Passed
Push — master ( 13c680...457c5e )
by Anthony
02:41
created

Connexion::setTestParamCompte()   B

Complexity

Conditions 6
Paths 4

Size

Total Lines 15
Code Lines 8

Duplication

Lines 0
Ratio 0 %

Importance

Changes 1
Bugs 0 Features 0
Metric Value
c 1
b 0
f 0
dl 0
loc 15
rs 8.8571
cc 6
eloc 8
nc 4
nop 3
1
<?php
2
	namespace core\auth;
3
4
	use core\App;
5
	use core\Configuration;
6
	use core\functions\DateHeure;
7
	use core\HTML\flashmessage\FlashMessage;
8
9
	class Connexion {
10
11
		public function __construct() {
12
			if (session_id() == null) {
13
				session_start();
14
			}
15
		}
16
17
		/**
18
		 * @param $valide
19
		 * @param $archiver
20
		 * @param $page_retour_err
21
		 */
22
		private function setTestParamCompte($valide, $archiver, $page_retour_err) {
23
			$config = new Configuration();
24
25
			//cela veut dire que l'utilisateur doit obligatoirement etre valider pour avoir acces au site
26
			if (($config->getValiderInscription() == 1) && ((isset($valide)) && ($valide != 1))) {
27
				FlashMessage::setFlash("Votre compta n'a encore pas été validé par un administrateur, vous ne pouvez donc pas accéder à ce site, veuillez réesseyer ultérieurement");
28
				header("location:$page_retour_err");
29
			}
30
31
			//si le compte est archiver (bloqué) l'utilisateur ne peut pas se connecter au site
32
			if ((isset($archiver)) && ($archiver == 1)) {
33
				FlashMessage::setFlash("Votre compte a été bloqué par un administrateur, vous ne pouvez donc pas vous connecter à ce site, veuillez réesseyer ultérieurement");
34
				header("location:$page_retour_err");
35
			}
36
		}
37
38
39
		/**
40
		 * Fonction de connexions a un espace membre ou prive avec un login / mdp
41
		 * @param string $pseudo pseudo que l'utilisateur utilise pour se connecter
42
		 * @param string $mdp mot de passe que l'utilisateur utilise
43
		 * @param string $page_retour_err page de retour en cas d'err de mdp ou pseudo
44
		 * @param string $page_retour page de retour quand connexion ok
45
		 * @param int $remember si on doit mémoriser la connexion au site
46
		 */
47
		public static function setLogin($pseudo, $mdp, $page_retour_err, $page_retour, $remember) {
48
			$dbc = App::getDb();
49
			$mdpbdd = "";
50
51
			//recup des donnees
52
			$pseudo = $dbc->quote(htmlspecialchars($pseudo));
53
			$mdp_nonencrypt = $mdp;
54
			$mdp = md5(htmlspecialchars($mdp));
55
56
			$query = $dbc->query("select * from identite where pseudo=$pseudo");
57
58
			//aficher query tant que qqch dans $ligne
59
			if ((is_array($query)) && (count($query) > 0)) {
60
				foreach ($query as $obj) {
61
					$id = $obj->ID_identite;
62
					$pseudo = $obj->pseudo;
63
					$valide = $obj->valide;
64
					$archiver = $obj->archiver;
65
					$mdpbdd = Encrypt::setDecryptMdp($obj->mdp, $id);
66
				}
67
			}
68
69
			//verif si num enr = 0
70
			if (!isset($id)) {
71
				FlashMessage::setFlash("Vos identifiants de connexions sont incorrects");
72
				header("location:$page_retour_err");
73
			}
74
			else {
75
				self::setTestParamCompte($valide, $archiver, $page_retour_err);
0 ignored issues
show
Bug introduced by
The variable $valide does not seem to be defined for all execution paths leading up to this point.

If you define a variable conditionally, it can happen that it is not defined for all execution paths.

Let’s take a look at an example:

function myFunction($a) {
    switch ($a) {
        case 'foo':
            $x = 1;
            break;

        case 'bar':
            $x = 2;
            break;
    }

    // $x is potentially undefined here.
    echo $x;
}

In the above example, the variable $x is defined if you pass “foo” or “bar” as argument for $a. However, since the switch statement has no default case statement, if you pass any other value, the variable $x would be undefined.

