summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--php/database.php70
-rw-r--r--php/mail.php30
-rwxr-xr-xsignup/signup.php38
-rwxr-xr-xsignup/verify/verify.php30
4 files changed, 111 insertions, 57 deletions
diff --git a/php/database.php b/php/database.php
new file mode 100644
index 0000000..e84ded3
--- /dev/null
+++ b/php/database.php
@@ -0,0 +1,70 @@
+<?php
+/*
+ * GNUfault.org - GNUfault's website
+ * Copyright (C) 2026 Connor Thomson
+ *
+ * This program is free software: you can redistribute it and/or modify
+ * it under the terms of the GNU Affero General Public License as published by
+ * the Free Software Foundation, either version 3 of the License, or
+ * (at your option) any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * GNU Affero General Public License for more details.
+ *
+ * You should have received a copy of the GNU Affero General Public License
+ * along with this program. If not, see <https://www.gnu.org/licenses/>.
+ */
+
+function database(): PDO {
+ static $pdo = null;
+
+ if ($pdo !== null) {
+ return $pdo;
+ }
+
+ $host = '127.0.0.1';
+ $name = 'gnufaultdb';
+ $user = 'gnufaultdb_user';
+ $password = trim(file_get_contents('/etc/gnufault.d/password'));
+ $charset = 'utf8mb4';
+
+ $dsn = "mysql:host=$host;dbname=$name;charset=$charset";
+
+ $options = [
+ PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION,
+ PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC,
+ PDO::ATTR_EMULATE_PREPARES => false
+ ];
+
+ try {
+ $pdo = new PDO($dsn, $user, $password, $options);
+ } catch (\PDOException $e) {
+ throw new \PDOException($e->getMessage(), (int)$e->getCode());
+ }
+
+ return $pdo;
+}
+
+function query(string $sql, array $parameters = []): PDOStatement {
+ $statement = database()->prepare($sql);
+
+ $statement->execute($parameters);
+
+ return $statement;
+}
+
+function fetch_row(string $sql, array $parameters = []): ?array {
+ $row = query($sql, $parameters)->fetch();
+
+ return $row === false ? null : $row;
+}
+
+function insert_row(string $sql, array $parameters = []): int {
+ query($sql, $parameters);
+
+ return (int)database()->lastInsertId();
+}
+
+?>
diff --git a/php/mail.php b/php/mail.php
new file mode 100644
index 0000000..155e6b4
--- /dev/null
+++ b/php/mail.php
@@ -0,0 +1,30 @@
+<?php
+/*
+ * GNUfault.org - GNUfault's website
+ * Copyright (C) 2026 Connor Thomson
+ *
+ * This program is free software: you can redistribute it and/or modify
+ * it under the terms of the GNU Affero General Public License as published by
+ * the Free Software Foundation, either version 3 of the License, or
+ * (at your option) any later version.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * GNU Affero General Public License for more details.
+ *
+ * You should have received a copy of the GNU Affero General Public License
+ * along with this program. If not, see <https://www.gnu.org/licenses/>.
+ */
+
+function send_mail(string $to, string $subject, string $content): bool {
+ $from = 'noreply@gnufault.org';
+
+ $headers = "From: $from" . "\r\n" .
+ "Reply-To: $from" . "\r\n" .
