fd
This commit is contained in:
parent
518cd35214
commit
10091b24c4
53
db/setup.php
53
db/setup.php
@ -27,6 +27,59 @@ try {
|
|||||||
$pdo->exec($sql);
|
$pdo->exec($sql);
|
||||||
echo "Table 'users' created successfully (if it didn't exist).\n";
|
echo "Table 'users' created successfully (if it didn't exist).\n";
|
||||||
|
|
||||||
|
// Create servers table
|
||||||
|
$sql = "
|
||||||
|
CREATE TABLE IF NOT EXISTS servers (
|
||||||
|
id INT AUTO_INCREMENT PRIMARY KEY,
|
||||||
|
name VARCHAR(100) NOT NULL,
|
||||||
|
owner_id INT NOT NULL,
|
||||||
|
created_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
|
||||||
|
FOREIGN KEY (owner_id) REFERENCES users(id) ON DELETE CASCADE
|
||||||
|
);";
|
||||||
|
$pdo->exec($sql);
|
||||||
|
echo "Table 'servers' created successfully.\n";
|
||||||
|
|
||||||
|
// Create server_members table
|
||||||
|
$sql = "
|
||||||
|
CREATE TABLE IF NOT EXISTS server_members (
|
||||||
|
id INT AUTO_INCREMENT PRIMARY KEY,
|
||||||
|
server_id INT NOT NULL,
|
||||||
|
user_id INT NOT NULL,
|
||||||
|
joined_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
|
||||||
|
FOREIGN KEY (server_id) REFERENCES servers(id) ON DELETE CASCADE,
|
||||||
|
FOREIGN KEY (user_id) REFERENCES users(id) ON DELETE CASCADE,
|
||||||
|
UNIQUE KEY (server_id, user_id)
|
||||||
|
);";
|
||||||
|
$pdo->exec($sql);
|
||||||
|
echo "Table 'server_members' created successfully.\n";
|
||||||
|
|
||||||
|
// Create channels table
|
||||||
|
$sql = "
|
||||||
|
CREATE TABLE IF NOT EXISTS channels (
|
||||||
|
id INT AUTO_INCREMENT PRIMARY KEY,
|
||||||
|
server_id INT NOT NULL,
|
||||||
|
name VARCHAR(100) NOT NULL,
|
||||||
|
created_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
|
||||||
|
FOREIGN KEY (server_id) REFERENCES servers(id) ON DELETE CASCADE
|
||||||
|
);";
|
||||||
|
$pdo->exec($sql);
|
||||||
|
echo "Table 'channels' created successfully.\n";
|
||||||
|
|
||||||
|
// Create messages table
|
||||||
|
$sql = "
|
||||||
|
CREATE TABLE IF NOT EXISTS messages (
|
||||||
|
id INT AUTO_INCREMENT PRIMARY KEY,
|
||||||
|
channel_id INT NOT NULL,
|
||||||
|
user_id INT NOT NULL,
|
||||||
|
message TEXT NOT NULL,
|
||||||
|
created_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
|
||||||
|
FOREIGN KEY (channel_id) REFERENCES channels(id) ON DELETE CASCADE,
|
||||||
|
FOREIGN KEY (user_id) REFERENCES users(id) ON DELETE CASCADE
|
||||||
|
);";
|
||||||
|
$pdo->exec($sql);
|
||||||
|
echo "Table 'messages' created successfully.\n";
|
||||||
|
|
||||||
|
|
||||||
} catch (PDOException $e) {
|
} catch (PDOException $e) {
|
||||||
die("DB SETUP ERROR: " . $e->getMessage());
|
die("DB SETUP ERROR: " . $e->getMessage());
|
||||||
}
|
}
|
||||||
|
|||||||
16
login.php
16
login.php
@ -11,11 +11,11 @@ if (isset($_SESSION['user_id'])) {
|
|||||||
$errors = [];
|
$errors = [];
|
||||||
|
|
||||||
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
||||||
$username = trim($_POST['username'] ?? '');
|
$email = trim($_POST['email'] ?? '');
|
||||||
$password = $_POST['password'] ?? '';
|
$password = $_POST['password'] ?? '';
|
||||||
|
|
||||||
if (empty($username)) {
|
if (empty($email)) {
|
||||||
$errors[] = 'Le nom d\'utilisateur est requis.';
|
$errors[] = 'L\'adresse e-mail est requise.';
|
||||||
}
|
}
|
||||||
if (empty($password)) {
|
if (empty($password)) {
|
||||||
$errors[] = 'Le mot de passe est requis.';
|
$errors[] = 'Le mot de passe est requis.';
|
||||||
@ -24,8 +24,8 @@ if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
|||||||
if (empty($errors)) {
|
if (empty($errors)) {
|
||||||
try {
|
try {
|
||||||
$pdo = db();
|
$pdo = db();
|
||||||
$stmt = $pdo->prepare("SELECT * FROM users WHERE username = ?");
|
$stmt = $pdo->prepare("SELECT * FROM users WHERE email = ?");
|
||||||
$stmt->execute([$username]);
|
$stmt->execute([$email]);
|
||||||
$user = $stmt->fetch();
|
$user = $stmt->fetch();
|
||||||
|
|
||||||
