed";
+ exit;
+ }
+
+ if ($code != $real_code) {
+ echo "Code is not correct!";
+ exit;
+ }
+
+ try {
+ $sql = "UPDATE users SET verification_code = :code WHERE id = :id";
+ $stmt = $pdo->prepare($sql);
+
+ $stmt->execute([
+ 'code' => '0001',
+ 'id' => $user_id
+ ]);
+
+ if ($stmt->rowCount() == 0) {
+ echo "User not found.";
+ }
+ } catch (\PDOException $e) {
+ echo "Error: " . $e->getMessage();
+ exit;
+ }
+
+ header("Location: /signin");
+}
+?>