cvs: bugtracker /htdocs .htaccess /htdocs/elements screen.css /includes email.php template.php user.php /template/generic header.html
/template/generic/user convert.php create.php help.php
| From: | Barry Carlyon | Date: | Mon, 11 Aug 2008 19:49:50 +0000 |
| Subject: | cvs: bugtracker /htdocs .htaccess /htdocs/elements screen.css /includes email.php template.php user.php /template/generic header.html /template/generic/user convert.php create.php help.php |
||
| Groups: | php.webmaster | ||
| Request: | Send a blank email to php-webmaster+get-2377@lists.php.net to get a copy of this message | ||
bcarlyon Mon Aug 11 19:49:50 2008 UTC
Added files:
/bugtracker/template/generic/user create.php help.php
Modified files:
/bugtracker/htdocs .htaccess
/bugtracker/htdocs/elements screen.css
/bugtracker/includes email.php template.php user.php
/bugtracker/template/generic header.html
/bugtracker/template/generic/user convert.php
Log:
Minor Fixes/updates
Added the user create functions for standard accounts
Added user help, for resend email verifications
Need to do the password recovery functionality
http://cvs.php.net/viewvc.cgi/bugtracker/htdocs/.htaccess?r1=1.6&r2=1.7&diff_format=u Index: bugtracker/htdocs/.htaccess diff -u bugtracker/htdocs/.htaccess:1.6 bugtracker/htdocs/.htaccess:1.7 --- bugtracker/htdocs/.htaccess:1.6 Sun Aug 10 23:39:57 2008 +++ bugtracker/htdocs/.htaccess Mon Aug 11 19:49:49 2008 @@ -17,8 +17,10 @@ #Other shuntage RewriteRule ^login(/)?$ /user/login/ [L,PT] -RewriteRule ^user/verify/(.*)/(.*)$ index/index.php?page=user/verify&email=$1&tehkey=$2 [L,PT] +RewriteRule ^user/verify/(.*)/(.*)?$ index/index.php?page=user/verify&email=$1&tehkey=$2 [L,PT] +RewriteRule ^(.*)/(.*)/(.+)$ index/index.php?page=$1/$2&method=$3 [L,PT] +#RewriteRule ^(.*)/(.*)/(.*)/(.+)$ index/index.php?page=$1/$2&method=$3&resouece=$4 [L,PT] #the big rewrite -RewriteRule (.*)$ index/index.php?page=$1&%{QUERY_STRING} [L,PT] +RewriteRule (.*)$ index/index.php?page=$1&%{QUERY_STRING} [L,PT] http://cvs.php.net/viewvc.cgi/bugtracker/htdocs/elements/screen.css?r1=1.9&r2=1.10&diff_format=u Index: bugtracker/htdocs/elements/screen.css diff -u bugtracker/htdocs/elements/screen.css:1.9 bugtracker/htdocs/elements/screen.css:1.10 --- bugtracker/htdocs/elements/screen.css:1.9 Thu Aug 7 14:27:20 2008 +++ bugtracker/htdocs/elements/screen.css Mon Aug 11 19:49:49 2008 @@ -8,7 +8,12 @@ background: #FFFFFF; color: #000000; } -p, a, li, body { +#main_drag { + margin-left: 10px; + margin-right: 10px; + margin-bottom: 10px; +} +p, a, li, body, #main_drag { font-family: verdana, arial, helvetica, sans-serif; color: #000000; } http://cvs.php.net/viewvc.cgi/bugtracker/includes/email.php?r1=1.6&r2=1.7&diff_format=u Index: bugtracker/includes/email.php diff -u bugtracker/includes/email.php:1.6 bugtracker/includes/email.php:1.7 --- bugtracker/includes/email.php:1.6 Mon Aug 11 10:51:22 2008 +++ bugtracker/includes/email.php Mon Aug 11 19:49:49 2008 @@ -69,8 +69,8 @@ 'X-Mailer' => 'PHP Bugtracker, PHP' . phpversion() ); - $this->send_email(); - return; + return $this->send_email(); +// return; } function send_to_assigned($bug_id) { } http://cvs.php.net/viewvc.cgi/bugtracker/includes/template.php?r1=1.14&r2=1.15&diff_format=u Index: bugtracker/includes/template.php diff -u bugtracker/includes/template.php:1.14 bugtracker/includes/template.php:1.15 --- bugtracker/includes/template.php:1.14 Mon Aug 11 10:51:22 2008 +++ bugtracker/includes/template.php Mon Aug 11 19:49:49 2008 @@ -58,7 +58,7 @@ public $content_title = ' '; // public $login = '<li> </li>'; - public $login = '<li><a href="/login/" title="Login">Login</a></li>'; + public $login = '<li><a href="/user/create/" title="Create">Create</a></li><li><a href="/login/" title="Login">Login</a></li>'; public $template_data = array(); public $form_data = array(); @@ -145,7 +145,7 @@ function generate_footer() { global $db, $trace; - $this->html .