if ($user && password_verify($password, $user['password'])) {
|
if ($user && password_verify($password, $user['password'])) {
|
||||||
@ -40,7 +40,7 @@ if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
|||||||
echo '<script>window.location.href = "index.php";</script>';
|
echo '<script>window.location.href = "index.php";</script>';
|
||||||
exit();
|
exit();
|
||||||
} else {
|
} else {
|
||||||
$errors[] = 'Nom d\'utilisateur ou mot de passe incorrect.';
|
$errors[] = 'Adresse e-mail ou mot de passe incorrect.';
|
||||||
}
|
}
|
||||||
} catch (PDOException $e) {
|
} catch (PDOException $e) {
|
||||||
error_log("Login Error: " . $e->getMessage());
|
error_log("Login Error: " . $e->getMessage());
|
||||||
@ -75,8 +75,8 @@ if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
|||||||
<?php endif; ?>
|
<?php endif; ?>
|
||||||
<form action="login.php" method="POST" novalidate>
|
<form action="login.php" method="POST" novalidate>
|
||||||
<div class="mb-3">
|
<div class="mb-3">
|
||||||
<label for="username" class="form-label">Nom d'utilisateur</label>
|
<label for="email" class="form-label">Adresse e-mail</label>
|
||||||
<input type="text" class="form-control" id="username" name="username" required value="<?php echo isset($_POST['username']) ? htmlspecialchars($_POST['username']) : '' ?>">
|
<input type="email" class="form-control" id="email" name="email" required value="<?php echo isset($_POST['email']) ? htmlspecialchars($_POST['email']) : '' ?>">
|
||||||
</div>
|
</div>
|
||||||
<div class="mb-3">
|
<div class="mb-3">
|
||||||
<label for="password" class="form-label">Mot de passe</label>
|
<label for="password" class="form-label">Mot de passe</label>
|
||||||
|
|||||||
63
register.php
63
register.php
@ -8,15 +8,20 @@ $success = '';
|
|||||||
|
|
||||||
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
||||||
$username = trim($_POST['username'] ?? '');
|
$username = trim($_POST['username'] ?? '');
|
||||||
|
$email = trim($_POST['email'] ?? '');
|
||||||
$password = $_POST['password'] ?? '';
|
$password = $_POST['password'] ?? '';
|
||||||
|
|
||||||
if (empty($username)) {
|
if (empty($username)) {
|
||||||
$errors[] = 'Le nom d\'utilisateur est requis.';
|
$errors[] = 'Le nom d\'utilisateur est requis.';
|
||||||
}
|
}
|
||||||
|
if (empty($email)) {
|
||||||
|
$errors[] = 'L\'adresse e-mail est requise.';
|
||||||
|
} elseif (!filter_var($email, FILTER_VALIDATE_EMAIL)) {
|
||||||
|
$errors[] = 'L\'adresse e-mail n\'est pas valide.';
|
||||||
|
}
|
||||||
if (empty($password)) {
|
if (empty($password)) {
|
||||||
$errors[] = 'Le mot de passe est requis.';
|
$errors[] = 'Le mot de passe est requis.';
|
||||||
}
|
}
|
||||||
// Basic password length validation
|
|
||||||
if (strlen($password) < 8) {
|
if (strlen($password) < 8) {
|
||||||
$errors[] = 'Le mot de passe doit contenir au moins 8 caractères.';
|
$errors[] = 'Le mot de passe doit contenir au moins 8 caractères.';
|
||||||
}
|
}
|
||||||
@ -25,22 +30,25 @@ if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
|||||||
try {
|
try {
|
||||||
$pdo = db();
|
$pdo = db();
|
||||||
|
|
||||||
// Check if username already exists
|
// Check if username or email already exists
|
||||||
$stmt = $pdo->prepare("SELECT COUNT(*) FROM users WHERE username = ?");
|
$stmt = $pdo->prepare("SELECT username, email FROM users WHERE username = ? OR email = ?");
|
||||||
$stmt->execute([$username]);
|
$stmt->execute([$username, $email]);
|
||||||
if ($stmt->fetchColumn() > 0) {
|
$existing_user = $stmt->fetch();
|
||||||
$errors[] = 'Ce nom d\'utilisateur est déjà pris.';
|
|
||||||
|
if ($existing_user) {
|
||||||
|
if ($existing_user['username'] === $username) {
|
||||||
|
$errors[] = 'Ce nom d\'utilisateur est déjà pris.';
|
||||||
|
}
|
||||||
|
if ($existing_user['email'] === $email) {
|
||||||
|
$errors[] = 'Cette adresse e-mail est déjà utilisée.';
|
||||||
|
}
|
||||||
} else {
|
} else {
|
||||||
// Generate unique IDs
|