Available Fixes

  1. Check for existence of the variable explicitly:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        if (isset($x)) { // Make sure it's always set.
            echo $x;
        }
    }
    
  2. Define a default value for the variable:

    function myFunction($a) {
        $x = ''; // Set a default which gets overridden for certain paths.
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        echo $x;
    }
    
  3. Add a value for the missing path:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
    
            // We add support for the missing case.
            default:
                $x = '';
                break;
        }
    
        echo $x;
    }
    
Loading history...
Bug introduced by
The variable $archiver does not seem to be defined for all execution paths leading up to this point.

If you define a variable conditionally, it can happen that it is not defined for all execution paths.

Let’s take a look at an example:

function myFunction($a) {
    switch ($a) {
        case 'foo':
            $x = 1;
            break;

        case 'bar':
            $x = 2;
            break;
    }

    // $x is potentially undefined here.
    echo $x;
}

In the above example, the variable $x is defined if you pass “foo” or “bar” as argument for $a. However, since the switch statement has no default case statement, if you pass any other value, the variable $x would be undefined.

Available Fixes

  1. Check for existence of the variable explicitly:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        if (isset($x)) { // Make sure it's always set.
            echo $x;
        }
    }
    
  2. Define a default value for the variable:

    function myFunction($a) {
        $x = ''; // Set a default which gets overridden for certain paths.
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
        }
    
        echo $x;
    }
    
  3. Add a value for the missing path:

    function myFunction($a) {
        switch ($a) {
            case 'foo':
                $x = 1;
                break;
    
            case 'bar':
                $x = 2;
                break;
    
            // We add support for the missing case.
            default:
                $x = '';
                break;
        }
    
        echo $x;
    }
    
Loading history...
76
77
				//si les mdp sont egaux on redirige ver esace membre sinon ver login avec un mess d'erreur
78
				if ($mdp == $mdpbdd) {
79
					$_SESSION['login'] = $pseudo;
80
					$_SESSION["idlogin".CLEF_SITE] = $id;
81
82
					self::setTestChangerMdp($id, $mdp_nonencrypt, $remember);
83
84
					FlashMessage::setFlash("Vous êtes maintenant connecté", "info");
85
					header("location:$page_retour");
86
				}
87
				else {
88
					FlashMessage::setFlash("Vos identifiants de connexions sont incorrects");
89
					header("location:$page_retour_err");
90
				}
91
			}
92
		}
93
94
		/**
95
		 * Fonction pour lancer une connexoin avec un compte
96
		 * @param int $obj_connecte si = 1 on est obligge d'être connecte pour avoir acces à la page
97
		 * @param string $page_retour page sur laquel rediriger le mec qui a clique sur déconnexion
98
		 */
99
		public static function setConnexion($obj_connecte, $page_retour) {
100
			$dbc = App::getDb();
101
102
			//si le user n'a rien mis dans login on lui de pense a se connecter
103
			if ((isset($_COOKIE["auth".CLEF_SITE])) && (!empty($_SESSION["idlogin".CLEF_SITE]))) {
104
				$auth = $_COOKIE["auth".CLEF_SITE];
105
106
				$auth = explode("-----", $auth);
107
108
				$query = $dbc->query("SELECT * FROM identite WHERE ID_identite=".$auth[0]);
109
				if ((is_array($query)) && (count($query) > 0)) {
110
					foreach ($query as $obj) {
111
						//si le compte est archivé on déconnecte la session et le cookie
112
						if ($obj->archiver == 1) {
113
							setcookie("auth".CLEF_SITE, NULL, -1);
114
							self::setDeconnexion($page_retour);
115
						}
116
						else {
117
							$key = sha1($obj->pseudo.$obj->mdp);
118
119
							if ($key == $auth[1]) {
120
								$_SESSION['login'] = $obj->pseudo;
121
								$_SESSION["idlogin".CLEF_SITE] = $obj->ID_identite;
122
123
								setcookie("auth".CLEF_SITE, $obj->ID_identite."-----".$key, time() + 3600 * 24 * 3, "/", "", false, true);
124
							}
125
							else if ($obj_connecte == 1) {
126
								self::setDeconnexion($page_retour);
127
							}
128
						}
129
					}
130
				}
131
			}
132
			else if ((!isset($_SESSION["idlogin".CLEF_SITE])) && ($obj_connecte == 1)) {
0 ignored issues
show
Duplication introduced by
This code seems to be duplicated across your project.