= file_get_contents($_SERVER['DOCUMENT_ROOT'] . '../template/generic/footer.html'); + $this->html .= '</div>' . file_get_contents($_SERVER['DOCUMENT_ROOT'] . '../template/generic/footer.html'); $this->swap('queries', $db->query_count ); $this->swap('year', date('Y',time()) ); $this->swap('last', date('r',filemtime($this->template_file))); http://cvs.php.net/viewvc.cgi/bugtracker/includes/user.php?r1=1.12&r2=1.13&diff_format=u Index: bugtracker/includes/user.php diff -u bugtracker/includes/user.php:1.12 bugtracker/includes/user.php:1.13 --- bugtracker/includes/user.php:1.12 Mon Aug 11 10:51:22 2008 +++ bugtracker/includes/user.php Mon Aug 11 19:49:49 2008 @@ -205,7 +205,7 @@ $subject .= ' Creation'; $message .= 'have signed up to use the phpBugtracker over at http://bugs.php.net/'; } - $message .= "\n\r" . 'In order to continue you will need to verfiy your email address'; + $message .= "\n\r" . 'In order to continue you will need to verifiy your email address'; $message .= "\n\r" . 'Click the following link, or copy and paste it into your browser'; $message .= "\n\r\n\r"; @@ -217,30 +217,37 @@ $email->send_to_user($dest,$subject,$message); } + else + { + trigger_error('Failed to add you to the database',E_USER_ERROR); + } return TRUE; } function login($user,$password) { - global $form_data,$db; - //lets authenticate the user - $query = 'SELECT * FROM ' . USER_TABLE . ' WHERE handle = \'' . $db->protect_data($user) . '\' AND password = \'' . $password . '\''; - $db->get_data($query); - $valid = $db->total_rows; + global $form_data,$db,$template; - //try email - $query = 'SELECT * FROM ' . USER_TABLE . ' WHERE email = \'' . $db->protect_data($user) . '\' AND password = \'' . $password . '\''; + //lets authenticate the user + $query = 'SELECT * FROM ' . USER_TABLE . ' WHERE (handle = \'' . $db->protect_data($user) . '\' OR email = \'' . $db->protect_data($user) . '\') AND password = \'' . $password . '\''; $db->get_data($query); - $valid = ($valid) ? $valid : $db->total_rows; - if ($valid) + if ($db->total_rows) { //so lets make sure we have this right $user_row = $db->fetch_row(); + + if ($user_row['account_type'] != USER) + { + //arg! not verified? + trigger_error('Your account has not been verified or is invalid<br /><a href="/user/help/" title="Help">Get Account Help</a>',E_USER_ERROR); + } + $this->handle = $user_row['handle']; if ($this->write_cookie('',$form_data['return'])) { + $user->logged_in = TRUE; return TRUE; } - $form_data['form_error'] = 'The Cookie could not be set'; + $template->system_error = 'The Cookie could not be set'; } //try temp @@ -308,6 +315,15 @@ return TRUE; } } + if ($mode == 'email') + { + $query = 'SELECT * FROM ' . USER_TABLE . ' WHERE email = \'' . $db->protect_data($search) . '\''; + $db->get_data($query); + if ($db->total_rows) + { + return TRUE; + } + } return FALSE; } function update_password($password,$email,$handle = '',$mode = '') { http://cvs.php.net/viewvc.cgi/bugtracker/template/generic/header.html?r1=1.8&r2=1.9&diff_format=u Index: bugtracker/template/generic/header.html diff -u bugtracker/template/generic/header.html:1.8 bugtracker/template/generic/header.html:1.9 --- bugtracker/template/generic/header.html:1.8 Thu Aug 7 13:31:55 2008 +++ bugtracker/template/generic/header.html Mon Aug 11 19:49:49 2008 @@ -63,5 +63,7 @@ <a name="content"></a><h2>{CONTENT_TITLE}</h2> +<div id="main_drag"> + {SYSTEM_ERROR} http://cvs.php.net/viewvc.cgi/bugtracker/template/generic/user/convert.php?r1=1.9&r2=1.10&diff_format=u Index: bugtracker/template/generic/user/convert.php diff -u bugtracker/template/generic/user/convert.php:1.9 bugtracker/template/generic/user/convert.php:1.10 --- bugtracker/template/generic/user/convert.php:1.9 Mon Aug 11 10:51:25 2008 +++ bugtracker/template/generic/user/convert.php Mon Aug 11 19:49:50 2008 @@ -237,3 +237,4 @@ { $template->prehtml = $content; } + http://cvs.php.net/viewvc.cgi/bugtracker/template/generic/user/create.php?view=markup&rev=1.1 Index: bugtracker/template/generic/user/create.php +++ bugtracker/template/generic/user/create.php <?php /* Copyright (c) 2008, Barry Carlyon <bcarlyon@php.net> All rights reserved. Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met: * Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer. * Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution. * Neither the name of the GSOC_PHP_BUGTRACKER nor the names of its contributors may be used to endorse or promote products derived from this software without specific prior written permission. THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. */ require_once($_SERVER['DOCUMENT_ROOT'] . '../includes/recaptchalib.php'); $template->page_title .= 'Create a Account'; $template->content_title = 'Create a Account'; $content = ''; if ($user->logged_in_temp) { header("Location: /user/convert/"); } else if ($user->logged_in) { trigger_error('You are logged in already', E_USER_ERROR); } $method = loadvar('method'); $form_data = array(); $error_data = array(); switch ($method) { case('create'): { $form_data['handle'] = loadvar('handle'); $form_data['email'] = loadvar('email'); $form_data['password'] = loadvar('password'); foreach($form_data as $ref => $data) { $error_data[$ref] = $data ? FALSE : TRUE; } $error_data['email'] = check_email_mx($form_data['email']) ? FALSE : '* Invalid'; if ($user->fetch_handle($form_data['handle'])) $error_data['handle'] = '* Already in use'; if ($user->fetch_handle($form_data['email'],'email')) $error_data['email'] = '* Already in use'; $errors = FALSE; $recap_resp = recaptcha_check_answer($recaptcha_prv,$_SERVER['REMOTE_ADDR'],loadvar('recaptcha_challenge_field'),loadvar('recaptcha_response_field')); if ($recap_resp->is_valid) { $error_data['captcha'] = FALSE; } else { $error_data['captcha'] = 'The Captcha is invalid'; $form_data['recap_error'] = $recap_resp->error; } foreach ($error_data as $ref => $empty) { if ($empty) { $errors = TRUE; if (strlen($empty) == 1) $error_data[$ref] = '* Required'; } } if (!$errors) { //generate user_data and pass it to the register function $user_data = array(); $user_data['handle'] = $form_data['handle']; $user_data['password'] = md5($form_data['password']); $user_data['email'] = $form_data['email']; if ($user->register($user_data)) { $content = '<div id="success">You have been added to our records<br />You know need to validate your email address'; $content .= '<br />We have sent you an email to the address your provided to facillitate this'; $content .= '</div>'; break; } else { $template->system_error = 'Unknown drop through, code: register013'; unset($form_data,$error_data); $form_data = $error_data = array(); } } else { $form_data['form_error'] = 'Please correct the errors shown'; } } default: { $form_data['form_error'] = isset($form_data['form_error']) ? $form_data['form_error'] : ''; $form_data['recap_error'] = isset($form_data['recap_error']) ? $form_data['recap_error'] : ''; $content .= ' <p>To register for the Bugtracker, you need to first verify your email address.</p> {FORM_FORM_ERROR} <form action="/user/create/" method="post" class="form"> <input type="hidden" name="method" value="create" /> <div class="slim"> <label for="handle">Desired Handle:</label> {ERROR_HANDLE} <input type="text" name="handle" id="handle" value="{FORM_HANDLE}" /> <br /><br /> <label for="email">Email Address:</label> {ERROR_EMAIL} <input type="text" name="email" id="email" value="{FORM_EMAIL}" /> <br /><br /> <label for="password">Password:</label> {ERROR_PASSWORD} <input type="password" name="password" id="password" value="" /> <br /><br /> <label for="captcha">Captcha: {ERROR_CAPTCHA}</label> <div id="captcha">'; $content .= recaptcha_get_html($recaptcha_key,$form_data['recap_error']); $content .