1
|
|
|
<?php |
2
|
|
|
require_once("gfunctions.php"); |
3
|
|
|
/** |
4
|
|
|
* Class registration |
5
|
|
|
* handles the user registration |
6
|
|
|
*/ |
7
|
|
|
class GuestReg |
|
|
|
|
8
|
|
|
{ |
9
|
|
|
/** |
10
|
|
|
* @var object $db_connection The database connection |
11
|
|
|
*/ |
12
|
|
|
private $db_connection = null; |
13
|
|
|
/** |
14
|
|
|
* @var array $errors Collection of error messages |
15
|
|
|
*/ |
16
|
|
|
public $errors = array(); |
17
|
|
|
/** |
18
|
|
|
* @var array $messages Collection of success / neutral messages |
19
|
|
|
*/ |
20
|
|
|
public $messages = array(); |
21
|
|
|
|
22
|
|
|
/** |
23
|
|
|
* the function "__construct()" automatically starts whenever an object of this class is created, |
24
|
|
|
* you know, when you do "$registration = new Registration();" |
25
|
|
|
*/ |
26
|
|
|
public function __construct() |
27
|
|
|
{ |
28
|
|
|
if (isset($_POST["register"])) { |
29
|
|
|
$this->registerNewUser(); |
30
|
|
|
} |
31
|
|
|
} |
32
|
|
|
|
33
|
|
|
/** |
34
|
|
|
* handles the entire registration process. checks all error possibilities |
35
|
|
|
* and creates a new user in the database if everything is fine |
36
|
|
|
*/ |
37
|
|
|
private function registerNewUser() |
38
|
|
|
{ |
39
|
|
|
$settings = require('config/settings.php'); |
40
|
|
|
|
41
|
|
|
if (empty($_POST['user_name'])) { |
42
|
|
|
$this->errors[] = "Empty Username"; |
43
|
|
|
} elseif (empty($_POST['user_password_new']) || empty($_POST['user_password_repeat'])) { |
44
|
|
|
$this->errors[] = "Empty Password"; |
45
|
|
|
} elseif ($_POST['user_password_new'] !== $_POST['user_password_repeat']) { |
46
|
|
|
$this->errors[] = "Password and password repeat are not the same"; |
47
|
|
|
} elseif (strlen($_POST['user_password_new']) < 6) { |
48
|
|
|
$this->errors[] = "Password has a minimum length of 6 characters"; |
49
|
|
View Code Duplication |
} elseif (strlen($_POST['user_name']) > 64 || strlen($_POST['user_name']) < 2) { |
|
|
|
|
50
|
|
|
$this->errors[] = "Username cannot be shorter than 2 or longer than 30 characters"; |
51
|
|
|
} elseif (!preg_match('/^[a-z\d]{2,30}$/i', $_POST['user_name'])) { |
52
|
|
|
$this->errors[] = "Username does not fit the name scheme: only a-Z and numbers are allowed, 2 to 64 characters"; |
53
|
|
|
} elseif (empty($_POST['user_email'])) { |
54
|
|
|
$this->errors[] = "Email cannot be empty"; |
55
|
|
|
} elseif (strlen($_POST['user_email']) > 64) { |
56
|
|
|
$this->errors[] = "Email cannot be longer than 64 characters"; |
57
|
|
|
} elseif (!filter_var($_POST['user_email'], FILTER_VALIDATE_EMAIL)) { |
58
|
|
|
$this->errors[] = "Your email address is not in a valid email format"; |
59
|
|
|
} elseif (!empty($_POST['user_name']) |
60
|
|
|
&& strlen($_POST['user_name']) <= 64 |
61
|
|
|
&& strlen($_POST['user_name']) >= 2 |
62
|
|
|
&& preg_match('/^[a-z\d]{2,64}$/i', $_POST['user_name']) |
63
|
|
|
&& !empty($_POST['user_email']) |
64
|
|
|
&& strlen($_POST['user_email']) <= 64 |
65
|
|
|
&& filter_var($_POST['user_email'], FILTER_VALIDATE_EMAIL) |
66
|
|
|
&& !empty($_POST['user_password_new']) |
67
|
|
|
&& !empty($_POST['user_password_repeat']) |
68
|
|
|
&& ($_POST['user_password_new'] === $_POST['user_password_repeat']) |
69
|
|
|
) { |
70
|
|
|
$temp_host = decrypt($settings['db']['host']); |
71
|
|
|
