. */ define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/'); require_once ROOT . '/php/session.php'; if ($_SERVER["REQUEST_METHOD"] == "POST") { $code = $_POST['code']; $user_id = get_user_id(); if (!$user_id) { echo "Not logged in."; exit; } $host = '127.0.0.1'; $db = 'gnufaultdb'; $db_user = 'gnufaultdb_user'; $pass = trim(file_get_contents('/etc/gnufault.d/password')); $charset = 'utf8mb4'; $dsn = "mysql:host=$host;dbname=$db;charset=$charset"; $options = [ PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION, PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC, PDO::ATTR_EMULATE_PREPARES => false, ]; try { $pdo = new PDO($dsn, $db_user, $pass, $options); } catch (\PDOException $e) { throw new \PDOException($e->getMessage(), (int)$e->getCode()); } try { $sql = "SELECT verification_code FROM users WHERE id = :id"; $stmt = $pdo->prepare($sql); $stmt->execute(['id' => $user_id]); $user = $stmt->fetch(); if (!$user) { echo "User not found."; exit; } $real_code = $user['verification_code']; } catch (\PDOException $e) { echo "Error: " . $e->getMessage(); exit; } if ($real_code == '0001') { echo "Account is already verifed"; exit; } if ($code != $real_code) { echo "Code is not correct!"; exit; } try { $sql = "UPDATE users SET verification_code = :code WHERE id = :id"; $stmt = $pdo->prepare($sql); $stmt->execute([ 'code' => '0001', 'id' => $user_id ]); if ($stmt->rowCount() == 0) { echo "User not found."; } } catch (\PDOException $e) { echo "Error: " . $e->getMessage(); exit; } header("Location: /signin"); } ?>