= ' <br /><br /> <input type="submit" name="submit" id="submit" value="Create Account" /> <br /><br /> </div> </form> '; } } $content = $template->dontloop(array('form' => $form_data, 'error' => $error_data), $content); $template->prehtml = $content; http://cvs.php.net/viewvc.cgi/bugtracker/template/generic/user/help.php?view=markup&rev=1.1 Index: bugtracker/template/generic/user/help.php +++ bugtracker/template/generic/user/help.php <?php /* Copyright (c) 2008, Barry Carlyon <bcarlyon@php.net> All rights reserved. Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met: * Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer. * Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution. * Neither the name of the GSOC_PHP_BUGTRACKER nor the names of its contributors may be used to endorse or promote products derived from this software without specific prior written permission. THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. */ $template->page_title .= 'Account Help'; $template->content_title = 'Account Help'; $method = str_replace('/','',loadvar('method')); $resource = str_replace('/','',loadvar('resource')); $content = ''; switch($method) { case('resend'): case('recover'): case('check'): { if ($resource) { //verify the data we have $query = 'SELECT email,handle,account_type,password FROM ' . USER_TABLE . ' WHERE handle = \'' . $resource . '\' OR email = \'' . $resource . '\''; $db->get_data($query); if (!$db->total_rows) { $user_data = FALSE; } else { $user_data = $db->fetch_row(); } //lets see if they are in the temp user table $query = 'SELECT handle,email,password FROM ' . TEMP_USER_TABLE . ' WHERE handle = \'' . $resource . '\' OR email = \'' . $resource . '\''; $db->get_data($query); $temp_data = array(); if ($db->total_rows) { $temp_data = $db->fetch_row(); $temp_data['account_type'] = TEMP_ACCOUNT; } else { $temp_data = FALSE; } switch($method) { case('resend'): { if (!$user_data) { //user is not in the user table //check for temp if so send to converter if ($temp_data) { $template->meta_refresh('/user/login/'); trigger_error('You need to login to continue', E_USER_ERROR); } else { trigger_error('The data you supploed is invalid', E_USER_ERROR); } } if ($user_data['account_type'] == 2) { trigger_error('This account has been verfied',E_USER_ERROR); } // so resend verif $dest = $user_data['email']; $subject = 'PHP Bugz Account'; $message = 'You or someone else '; if (!$user_data['account_type']) { $subject .= ' Conversion'; $message .= 'has converted your http://bugs.php.net/ Account to a full account'; } else { $subject .= ' Creation'; $message .= 'have signed up to use the phpBugtracker over at http://bugs.php.net/'; } $message .= "\n\r" . 'In order to continue you will need to verifiy your email address'; $message .= "\n\r" . 'Click the following link, or copy and paste it into your browser'; $message .= "\n\r\n\r"; $message .= 'http://' . $_SERVER['HTTP_HOST'] . '/user/verify/'; $message .= $dest . '/'; $message .= md5( md5($dest) . '_' . md5 ($user_data['password']) ); $message .= "\n\r\n\r"; if ($email->send_to_user($dest,$subject,$message)) { $content .= '<div id="success">Successfully Resent the email confirm email</div>'; } else { trigger_error('Failed to resend the confirm email', E_USER_ERROR); } break; } case('check'): { //if the user is a temp and not a real one, call user convert if (isset($user_data['account_type'])) { if ($user_data['account_type'] == 2) { $content .= 'This account is a full account'; } else { $content .= 'This account appears to be part converted, awaiting verification of your email address'; } $content .= '<br /><br />'; break; } else if ($temp_data) { $template->meta_refresh('/user/login/'); trigger_error('Your account is currently a temporary account, you need to login to start conversion', E_USER_ERROR); } break; } case('recover'): { $content = 'Hmm not quite sure what to do with this one yet....<br /><br />'; break; } } } else { $content .= '<p>Ok we will need some details from you</p>'; $content .= '<form action="./." method="post" class="form"> <div class="slim"> <label for="resource">Handle/Email</label> <input type="submit" value="Go!" /> <input type="text" name="resource" id="resource" value="" /> </div> </form> <br /><br /><br /><br />'; } break; } default: $template->system_error = 'That mode ' . $method . ' is not defined'; } $content .= 'So, your account is being funky? There are a couple of things we can do:'; $content .= '<ul> <li><a href="/user/help/resend/">Resend Verficiation Email</a></li> <li><a href="/user/help/check/">Check temporary account status, and update if needed</a></li> <li><a href="/user/help/recover/">Recover your password</a></li> </ul> '; $template->prehtml = $content;
