@@ -43,12 +43,12 @@ |
||
| 43 | 43 | <body> |
| 44 | 44 | <?php require(__DIR__ . "/important/header.php"); ?> |
| 45 | 45 | <div class="container"> |
| 46 | - <?php if (isset($err)) {echo "<b style='color:red;'>" . $err . "</b><br><br>";}?> |
|
| 46 | + <?php if (isset($err)) {echo "<b style='color:red;'>" . $err . "</b><br><br>"; }?> |
|
| 47 | 47 | To enable 2FA, scan the following QR code with your authenticator app:<br><br> |
| 48 | 48 | <img src="<?php echo $totp->getQrCodeUri( |
| 49 | 49 | 'https://api.qrserver.com/v1/create-qr-code/?data=[DATA]&size=300x300&ecc=M&qzone=1&format=png', |
| 50 | 50 | '[DATA]' |
| 51 | - );?>"><br><br> |
|
| 51 | + ); ?>"><br><br> |
|
| 52 | 52 | Or use the following string: <b><?php echo $secret; ?></b><br> |
| 53 | 53 | Then type the 6-digit code your app generates below and click 'Submit':<br><br> |
| 54 | 54 | <form method="post" enctype="multipart/form-data"> |
@@ -69,7 +69,7 @@ discard block |
||
| 69 | 69 | <source src="/musicfiles/' . $filename . '"> |
| 70 | 70 | </audio>'; |
| 71 | 71 | } else if($type == "image") { |
| 72 | - echo "<img style='max-width: 100%;' src='/images/" . $filename . "'>"; |
|
| 72 | + echo "<img style='max-width: 100%;' src='/images/" . $filename . "'>"; |
|
| 73 | 73 | } else if($type == "midi") { |
| 74 | 74 | echo "Note: It may take a few seconds for the MIDI to load.<br>"; |
| 75 | 75 | echo "<a href='#' onClick=\"MIDIjs.play('/midis/" . $filename . "');\">Play " . $title . "</a>"; |
@@ -202,9 +202,9 @@ discard block |
||
| 202 | 202 | <script type="text/javascript" src="//cdn.jsdelivr.net/gh/deskjet/chiptune2.js@master/chiptune2.js"></script>'; |
| 203 | 203 | echo '<a class="song" data-modurl="/midis/' . $filename . '" href="#">Play ' . $title . '</a>'; |
| 204 | 204 | } else if($type == "news" || $type == "review") { |
| 205 | - //do nothing |
|
| 205 | + //do nothing |
|
| 206 | 206 | } else if($type == "video") { |
| 207 | - echo ' <video width="640" height="400" controls> |
|
| 207 | + echo ' <video width="640" height="400" controls> |
|
| 208 | 208 | <source src="/videos/' . $filename . '" type="video/mp4"> |
| 209 | 209 | </video> '; |
| 210 | 210 | } else { |
@@ -7,13 +7,13 @@ discard block |
||
| 7 | 7 | require(__DIR__ . "/func/func.php"); |
| 8 | 8 | require(__DIR__ . "/func/conn.php"); |
| 9 | 9 | |
| 10 | - if(isset($_GET['id'])) { |
|
| 10 | + if (isset($_GET['id'])) { |
|
| 11 | 11 | $stmt = $conn->prepare("SELECT * FROM files WHERE id = ?"); |
| 12 | 12 | $stmt->bind_param("i", $_GET['id']); |
| 13 | 13 | $stmt->execute(); |
| 14 | 14 | $result = $stmt->get_result(); |
| 15 | - if($result->num_rows === 0) echo('There are no users.'); |
|
| 16 | - while($row = $result->fetch_assoc()) { |
|
| 15 | + if ($result->num_rows === 0) echo('There are no users.'); |
|
| 16 | + while ($row = $result->fetch_assoc()) { |
|
| 17 | 17 | $author = $row['author']; |
| 18 | 18 | $id = $row['id']; |
| 19 | 19 | $date = $row['date']; |
@@ -23,7 +23,7 @@ discard block |
||
| 23 | 23 | $status = $row['status']; |
| 24 | 24 | $filename = $row['filename']; |
| 25 | 25 | |
| 26 | - if($status != "y") { |
|
| 26 | + if ($status != "y") { |
|
| 27 | 27 | die("Item is not approved yet."); |
| 28 | 28 | } |
