-
Notifications
You must be signed in to change notification settings - Fork 1
/
get_user_state.php
98 lines (87 loc) · 2.63 KB
/
get_user_state.php
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
<?php
include('config.php');
require './includes/sanitizer.php';
session_start();
// $user_check = $_SESSION['login_user'];
$user_check = sanitizeInput($_SESSION['login_user']);
// echo($_SESSION['id']);
$user_id = substr(sanitizeInput($_SESSION['id']),0,3);
$saved_hash = substr(sanitizeInput($_SESSION['logid']),0,8);
// $user_check = sanitizeInput($_SESSION['login_user']);
// $ses_sql = mysqli_query($conn,"select email, name, status, role from users where email = '$user_check' ");
// $row = mysqli_fetch_array($ses_sql,MYSQLI_ASSOC);
try{
$sql = "select email, name, status, role from users where email = ?";
$stmt = $conn->prepare($sql);
$stmt->bind_param("s", $user_check);
$stmt->execute();
$result = $stmt->get_result();
} catch(Exception $e){
if ($debug_mode == true){
// echo $e;
die('debug: '.$e);
}
else{
echo 'error';
die();
}
}
$row = $result->fetch_assoc();
$login_session = $row['email'];
$login_username = $row['name'];
if (isset($_SESSION['login_user'])){
if ($row['status'] =='true'){
// $ses_sql = mysqli_query($conn,"SELECT ts_hash FROM login_logs WHERE users_id = ".$user_id.";");
// $row = mysqli_fetch_array($ses_sql,MYSQLI_ASSOC);
try{
$sql = "select s_id from scoreboard where user_id = ? and c_id = ?";
$stmt = $conn->prepare($sql);
$stmt->bind_param("ii", $user_id, $challenge_id);
$stmt->execute();
$result = $stmt->get_result();
} catch(Exception $e){
if ($debug_mode == true){
// echo $e;
die('debug: '.$e);
}
else{
echo 'error';
die();
}
}
try{
$sql = "SELECT ts_hash FROM login_logs WHERE users_id = ?";
$stmt = $conn->prepare($sql);
$stmt->bind_param("i", $user_id);
$stmt->execute();
$result = $stmt->get_result();
} catch(Exception $e){
if ($debug_mode == true){
// echo $e;
die('debug: '.$e);
}
else{
echo 'error';
die();
}
}
$row = $result->fetch_assoc();
$db_hash = $row['ts_hash'];
if ($saved_hash == $db_hash){
echo 'true';
}
else{
echo 'old';
}
}
elseif ($row['status'] =='false'){
echo 'false';
}
else{
echo 'error';
}
}
else{
echo 'error';
}
?>