http://cvs.php.net/viewvc.cgi/bugtracker/htdocs/.htaccess?r1=1.6&r2=1.7&diff_format=u Index: bugtracker/htdocs/.htaccess diff -u bugtracker/htdocs/.htaccess:1.6 bugtracker/htdocs/.htaccess:1.7 --- bugtracker/htdocs/.htaccess:1.6 Sun Aug 10 23:39:57 2008 +++ bugtracker/htdocs/.htaccess Mon Aug 11 19:49:49 2008 @@ -17,8 +17,10 @@ #Other shuntage RewriteRule ^login(/)?$ /user/login/ [L,PT] -RewriteRule ^user/verify/(.*)/(.*)$ index/index.php?page=user/verify&email=$1&tehkey=$2 [L,PT] +RewriteRule ^user/verify/(.*)/(.*)?$ index/index.php?page=user/verify&email=$1&tehkey=$2 [L,PT] +RewriteRule ^(.*)/(.*)/(.+)$ index/index.php?page=$1/$2&method=$3 [L,PT] +#RewriteRule ^(.*)/(.*)/(.*)/(.+)$ index/index.php?page=$1/$2&method=$3&resouece=$4 [L,PT] #the big rewrite -RewriteRule (.*)$ index/index.php?page=$1&%{QUERY_STRING} [L,PT] +RewriteRule (.*)$ index/index.php?page=$1&%{QUERY_STRING} [L,PT] http://cvs.php.net/viewvc.cgi/bugtracker/htdocs/elements/screen.css?r1=1.9&r2=1.10&diff_format=u Index: bugtracker/htdocs/elements/screen.css diff -u bugtracker/htdocs/elements/screen.css:1.9 bugtracker/htdocs/elements/screen.css:1.10 --- bugtracker/htdocs/elements/screen.css:1.9 Thu Aug 7 14:27:20 2008 +++ bugtracker/htdocs/elements/screen.css Mon Aug 11 19:49:49 2008 @@ -8,7 +8,12 @@ background: #FFFFFF; color: #000000; } -p, a, li, body { +#main_drag { + margin-left: 10px; + margin-right: 10px; + margin-bottom: 10px; +} +p, a, li, body, #main_drag { font-family: verdana, arial, helvetica, sans-serif; color: #000000; } http://cvs.php.net/viewvc.cgi/bugtracker/includes/email.php?r1=1.6&r2=1.7&diff_format=u Index: bugtracker/includes/email.php diff -u bugtracker/includes/email.php:1.6 bugtracker/includes/email.php:1.7 --- bugtracker/includes/email.php:1.6 Mon Aug 11 10:51:22 2008 +++ bugtracker/includes/email.php Mon Aug 11 19:49:49 2008 @@ -69,8 +69,8 @@ 'X-Mailer' => 'PHP Bugtracker, PHP' . phpversion() ); - $this->send_email(); - return; + return $this->send_email(); +// return; } function send_to_assigned($bug_id) { } http://cvs.php.net/viewvc.cgi/bugtracker/includes/template.php?r1=1.14&r2=1.15&diff_format=u Index: bugtracker/includes/template.php diff -u bugtracker/includes/template.php:1.14 bugtracker/includes/template.php:1.15 --- bugtracker/includes/template.php:1.14 Mon Aug 11 10:51:22 2008 +++ bugtracker/includes/template.php Mon Aug 11 19:49:49 2008 @@ -58,7 +58,7 @@ public $content_title = ' '; // public $login = '<li> </li>'; - public $login = '<li><a href="/login/" title="Login">Login</a></li>'; + public $login = '<li><a href="/user/create/" title="Create">Create</a></li><li><a href="/login/" title="Login">Login</a></li>'; public $template_data = array(); public $form_data = array(); @@ -145,7 +145,7 @@ function generate_footer() { global $db, $trace; - $this->html .= file_get_contents($_SERVER['DOCUMENT_ROOT'] . '../template/generic/footer.html'); + $this->html .= '</div>' . file_get_contents($_SERVER['DOCUMENT_ROOT'] . '../template/generic/footer.html'); $this->swap('queries', $db->query_count ); $this->swap('year', date('Y',time()) ); $this->swap('last', date('r',filemtime($this->template_file))); http://cvs.php.net/viewvc.cgi/bugtracker/includes/user.php?r1=1.12&r2=1.13&diff_format=u Index: bugtracker/includes/user.php diff -u bugtracker/includes/user.php:1.12 bugtracker/includes/user.php:1.13 --- bugtracker/includes/user.php:1.12 Mon Aug 11 10:51:22 2008 +++ bugtracker/includes/user.php Mon Aug 11 19:49:49 2008 @@ -205,7 +205,7 @@ $subject .