| 29 | 29 | } |
@@ -37,11 +37,11 @@ discard block |
||
| 37 | 37 | |
| 38 | 38 | <div class="container"> |
| 39 | 39 | <?php |
| 40 | - if($_SERVER['REQUEST_METHOD'] == 'POST') |
|
| 40 | + if ($_SERVER['REQUEST_METHOD'] == 'POST') |
|
| 41 | 41 | { |
| 42 | - if(!isset($_SESSION['user'])){ $error = "you are not logged in"; goto skipcomment; } |
|
| 43 | - if(!$_POST['comment']){ $error = "your comment cannot be blank"; goto skipcomment; } |
|
| 44 | - if(strlen($_POST['comment']) > 500){ $error = "your comment must be shorter than 500 characters"; goto skipcomment; } |
|
| 42 | + if (!isset($_SESSION['user'])) { $error = "you are not logged in"; goto skipcomment; } |
|
| 43 | + if (!$_POST['comment']) { $error = "your comment cannot be blank"; goto skipcomment; } |
|
| 44 | + if (strlen($_POST['comment']) > 500) { $error = "your comment must be shorter than 500 characters"; goto skipcomment; } |
|
| 45 | 45 | |
| 46 | 46 | $stmt = $conn->prepare("INSERT INTO `gamecomments` (toid, author, text, date) VALUES (?, ?, ?, now())"); |
| 47 | 47 | $stmt->bind_param("sss", $_GET['id'], $_SESSION['user'], $text); |
@@ -52,7 +52,7 @@ discard block |
||
| 52 | 52 | $stmt->close(); |
| 53 | 53 | } |
| 54 | 54 | skipcomment: |
| 55 | - if(isset($error)) { |
|
| 55 | + if (isset($error)) { |
|
| 56 | 56 | echo "<span style='color: red;'><small>" . $error . "</small></span><br>"; |
| 57 | 57 | } |
| 58 | 58 | |
@@ -64,17 +64,17 @@ discard block |
||
| 64 | 64 | <br><br>" . $extrainfo . "</small><hr>"; |
| 65 | 65 | ?> |
| 66 | 66 | <?php |
| 67 | - if($type == "song") { |
|
| 67 | + if ($type == "song") { |
|
| 68 | 68 | echo '<audio controls> |
| 69 | 69 | <source src="/musicfiles/' . $filename . '"> |
| 70 | 70 | </audio>'; |
| 71 | - } else if($type == "image") { |
|
| 71 | + } else if ($type == "image") { |
|
| 72 | 72 | echo "<img style='max-width: 100%;' src='/images/" . $filename . "'>"; |
| 73 | - } else if($type == "midi") { |
|
| 73 | + } else if ($type == "midi") { |
|
| 74 | 74 | echo "Note: It may take a few seconds for the MIDI to load.<br>"; |
| 75 | 75 | echo "<a href='#' onClick=\"MIDIjs.play('/midis/" . $filename . "');\">Play " . $title . "</a>"; |
| 76 | 76 | echo "<br><a href='#' onClick='MIDIjs.stop();'>Stop MIDI Playback</a>"; |
| 77 | - } else if($type == "chiptune") { |
|
| 77 | + } else if ($type == "chiptune") { |
|
| 78 | 78 | //the way i did this absolutely sucks and im |
| 79 | 79 | echo '<script type="text/javascript"> |
| 80 | 80 | window["libopenmpt"] = {}; |
@@ -201,9 +201,9 @@ discard block |
||
| 201 | 201 | <script type="text/javascript" src="//cdn.jsdelivr.net/gh/deskjet/chiptune2.js@master/libopenmpt.js"></script> |
| 202 | 202 | <script type="text/javascript" src="//cdn.jsdelivr.net/gh/deskjet/chiptune2.js@master/chiptune2.js"></script>'; |
| 203 | 203 | echo '<a class="song" data-modurl="/midis/' . $filename . '" href="#">Play ' . $title . '</a>'; |
| 204 | - } else if($type == "news" || $type == "review") { |
|
| 204 | + } else if ($type == "news" || $type == "review") { |
|
| 205 | 205 | //do nothing |
| 206 | - } else if($type == "video") { |
|
| 206 | + } else if ($type == "video") { |
|
| 207 | 207 | echo ' <video width="640" height="400" controls> |