$temp_user = decrypt($settings['db']['user']); |
72
|
|
|
$temp_pass = decrypt($settings['db']['pass']); |
73
|
|
|
$temp_name = decrypt($settings['db']['name']); |
74
|
|
|
|
75
|
|
|
// create a database connection, using the constants from config/config.php (which we loaded in index.php) |
76
|
|
|
$this->db_connection = new mysqli($temp_host, $temp_user, $temp_pass, $temp_name); |
77
|
|
|
|
78
|
|
|
// change character set to utf8 and check it |
79
|
|
|
if (!$this->db_connection->set_charset("utf8")) { |
80
|
|
|
$this->errors[] = $this->db_connection->error; |
81
|
|
|
} |
82
|
|
|
|
83
|
|
|
// if no connection errors (= working database connection) |
84
|
|
|
if (!$this->db_connection->connect_errno) { |
85
|
|
|
|
86
|
|
|
// escaping, additionally removing everything that could be (html/javascript-) code |
87
|
|
|
$user_name = $this->db_connection->real_escape_string(strip_tags($_POST['user_name'], ENT_QUOTES)); |
88
|
|
|
$user_email = $this->db_connection->real_escape_string(strip_tags($_POST['user_email'], ENT_QUOTES)); |
89
|
|
|
$user_password = $_POST['user_password_new']; |
90
|
|
|
$user_profile = $_POST['profile_pic']; |
91
|
|
|
|
92
|
|
|
// crypt the user's password with PHP 5.5's password_hash() function, results in a 60 character |
93
|
|
|
// hash string. the PASSWORD_DEFAULT constant is defined by the PHP 5.5, or if you are using |
94
|
|
|
// PHP 5.3/5.4, by the password hashing compatibility library |
95
|
|
|
$user_password_hash = password_hash($user_password, PASSWORD_DEFAULT); |
96
|
|
|
|
97
|
|
|
// check if user or email address already exists |
98
|
|
|
$sql = "SELECT * FROM `users` WHERE `user_name` = '" . $user_name . "' OR `user_email = '" . $user_email . "';"; |
99
|
|
|
$query_check_user_name = $this->db_connection->query($sql); |
|
|
|
|
100
|
|
|
|
101
|
|
|
if ($query_check_user_name->num_rows == 1) { |
102
|
|
|
$this->errors[] = "Sorry, that username / email address is already taken."; |
103
|
|
|
|
104
|
|
|
} else { |
105
|
|
|
|
106
|
|
|
$permissions = include 'config/permissions.php'; |
107
|
|
|
$userPerms = json_encode($permissions[1]); |
108
|
|
|
|
109
|
|
|
// write new user's data into database |
110
|
|
|
$sql = "INSERT INTO `users` (`user_name`, `user_password_hash`, `user_email`, `playerid`, `user_level`, `permissions`, `user_profile`) VALUES |
111
|
|
|
('" . $user_name . "', '" . $user_password_hash . "', '" . $user_email . "', '" . $_SESSION['playerid'] . "', '1', '" . $userPerms . "', '1');"; |
112
|
|
|
|
113
|
|
|
$query_new_user_insert = $this->db_connection->query($sql); |
|
|
|
|
114
|
|
|
|
115
|
|
|
// if user has been added successfully |
116
|
|
|
if ($query_new_user_insert) { |
117
|
|
|
$this->messages[] = "Your account has been created"; |
118
|
|
|
} else { |
119
|
|
|
$this->errors[] = "Sorry, your registration failed. Please go back and try again."; |
120
|
|
|
} |
121
|
|
|
} |
122
|
|
|
} else { |
123
|
|
|
$this->errors[] = "Sorry, no database connection."; |
124
|
|
|
} |
125
|
|
|
} else { |
126
|
|
|
$this->errors[] = "An unknown error occurred."; |
127
|
|
|
} |
128
|
|
|
} |
129
|
|
|
} |
|
|
|
|
130
|
|
|
|
You can fix this by adding a namespace to your class:
When choosing a vendor namespace, try to pick something that is not too generic to avoid conflicts with other libraries.