= ' Creation'; $message .= 'have signed up to use the phpBugtracker over at http://bugs.php.net/'; } - $message .= "\n\r" . 'In order to continue you will need to verfiy your email address'; + $message .= "\n\r" . 'In order to continue you will need to verifiy your email address'; $message .= "\n\r" . 'Click the following link, or copy and paste it into your browser'; $message .= "\n\r\n\r"; @@ -217,30 +217,37 @@ $email->send_to_user($dest,$subject,$message); } + else + { + trigger_error('Failed to add you to the database',E_USER_ERROR); + } return TRUE; } function login($user,$password) { - global $form_data,$db; - //lets authenticate the user - $query = 'SELECT * FROM ' . USER_TABLE . ' WHERE handle = \'' . $db->protect_data($user) . '\' AND password = \'' . $password . '\''; - $db->get_data($query); - $valid = $db->total_rows; + global $form_data,$db,$template; - //try email - $query = 'SELECT * FROM ' . USER_TABLE . ' WHERE email = \'' . $db->protect_data($user) . '\' AND password = \'' . $password . '\''; + //lets authenticate the user + $query = 'SELECT * FROM ' . USER_TABLE . ' WHERE (handle = \'' . $db->protect_data($user) . '\' OR email = \'' . $db->protect_data($user) . '\') AND password = \'' . $password . '\''; $db->get_data($query); - $valid = ($valid) ? $valid : $db->total_rows; - if ($valid) + if ($db->total_rows) { //so lets make sure we have this right $user_row = $db->fetch_row(); + + if ($user_row['account_type'] != USER) + { + //arg! not verified? + trigger_error('Your account has not been verified or is invalid<br /><a href="/user/help/" title="Help">Get Account Help</a>',E_USER_ERROR); + } + $this->handle = $user_row['handle']; if ($this->write_cookie('',$form_data['return'])) { + $user->logged_in = TRUE; return TRUE; } - $form_data['form_error'] = 'The Cookie could not be set'; + $template->system_error = 'The Cookie could not be set'; } //try temp @@ -308,6 +315,15 @@ return TRUE; } } + if ($mode == 'email') + { + $query = 'SELECT * FROM ' . USER_TABLE . ' WHERE email = \'' . $db->protect_data($search) . '\''; + $db->get_data($query); + if ($db->total_rows) + { + return TRUE; + } + } return FALSE; } function update_password($password,$email,$handle = '',$mode = '') { http://cvs.php.net/viewvc.cgi/bugtracker/template/generic/header.html?r1=1.8&r2=1.9&diff_format=u Index: bugtracker/template/generic/header.html diff -u bugtracker/template/generic/header.html:1.8 bugtracker/template/generic/header.html:1.9 --- bugtracker/template/generic/header.html:1.8 Thu Aug 7 13:31:55 2008 +++ bugtracker/template/generic/header.html Mon Aug 11 19:49:49 2008 @@ -63,5 +63,7 @@ <a name="content"></a><h2>{CONTENT_TITLE}</h2> +<div id="main_drag"> + {SYSTEM_ERROR} http://cvs.php.net/viewvc.cgi/bugtracker/template/generic/user/convert.php?r1=1.9&r2=1.10&diff_format=u Index: bugtracker/template/generic/user/convert.php diff -u bugtracker/template/generic/user/convert.php:1.9 bugtracker/template/generic/user/convert.php:1.10 --- bugtracker/template/generic/user/convert.php:1.9 Mon Aug 11 10:51:25 2008 +++ bugtracker/template/generic/user/convert.php Mon Aug 11 19:49:50 2008 @@ -237,3 +237,4 @@ { $template->prehtml = $content; } + http://cvs.php.net/viewvc.cgi/bugtracker/template/generic/user/create.php?view=markup&rev=1.1 Index: bugtracker/template/generic/user/create.php +++ bugtracker/template/generic/user/create.php <?php /* Copyright (c) 2008, Barry Carlyon <bcarlyon@php.net> All rights reserved. Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met: * Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer. * Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution. * Neither the name of the GSOC_PHP_BUGTRACKER nor the names of its contributors may be used to endorse or promote products derived from this software without specific prior written permission. THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. */ require_once($_SERVER['DOCUMENT_ROOT'] . '../includes/recaptchalib.php'); $template->page_title .