| 208 | 208 | <source src="/videos/' . $filename . '" type="video/mp4"> |
| 209 | 209 | </video> '; |
@@ -223,7 +223,7 @@ discard block |
||
| 223 | 223 | $result = $stmt->get_result(); |
| 224 | 224 | ?> |
| 225 | 225 | <div class="commentsList"> |
| 226 | - <?php while($row = $result->fetch_assoc()) { ?> |
|
| 226 | + <?php while ($row = $result->fetch_assoc()) { ?> |
|
| 227 | 227 | <div class='commentRight' style='display: grid; grid-template-columns: auto 85%; padding:5px;'> |
| 228 | 228 | <div> |
| 229 | 229 | <a style='float: left;' href='/?id=<?php echo getID($row['author'], $conn); ?>'><?php echo $row['author']; ?></a> |
@@ -232,7 +232,7 @@ discard block |
||
| 232 | 232 | </div> |
| 233 | 233 | <div style="word-wrap: break-word;"> |
| 234 | 234 | <small><?php echo $row['date']; ?></small> |
| 235 | - <?php echo validateMarkdown($row['text']);?> |
|
| 235 | + <?php echo validateMarkdown($row['text']); ?> |
|
| 236 | 236 | </div> |
| 237 | 237 | </div> |
| 238 | 238 | <?php } ?> |
@@ -12,7 +12,9 @@ |
||
| 12 | 12 | $stmt->bind_param("i", $_GET['id']); |
| 13 | 13 | $stmt->execute(); |
| 14 | 14 | $result = $stmt->get_result(); |
| 15 | - if($result->num_rows === 0) echo('There are no users.'); |
|
| 15 | + if($result->num_rows === 0) { |
|
| 16 | + echo('There are no users.'); |
|
| 17 | + } |
|
| 16 | 18 | while($row = $result->fetch_assoc()) { |
| 17 | 19 | $author = $row['author']; |
| 18 | 20 | $id = $row['id']; |
@@ -16,8 +16,8 @@ discard block |
||
| 16 | 16 | if ($_SERVER['REQUEST_METHOD'] == 'GET' && isset($_GET["r_login"])) { |
| 17 | 17 | $error = "The page you tried to access requires you to be logged in."; |
| 18 | 18 | } |
| 19 | - if($_SERVER['REQUEST_METHOD'] == 'POST' && $_POST['password'] && $_POST['username']) { |
|
| 20 | - if(isset($_POST['remember'])) { |
|
| 19 | + if ($_SERVER['REQUEST_METHOD'] == 'POST' && $_POST['password'] && $_POST['username']) { |
|
| 20 | + if (isset($_POST['remember'])) { |
|
| 21 | 21 | $rememberMe = true; |
| 22 | 22 | } else { |
| 23 | 23 | $rememberMe = false; |
@@ -26,12 +26,12 @@ discard block |
||
| 26 | 26 | $stmt->bind_param("s", $_POST['username']); |
| 27 | 27 | $stmt->execute(); |
| 28 | 28 | $result = $stmt->get_result(); |
| 29 | - if(!mysqli_num_rows($result)){ { $error = "incorrect username or password"; goto skip; } } |
|
| 29 | + if (!mysqli_num_rows($result)) { { $error = "incorrect username or password"; goto skip; } } |
|
| 30 | 30 | |
| 31 | 31 | $row = $result->fetch_assoc(); |
| 32 | 32 | $hash = $row['password']; |
| 33 | 33 | |
| 34 | - if(!password_verify($_POST['password'], $hash)) { |
|
| 34 | + if (!password_verify($_POST['password'], $hash)) { |
|
| 35 | 35 | $error = "incorrect username or password"; goto skip; |
| 36 | 36 | } |
| 37 | 37 | |
@@ -42,7 +42,7 @@ discard block |
||
| 42 | 42 | if (isset($result['otpsecret'])) { |
| 43 | 43 | $otp = true; |
| 44 | 44 | if (isset($_POST['totp'])) { |
| 45 | - if ($_POST['totp'] === $result['otpbackupcode']) {goto skip2fa;} |
|
| 45 | + if ($_POST['totp'] === $result['otpbackupcode']) {goto skip2fa; } |
|
| 46 | 46 | require("vendor/autoload.php"); |
| 47 | 47 | $totp = OTPHP\TOTP::create($result['otpsecret']); |
