Рефакторинг, очистка, работа над ошибками, связанными с базой, отказ от глобальной переменной $user во многих файлах.
Singleton в некоторых местах вместо решения #42. Новые шаги для решения #16 и #52. Closes #42. Closes #32. Closes #31.
This commit is contained in:
+10
-12
@@ -1,6 +1,6 @@
|
||||
<?php
|
||||
|
||||
use Battles\Database\DBPDO;
|
||||
use Battles\Database\Db;
|
||||
use Battles\Template;
|
||||
|
||||
require_once("config.php");
|
||||
@@ -37,16 +37,15 @@ $operation = new class {
|
||||
|
||||
public function sendRecoveryMail(string $to): string
|
||||
{
|
||||
$db = new DBPDO();
|
||||
$check = $db->ofetch('SELECT email FROM users WHERE login = ?', $to);
|
||||
if (!$check) {
|
||||
$check = Db::getInstance()->ofetch('SELECT email FROM users WHERE login = ?', $to);
|
||||
if (!empty(Db::getInstance()->fetchColumn('select email from users where login = ?', $to))) {
|
||||
return ERROR_WRONG_LOGIN;
|
||||
}
|
||||
if ($db->ofetch('SELECT 1 FROM users_recovery WHERE login = ?', $to)) {
|
||||
if (!empty(Db::getInstance()->ofetch('SELECT 1 FROM users_recovery WHERE login = ?', $to))) {
|
||||
return ERROR_TOO_MANY_TRIES;
|
||||
}
|
||||
$hash = bin2hex(random_bytes(8));
|
||||
$db->execute('INSERT INTO users_recovery (login, hash, ip, date) VALUES (?,?,?,?)', [$to, $hash, date('Y-m-d', strtotime('+1days')), $_SERVER['REMOTE_ADDR']]);
|
||||
Db::getInstance()->execute('INSERT INTO users_recovery (login, hash, ip, date) VALUES (?,?,?,?)', [$to, $hash, date('Y-m-d', strtotime('+1days')), $_SERVER['REMOTE_ADDR']]);
|
||||
$message = "Здравствуйте!<br><br>
|
||||
Кто-то запросил восстановление пароля к вашему персонажу " . $to . ".<br><br>
|
||||
Для смены пароля пройдите по
|
||||
@@ -58,19 +57,18 @@ $operation = new class {
|
||||
|
||||
public function isAllowed($hash)
|
||||
{
|
||||
return DBPDO::INIT()->fetch('SELECT 1 FROM users_recovery WHERE hash = ? AND date < ?', [$hash, date('Y-m-d')]) ? true : ERROR_OLD_HASH;
|
||||
return Db::getInstance()->execute('SELECT 1 FROM users_recovery WHERE hash = ? AND date < ?', [$hash, date('Y-m-d')])->fetchColumn() ? true : ERROR_OLD_HASH;
|
||||
}
|
||||
|
||||
public function setNewPassword(string $newPassword, string $hash):string
|
||||
{
|
||||
$db = new DBPDO();
|
||||
$row = $db->ofetch('SELECT login FROM users_recovery WHERE hash = ?', $hash);
|
||||
if (!$row) {
|
||||
$login = Db::getInstance()->execute('select login from users_recovery where hash = ?', $hash)->fetchColumn();
|
||||
if (empty($login)) {
|
||||
return ERROR_WRONG_HASH;
|
||||
}
|
||||
$newPassword = password_hash($newPassword, PASSWORD_DEFAULT);
|
||||
$db->execute('UPDATE users SET pass = ? WHERE login = ?', [$newPassword, $row->login]);
|
||||
$db->execute('DELETE FROM users_recovery WHERE hash = ?', $hash);
|
||||
Db::getInstance()->execute('UPDATE users SET pass = ? WHERE login = ?', [$newPassword, $login]);
|
||||
Db::getInstance()->execute('DELETE FROM users_recovery WHERE hash = ?', $hash);
|
||||
return OK_PASSWORD_CHANGED;
|
||||
}
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user