= 'Create a Account'; $template->content_title = 'Create a Account'; $content = ''; if ($user->logged_in_temp) { header("Location: /user/convert/"); } else if ($user->logged_in) { trigger_error('You are logged in already', E_USER_ERROR); } $method = loadvar('method'); $form_data = array(); $error_data = array(); switch ($method) { case('create'): { $form_data['handle'] = loadvar('handle'); $form_data['email'] = loadvar('email'); $form_data['password'] = loadvar('password'); foreach($form_data as $ref => $data) { $error_data[$ref] = $data ? FALSE : TRUE; } $error_data['email'] = check_email_mx($form_data['email']) ? FALSE : '* Invalid'; if ($user->fetch_handle($form_data['handle'])) $error_data['handle'] = '* Already in use'; if ($user->fetch_handle($form_data['email'],'email')) $error_data['email'] = '* Already in use'; $errors = FALSE; $recap_resp = recaptcha_check_answer($recaptcha_prv,$_SERVER['REMOTE_ADDR'],loadvar('recaptcha_challenge_field'),loadvar('recaptcha_response_field')); if ($recap_resp->is_valid) { $error_data['captcha'] = FALSE; } else { $error_data['captcha'] = 'The Captcha is invalid'; $form_data['recap_error'] = $recap_resp->error; } foreach ($error_data as $ref => $empty) { if ($empty) { $errors = TRUE; if (strlen($empty) == 1) $error_data[$ref] = '* Required'; } } if (!$errors) { //generate user_data and pass it to the register function $user_data = array(); $user_data['handle'] = $form_data['handle']; $user_data['password'] = md5($form_data['password']); $user_data['email'] = $form_data['email']; if ($user->register($user_data)) { $content = '<div id="success">You have been added to our records<br />You know need to validate your email address'; $content .= '<br />We have sent you an email to the address your provided to facillitate this'; $content .= '</div>'; break; } else { $template->system_error = 'Unknown drop through, code: register013'; unset($form_data,$error_data); $form_data = $error_data = array(); } } else { $form_data['form_error'] = 'Please correct the errors shown'; } } default: { $form_data['form_error'] = isset($form_data['form_error']) ? $form_data['form_error'] : ''; $form_data['recap_error'] = isset($form_data['recap_error']) ? $form_data['recap_error'] : ''; $content .= ' <p>To register for the Bugtracker, you need to first verify your email address.</p> {FORM_FORM_ERROR} <form action="/user/create/" method="post" class="form"> <input type="hidden" name="method" value="create" /> <div class="slim"> <label for="handle">Desired Handle:</label> {ERROR_HANDLE} <input type="text" name="handle" id="handle" value="{FORM_HANDLE}" /> <br /><br /> <label for="email">Email Address:</label> {ERROR_EMAIL} <input type="text" name="email" id="email" value="{FORM_EMAIL}" /> <br /><br /> <label for="password">Password:</label> {ERROR_PASSWORD} <input type="password" name="password" id="password" value="" /> <br /><br /> <label for="captcha">Captcha: {ERROR_CAPTCHA}</label> <div id="captcha">'; $content .= recaptcha_get_html($recaptcha_key,$form_data['recap_error']); $content .= ' <br /><br /> <input type="submit" name="submit" id="submit" value="Create Account" /> <br /><br /> </div> </form> '; } } $content = $template->dontloop(array('form' => $form_data, 'error' => $error_data), $content); $template->prehtml = $content; http://cvs.php.net/viewvc.cgi/bugtracker/template/generic/user/help.php?view=markup&rev=1.1 Index: bugtracker/template/generic/user/help.php +++ bugtracker/template/generic/user/help.php <?php /* Copyright (c) 2008, Barry Carlyon <bcarlyon@php.net> All rights reserved. Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met: * Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer. * Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution. * Neither the name of the GSOC_PHP_BUGTRACKER nor the names of its contributors may be used to endorse or promote products derived from this software without specific prior written permission. THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. */ $template->page_title .