|
||||||
$simple_id = generateSimpleId();
|
|
||||||
$ultra_id = generateUltraId();
|
|
||||||
|
|
||||||
// Hash password
|
// Hash password
|
||||||
$hashed_password = password_hash($password, PASSWORD_DEFAULT);
|
$hashed_password = password_hash($password, PASSWORD_DEFAULT);
|
||||||
|
|
||||||
// Insert user
|
// Insert user
|
||||||
$stmt = $pdo->prepare("INSERT INTO users (username, password, simple_id, ultra_id) VALUES (?, ?, ?, ?)");
|
$stmt = $pdo->prepare("INSERT INTO users (username, email, password) VALUES (?, ?, ?)");
|
||||||
$stmt->execute([$username, $hashed_password, $simple_id, $ultra_id]);
|
$stmt->execute([$username, $email, $hashed_password]);
|
||||||
|
|
||||||
// Get the new user's ID
|
// Get the new user's ID
|
||||||
$user_id = $pdo->lastInsertId();
|
$user_id = $pdo->lastInsertId();
|
||||||
@ -84,24 +92,21 @@ if ($_SERVER['REQUEST_METHOD'] === 'POST') {
|
|||||||
<?php endforeach; ?>
|
<?php endforeach; ?>
|
||||||
</div>
|
</div>
|
||||||
<?php endif; ?>
|
<?php endif; ?>
|
||||||
<?php if ($success): ?>
|
<form action="register.php" method="POST" novalidate>
|
||||||
<div class="alert alert-success">
|
<div class="mb-3">
|
||||||
<p><?php echo htmlspecialchars($success); ?></p>
|
<label for="username" class="form-label">Nom d'utilisateur</label>
|
||||||
<p>Redirection vers la page de connexion...</p>
|
<input type="text" class="form-control" id="username" name="username" required value="<?php echo isset($_POST['username']) ? htmlspecialchars($_POST['username']) : '' ?>">
|
||||||
</div>
|
</div>
|
||||||
<?php else: ?>
|
<div class="mb-3">
|
||||||
<form action="register.php" method="POST" novalidate>
|
<label for="email" class="form-label">Adresse e-mail</label>
|
||||||
<div class="mb-3">
|
<input type="email" class="form-control" id="email" name="email" required value="<?php echo isset($_POST['email']) ? htmlspecialchars($_POST['email']) : '' ?>">
|
||||||
<label for="username" class="form-label">Nom d'utilisateur</label>
|
</div>
|
||||||
<input type="text" class="form-control" id="username" name="username" required value="<?php echo isset($_POST['username']) ? htmlspecialchars($_POST['username']) : '' ?>">
|
<div class="mb-3">
|
||||||
</div>
|
<label for="password" class="form-label">Mot de passe</label>
|
||||||
<div class="mb-3">
|
<input type="password" class="form-control" id="password" name="password" required>
|
||||||
<label for="password" class="form-label">Mot de passe</label>
|
</div>
|
||||||
<input type="password" class="form-control" id="password" name="password" required>
|
<button type="submit" class="btn btn-primary">S'inscrire</button>
|
||||||
</div>
|
</form>
|
||||||
<button type="submit" class="btn btn-primary">S'inscrire</button>
|
|
||||||
</form>
|
|
||||||
<?php endif; ?>
|
|
||||||
</div>
|
</div>
|
||||||
<div class="card-footer text-center">
|
<div class="card-footer text-center">
|
||||||
<a href="login.php">Déjà un compte ? Connectez-vous</a>
|
<a href="login.php">Déjà un compte ? Connectez-vous</a>
|
||||||
|
|||||||
19
utils.php
19
utils.php
@ -14,4 +14,23 @@ function redirect($url) {
|
|||||||
header('Location: ' . $url);
|
header('Location: ' . $url);
|
||||||
exit();
|
exit();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function get_user_by_id($user_id) {
|
||||||
|
$pdo = db();
|
||||||
|
$stmt = $pdo->prepare("SELECT * FROM users WHERE id = ?");
|
||||||
|
$stmt->execute([$user_id]);
|
||||||
|
return $stmt->fetch(PDO::FETCH_ASSOC);
|
||||||
|
}
|
||||||
|
|
||||||
|
function get_user_servers($user_id) {
|
||||||
|
$pdo = db();
|
||||||
|
$stmt = $pdo->prepare("
|
||||||
|
SELECT s.* FROM servers s
|
||||||
|
JOIN server_members sm ON s.id = sm.server_id
|
||||||
|
WHERE sm.user_id = ?
|
||||||
|
");
|
||||||
|
$stmt->execute([$user_id]);
|
||||||
|
return $stmt->fetchAll(PDO::FETCH_ASSOC);
|
||||||
|
}
|
||||||
|
|
||||||
?>
|
?>
|
||||||
Loading…
x
Reference in New Issue
Block a user