Duplicated code is one of the most pungent code smells. If you need to duplicate the same code in three or more different places, we strongly encourage you to look into extracting the code into a single class or operation.

You can also find more detailed suggestions in the “Code” section of your repository.

Loading history...
133
				FlashMessage::setFlash("Vous devez être connecté pour accéder à cette page");
134
				header("location:".$page_retour);
135
			}
136
		}
137
138
		/**
139
		 * Fonction pour déconnecter un membre (on degage session et cookie)
140
		 * @param string $page_retour page sur laquel rediriger le mec qui a clique sur déconnexion
141
		 */
142
		public static function setDeconnexion($page_retour) {
143
			$_SESSION['login'];
144
			$_SESSION["idlogin".CLEF_SITE];
145
			unset($_SESSION['login']);
146
			unset($_SESSION["idlogin".CLEF_SITE]);
147
			session_destroy();
148
			setcookie("auth".CLEF_SITE, NULL, -1);
149
150
			session_start();
151
			FlashMessage::setFlash("Vous avez été déconnecté avec succès", "success");
152
153
			header("location:".$page_retour);
154
		}
155
156
157
		//--------------------------------- info concernant les connexion au site du user --------------------------
158
		/**
159
		 * pour remettre la derniere connexoin à la date du jour
160
		 * @param $id_identite
161
		 */
162
		public static function setUpdatelastConnexion($id_identite) {
163
			$dbc = App::getDb();
164
165
			$dbc->prepare("UPDATE identite SET last_change_mdp=:date WHERE ID_identite=:id_identite", array("date"=>date("Y-m-d"), "id_identite"=>$id_identite));
166
		}
167
168
		/**
169
		 * permet de récupérer la dernier fois que l'utilisateur s'est connecté au site
170
		 * @param $id_identite
171
		 * @return mixed
172
		 */
173
		public static function getlastConnexion($id_identite) {
0 ignored issues
show
Duplication introduced by
This method seems to be duplicated in your project.

Duplicated code is one of the most pungent code smells. If you need to duplicate the same code in three or more different places, we strongly encourage you to look into extracting the code into a single class or operation.

You can also find more detailed suggestions in the “Code” section of your repository.

Loading history...
174
			$dbc = App::getDb();
175
176
			$query = $dbc->query("SELECT last_change_mdp FROM identite WHERE ID_identite=".$id_identite);
177
			if ((is_array($query)) && (count($query) > 0)) {
178
				foreach ($query as $obj) return $obj->last_change_mdp;
179
			}
180
		}
181
182
		/**
183
		 * @param $id_identite
184
		 * @param null $remember
185
		 */
186
		private static function setTestChangerMdp($id_identite, $mdp_nonencrypt_tape, $remember) {
187
			$membre = new Membre($id_identite);
188
189
			$date_array = DateHeure::dateBddToArray(self::getlastConnexion($id_identite));
190
			$last_change_mdp = mktime(0, 0, 0, $date_array[1], $date_array[2], $date_array[0]);
191
			$today = mktime(0, 0, 0, date("m"), date("d"), date("Y"));
192
193
			if (($today - $last_change_mdp) > 259200) {
194
				self::setUpdatelastConnexion($id_identite);
195
196
				$membre->setMdp($mdp_nonencrypt_tape, $mdp_nonencrypt_tape, $mdp_nonencrypt_tape);
197
			}
198
199
			if ((isset($remember)) && ($remember != 0)) {
200
				setcookie("auth".CLEF_SITE, NULL, -1);
201
				setcookie("auth".CLEF_SITE, $id_identite."-----".sha1($membre->getPseudo().$membre->getMdp()), time() + 3600 * 24 * 3, "/", "", false, true);
202
			}
203
		}
204
	}