= 'Account Help'; $template->content_title = 'Account Help'; $method = str_replace('/','',loadvar('method')); $resource = str_replace('/','',loadvar('resource')); $content = ''; switch($method) { case('resend'): case('recover'): case('check'): { if ($resource) { //verify the data we have $query = 'SELECT email,handle,account_type,password FROM ' . USER_TABLE . ' WHERE handle = \'' . $resource . '\' OR email = \'' . $resource . '\''; $db->get_data($query); if (!$db->total_rows) { $user_data = FALSE; } else { $user_data = $db->fetch_row(); } //lets see if they are in the temp user table $query = 'SELECT handle,email,password FROM ' . TEMP_USER_TABLE . ' WHERE handle = \'' . $resource . '\' OR email = \'' . $resource . '\''; $db->get_data($query); $temp_data = array(); if ($db->total_rows) { $temp_data = $db->fetch_row(); $temp_data['account_type'] = TEMP_ACCOUNT; } else { $temp_data = FALSE; } switch($method) { case('resend'): { if (!$user_data) { //user is not in the user table //check for temp if so send to converter if ($temp_data) { $template->meta_refresh('/user/login/'); trigger_error('You need to login to continue', E_USER_ERROR); } else { trigger_error('The data you supploed is invalid', E_USER_ERROR); } } if ($user_data['account_type'] == 2) { trigger_error('This account has been verfied',E_USER_ERROR); } // so resend verif $dest = $user_data['email']; $subject = 'PHP Bugz Account'; $message = 'You or someone else '; if (!$user_data['account_type']) { $subject .= ' Conversion'; $message .= 'has converted your http://bugs.php.net/ Account to a full account'; } else { $subject .= ' Creation'; $message .= 'have signed up to use the phpBugtracker over at http://bugs.php.net/'; } $message .= "\n\r" . 'In order to continue you will need to verifiy your email address'; $message .= "\n\r" . 'Click the following link, or copy and paste it into your browser'; $message .= "\n\r\n\r"; $message .= 'http://' . $_SERVER['HTTP_HOST'] . '/user/verify/'; $message .= $dest . '/'; $message .= md5( md5($dest) . '_' . md5 ($user_data['password']) ); $message .= "\n\r\n\r"; if ($email->send_to_user($dest,$subject,$message)) { $content .= '<div id="success">Successfully Resent the email confirm email</div>'; } else { trigger_error('Failed to resend the confirm email', E_USER_ERROR); } break; } case('check'): { //if the user is a temp and not a real one, call user convert if (isset($user_data['account_type'])) { if ($user_data['account_type'] == 2) { $content .= 'This account is a full account'; } else { $content .= 'This account appears to be part converted, awaiting verification of your email address'; } $content .= '<br /><br />'; break; } else if ($temp_data) { $template->meta_refresh('/user/login/'); trigger_error('Your account is currently a temporary account, you need to login to start conversion', E_USER_ERROR); } break; } case('recover'): { $content = 'Hmm not quite sure what to do with this one yet....<br /><br />'; break; } } } else { $content .= '<p>Ok we will need some details from you</p>'; $content .= '<form action="./." method="post" class="form"> <div class="slim"> <label for="resource">Handle/Email</label> <input type="submit" value="Go!" /> <input type="text" name="resource" id="resource" value="" /> </div> </form> <br /><br /><br /><br />'; } break; } default: $template->system_error = 'That mode ' . $method . ' is not defined'; } $content .= 'So, your account is being funky? There are a couple of things we can do:'; $content .= '<ul> <li><a href="/user/help/resend/">Resend Verficiation Email</a></li> <li><a href="/user/help/check/">Check temporary account status, and update if needed</a></li> <li><a href="/user/help/recover/">Recover your password</a></li> </ul> '; $template->prehtml = $content;