1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
|
<?php
/*
* GNUfault.org - GNUfault's website
* Copyright (C) 2026 Connor Thomson
*
* This program is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License as published by
* the Free Software Foundation, either version 3 of the License, or
* (at your option) any later version.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License
* along with this program. If not, see <https://www.gnu.org/licenses/>.
*/
define('ROOT', rtrim($_SERVER['DOCUMENT_ROOT'], '/') . '/');
require_once ROOT . '/php/session.php';
if ($_SERVER["REQUEST_METHOD"] == "POST") {
$code = $_POST['code'];
$user_id = get_user_id();
if (!$user_id) {
echo "Not logged in.";
exit;
}
$host = '127.0.0.1';
$db = 'gnufaultdb';
$db_user = 'gnufaultdb_user';
$pass = trim(file_get_contents('/etc/gnufault.d/password'));
$charset = 'utf8mb4';
$dsn = "mysql:host=$host;dbname=$db;charset=$charset";
$options = [
PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION,
PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC,
PDO::ATTR_EMULATE_PREPARES => false,
];
try {
$pdo = new PDO($dsn, $db_user, $pass, $options);
} catch (\PDOException $e) {
throw new \PDOException($e->getMessage(), (int)$e->getCode());
}
try {
$sql = "SELECT verification_code FROM users WHERE id = :id";
$stmt = $pdo->prepare($sql);
$stmt->execute(['id' => $user_id]);
$user = $stmt->fetch();
if (!$user) {
echo "User not found.";
exit;
}
$real_code = $user['verification_code'];
} catch (\PDOException $e) {
echo "Error: " . $e->getMessage();
exit;
}
if ($real_code == '0001') {
echo "Account is already verifed";
exit;
}
if ($code != $real_code) {
echo "Code is not correct!";
exit;
}
try {
$sql = "UPDATE users SET verification_code = :code WHERE id = :id";
$stmt = $pdo->prepare($sql);
$stmt->execute([
'code' => '0001',
'id' => $user_id
]);
if ($stmt->rowCount() == 0) {
echo "User not found.";
}
} catch (\PDOException $e) {
echo "Error: " . $e->getMessage();
exit;
}
header("Location: /signin");
}
?>
|