+ "X-Mailer: PHP/" . phpversion();
+
+ return mail($to, $subject, $content, $headers);
+}
+
+?>
diff --git a/signup/signup.php b/signup/signup.php
index a0d0dea..a41454a 100755
--- a/signup/signup.php
+++ b/signup/signup.php
@@ -20,6 +20,8 @@
define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/');
require_once ROOT . '/php/session.php';
+require_once ROOT . '/php/database.php';
+require_once ROOT . '/php/mail.php';
if ($_SERVER["REQUEST_METHOD"] == "POST") {
$username = $_POST['username'];
@@ -34,41 +36,19 @@ if ($_SERVER["REQUEST_METHOD"] == "POST") {
$hashed_password = password_hash($password, PASSWORD_DEFAULT);
- $code = rand(1000, 9999);
-
- $host = '127.0.0.1';
- $db = 'gnufaultdb';
- $db_user = 'gnufaultdb_user';
- $pass = trim(file_get_contents('/etc/gnufault.d/password'));
-
- $charset = 'utf8mb4';
- $dsn = "mysql:host=$host;dbname=$db;charset=$charset";
-
- $options = [
- PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION,
- PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC,
- PDO::ATTR_EMULATE_PREPARES => false,
- ];
-
- try {
- $pdo = new PDO($dsn, $db_user, $pass, $options);
- } catch (\PDOException $e) {
- throw new \PDOException($e->getMessage(), (int)$e->getCode());
- }
+ $code = rand(1000, 9999);
try {
$sql = "INSERT INTO users (username, email, password, verification_code) VALUES (:username, :email, :password, :code)";
- $stmt = $pdo->prepare($sql);
- $stmt->execute([
+
+ $user_id = insert_row($sql, [
'username' => $username,
'email' => $email,
'password' => $hashed_password,
'code' => $code
]);
- $user_id = $pdo->lastInsertId();
-
- set_user_id((int)$user_id);
+ set_user_id($user_id);
} catch (\PDOException $e) {
if ($e->getCode() == 23000) {
echo "Error: Username or email is already taken.";
@@ -80,11 +60,7 @@ if ($_SERVER["REQUEST_METHOD"] == "POST") {
$subject = "GNUfault.org Verification Code";
- $headers = "From: noreply@gnufault.org" . "\r\n" .
- "Reply-To: noreply@gnufault.org" . "\r\n" .
- "X-Mailer: PHP/" . phpversion();
-
- if (mail($email, $subject, $code, $headers)) {
+ if (send_mail($email, $subject, (string)$code)) {
header("Location: verify");
} else {
echo "Failed to send";
diff --git a/signup/verify/verify.php b/signup/verify/verify.php
index 471251d..592915f 100755
--- a/signup/verify/verify.php
+++ b/signup/verify/verify.php
@@ -20,6 +20,7 @@
define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/');
require_once ROOT . '/php/session.php';
+require_once ROOT . '/php/database.php';
if ($_SERVER["REQUEST_METHOD"] == "POST") {
$code = $_POST['code'];
@@ -30,33 +31,11 @@ if ($_SERVER["REQUEST_METHOD"] == "POST") {
exit;
}
- $host = '127.0.0.1';
- $db = 'gnufaultdb';
- $db_user = 'gnufaultdb_user';
- $pass = trim(file_get_contents('/etc/gnufault.d/password'));
-
- $charset = 'utf8mb4';
- $dsn = "mysql:host=$host;dbname=$db;charset=$charset";
-
- $options = [
- PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION,
- PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC,
- PDO::ATTR_EMULATE_PREPARES => false,
- ];
-
- try {
- $pdo = new PDO($dsn, $db_user, $pass, $options);
- } catch (\PDOException $e) {
- throw new \PDOException($e->getMessage(), (int)$e->getCode());
- }
-
try {
$sql = "SELECT verification_code FROM users WHERE id = :id";
- $stmt = $pdo->prepare($sql);
- $stmt->execute(['id' => $user_id]);
+ $user = fetch_row($sql, ['id' => $user_id]);
- $user = $stmt->fetch();
if (!$user) {
echo "User not found.";
exit;
@@ -80,14 +59,13 @@ if ($_SERVER["REQUEST_METHOD"] == "POST") {
try {
$sql = "UPDATE users SET verification_code = :code WHERE id = :id";
- $stmt = $pdo->prepare($sql);
- $stmt->execute([
+ $statement = query($sql, [
'code' => '0001',
'id' => $user_id
]);
- if ($stmt->rowCount() == 0) {
+ if ($statement->rowCount() == 0) {
echo "User not found.";
}
} catch (\PDOException $e) {