| 48 | 48 | if (!$totp->verify($_POST['totp'])) { |
@@ -56,7 +56,7 @@ discard block |
||
| 56 | 56 | } |
| 57 | 57 | skip2fa: |
| 58 | 58 | |
| 59 | - if($rememberMe == true) { |
|
| 59 | + if ($rememberMe == true) { |
|
| 60 | 60 | session_write_close(); |
| 61 | 61 | session_set_cookie_params("2678400"); |
| 62 | 62 | ini_set('session.gc_maxlifetime', 2678400); |
@@ -70,7 +70,7 @@ discard block |
||
| 70 | 70 | } |
| 71 | 71 | skip: |
| 72 | 72 | |
| 73 | - if(isset($error)) { echo "<small style='color:red'>".$error."</small>"; } |
|
| 73 | + if (isset($error)) { echo "<small style='color:red'>" . $error . "</small>"; } |
|
| 74 | 74 | ?> |
| 75 | 75 | <form method="post"> |
| 76 | 76 | <input required placeholder="Username" type="text" name="username"><br> |
@@ -12,8 +12,8 @@ discard block |
||
| 12 | 12 | <body> |
| 13 | 13 | <?php require(__DIR__ . "/important/header.php"); |
| 14 | 14 | |
| 15 | - if(@$_POST['submit']) { |
|
| 16 | - if(isset($_SESSION['user'])) { |
|
| 15 | + if (@$_POST['submit']) { |
|
| 16 | + if (isset($_SESSION['user'])) { |
|
| 17 | 17 | $target_dir = __DIR__ . "/musicfiles/"; |
| 18 | 18 | $target_file = $target_dir . basename($_FILES["fileToUpload"]["name"]); |
| 19 | 19 | $uploadOk = 1; |
@@ -23,7 +23,7 @@ discard block |
||
| 23 | 23 | echo 'file with the same name already exists<hr>'; |
| 24 | 24 | $uploadOk = 0; |
| 25 | 25 | } |
| 26 | - if($imageFileType != "ogg" && $imageFileType != "mp3") { |
|
| 26 | + if ($imageFileType != "ogg" && $imageFileType != "mp3") { |
|
| 27 | 27 | echo 'unsupported file type. must be ogg or mp3<hr>'; |
| 28 | 28 | $uploadOk = 0; |
| 29 | 29 | } |
@@ -19,7 +19,7 @@ discard block |
||
| 19 | 19 | $stmt = $conn->prepare("SELECT * FROM files WHERE id = 27"); |
| 20 | 20 | $stmt->execute(); |
| 21 | 21 | $result = $stmt->get_result(); |
| 22 | - while($row = $result->fetch_assoc()) { |
|
| 22 | + while ($row = $result->fetch_assoc()) { |
|
| 23 | 23 | echo "<br><img style='height: 5em;position: absolute;border: 1px solid white; width: 5em;' src='pfp/" . getPFP($row['author'], $conn) . "'> |
| 24 | 24 | <small> |
| 25 | 25 | <a href='view.php?id=" . $row['id'] . "'><span style='float:right;color: gold;'><i>[" . $row['agerating'] . "] " . $row['title'] . "</a></i></span><br> |
@@ -38,7 +38,7 @@ discard block |
||
| 38 | 38 | $stmt = $conn->prepare("SELECT * FROM files WHERE id = 1"); |
| 39 | 39 | $stmt->execute(); |
| 40 | 40 | $result = $stmt->get_result(); |
| 41 | - while($row = $result->fetch_assoc()) { |
|
| 41 | + while ($row = $result->fetch_assoc()) { |
|
| 42 | 42 | echo "<br><img style='height: 5em;position: absolute;border: 1px solid white; width: 5em;' src='pfp/" . getPFP($row['author'], $conn) . "'> |
| 43 | 43 | <small> |
| 44 | 44 | <a href='view.php?id=" . $row['id'] . "'><span style='float:right;color: gold;'><i>[" . $row['agerating'] . "] " . $row['title'] . "</a></i></span><br> |
@@ -12,8 +12,8 @@ discard block |
||
| 12 | 12 | <body> |
| 13 | 13 | <?php require(__DIR__ . "/important/header.php"); |
| 14 | 14 | |
| 15 | - if(@$_POST['submit']) { |
|
| 16 | - if(isset($_SESSION['user'])) { |
|
| 15 | + if (@$_POST['submit']) { |
|
| 16 | + if (isset($_SESSION['user'])) { |
|
| 17 | 17 | $target_dir = __DIR__ . "/gamefiles/"; |
| 18 | 18 | $target_file = $target_dir . basename($_FILES["fileToUpload"]["name"]); |
| 19 | 19 | $uploadOk = 1; |
@@ -23,7 +23,7 @@ discard block |
||
| 23 | 23 | echo 'file with the same name already exists<hr>'; |
| 24 | 24 | $uploadOk = 0; |
| 25 | 25 | } |
| 26 | - if($imageFileType != "swf") { |
|
| 26 | + if ($imageFileType != "swf") { |
|
| 27 | 27 | echo 'unsupported file type. must be swf<hr>'; |
| 28 | 28 | $uploadOk = 0; |
| 29 | 29 | } |
@@ -12,18 +12,18 @@ |
||
| 12 | 12 | <body> |
| 13 | 13 | <?php require(__DIR__ . "/important/header.php"); |
| 14 | 14 | |
| 15 | - if(isset($_GET['id'])) { |
|
| 15 | + if (isset($_GET['id'])) { |
|
| 16 | 16 | $stmt = $conn->prepare("SELECT * FROM files WHERE author = ? AND id = ?"); |
| 17 | 17 | $stmt->bind_param("si", $_SESSION['user'], $_GET['id']); |
| 18 | 18 | $stmt->execute(); |
| 19 | 19 | $result = $stmt->get_result(); |
| 20 | - if($result->num_rows === 0) die('Item doesnt exist or item isnt made by you.'); |
|
| 20 | + if ($result->num_rows === 0) die('Item doesnt exist or item isnt made by you.'); |
|
| 21 | 21 | } else { |
| 22 | 22 | header("Location: index.php"); |
| 23 | 23 | } |
| 24 | 24 | |
| 25 | - if(@$_POST['submit']) { |
|
| 26 | - if(isset($_SESSION['user'])) { |
|
| 25 | + if (@$_POST['submit']) { |
|
| 26 | + if (isset($_SESSION['user'])) { |
|
| 27 | 27 | $stmt = $conn->prepare("UPDATE files SET title = ?, extrainfo = ? WHERE id = ?"); |
| 28 | 28 | $stmt->bind_param("ssi", $title, $description, $_GET['id']); |
| 29 | 29 | $title = htmlspecialchars($_POST['title']); |
@@ -17,7 +17,9 @@ |
||
| 17 | 17 | $stmt->bind_param("si", $_SESSION['user'], $_GET['id']); |
| 18 | 18 | $stmt->execute(); |
| 19 | 19 | $result = $stmt->get_result(); |
| 20 | - if($result->num_rows === 0) die('Item doesnt exist or item isnt made by you.'); |
|
| 20 | + if($result->num_rows === 0) { |
|
| 21 | + die('Item doesnt exist or item isnt made by you.'); |
|
| 22 | + } |
|
| 21 | 23 | } else { |
| 22 | 24 | header("Location: index.php"); |
| 23 | 25 | } |
@@ -12,8 +12,8 @@ |
||
| 12 | 12 | <body> |
| 13 | 13 | <?php require(__DIR__ . "/important/header.php"); |
| 14 | 14 | |
| 15 | - if(@$_POST['submit']) { |
|
| 16 | - if(isset($_SESSION['user'])) { |
|
| 15 | + if (@$_POST['submit']) { |
|
| 16 | + if (isset($_SESSION['user'])) { |
|
| 17 | 17 | $stmt = $conn->prepare("INSERT INTO files (type, title, extrainfo, author, filename) VALUES ('news', ?, ?, ?, '')"); |
| 18 | 18 | $stmt->bind_param("sss", $title, $description, $_SESSION['user']); |
| 19 | 19 | |
@@ -2,13 +2,13 @@ |
||
| 2 | 2 | require(__DIR__ . "/func/func.php"); |
| 3 | 3 | require(__DIR__ . "/func/conn.php"); |
| 4 | 4 | |
| 5 | -if(isset($_SESSION['user'])) { |
|
| 6 | - if(isset($_GET['id'])) { |
|
| 5 | +if (isset($_SESSION['user'])) { |
|
| 6 | + if (isset($_GET['id'])) { |
|
| 7 | 7 | $stmt = $conn->prepare("SELECT * FROM `groups` WHERE id = ?"); |
| 8 | 8 | $stmt->bind_param("i", $_GET['id']); |
| 9 | 9 | $stmt->execute(); |
| 10 | 10 | $result = $stmt->get_result(); |
| 11 | - if($result->num_rows === 0) { |
|
| 11 | + if ($result->num_rows === 0) { |
|
| 12 | 12 | die("Group doesn't exist"); |
| 13 | 13 | } |
| 14 | 14 | $stmt->close(); |