WebOrbiton
v1.0.0.8

Publisium

108 lines · 6.3 KB
  1. <?php
  2. ​
  3. declare(strict_types=1);
  4. ​
  5. require_once __DIR__ . '/includes/config.php';
  6. require_once __DIR__ . '/includes/database.php';
  7. require_once __DIR__ . '/includes/user-auth.php';
  8. require_once __DIR__ . '/includes/csrf.php';
  9. require_once __DIR__ . '/includes/language.php';
  10. require_once __DIR__ . '/includes/site-front.php';
  11. require_once __DIR__ . '/includes/currency.php';
  12. ​
  13. UserAuth::boot();
  14. UserAuth::requireLogin();
  15. ​
  16. $reader = UserAuth::user();
  17. $settings = SiteFront::settings();
  18. $flashMessage = null;
  19. ​
  20. if ($_SERVER['REQUEST_METHOD'] === 'POST') {
  21. if (!Csrf::verify($_POST['csrf_token'] ?? null)) {
  22. $flashMessage = Language::get('auth_session_expired', 'Your session expired. Please try again.');
  23. } else {
  24. $flashMessage = require __DIR__ . '/dashboard-actions/save-account.php';
  25. $reader = UserAuth::user();
  26. }
  27. }
  28. ​
  29. $subscriptionsStatement = Database::users()->prepare(
  30. 'SELECT * FROM subscriptions WHERE user_account_id = :id ORDER BY created_at DESC'
  31. );
  32. $subscriptionsStatement->execute(['id' => $reader['id']]);
  33. $subscriptions = $subscriptionsStatement->fetchAll();
  34. ​
  35. $consentsStatement = Database::users()->prepare(
  36. 'SELECT consent_type, is_granted FROM user_consents WHERE user_account_id = :id'
  37. );
  38. $consentsStatement->execute(['id' => $reader['id']]);
  39. $consentRows = $consentsStatement->fetchAll();
  40. $consents = [];
  41. foreach ($consentRows as $row) {
  42. $consents[$row['consent_type']] = (bool) $row['is_granted'];
  43. }
  44. ​
  45. $pageTitle = Language::get('account_profile', 'Profile') . ' - ' . $settings['site_name'];
  46. $showBanner = false;
  47. ​
  48. require __DIR__ . '/includes/front-header.php';
  49. ​
  50. ?>
  51. <h1 class="article-title"><?= htmlspecialchars(Language::get('account_profile', 'Profile')) ?></h1>
  52. ​
  53. <?php if ($flashMessage !== null): ?>
  54. <p style="color: var(--accent);"><?= htmlspecialchars($flashMessage) ?></p>
  55. <?php endif; ?>
  56. ​
  57. <form method="post" style="max-width:420px;margin-bottom:32px;">
  58. <?= Csrf::field() ?>
  59. <input type="hidden" name="action" value="update_profile">
  60. <label><?= htmlspecialchars(Language::get('auth_display_name', 'Display name')) ?></label>
  61. <input type="text" name="display_name" value="<?= htmlspecialchars($reader['display_name'] ?? '') ?>" style="width:100%;padding:10px;border-radius:8px;border:1px solid var(--border);background:var(--panel);color:var(--text);margin:6px 0 14px;">
  62. <label><?= htmlspecialchars(Language::get('account_new_password', 'New password (leave empty to keep your current one)')) ?></label>
  63. <input type="password" name="new_password" minlength="8" style="width:100%;padding:10px;border-radius:8px;border:1px solid var(--border);background:var(--panel);color:var(--text);margin:6px 0 14px;">
  64. <button type="submit" class="unlock-btn" style="border:none;cursor:pointer;"><?= htmlspecialchars(Language::get('account_save', 'Save changes')) ?></button>
  65. </form>
  66. ​
  67. <h2><?= htmlspecialchars(Language::get('account_subscriptions', 'Subscriptions')) ?></h2>
  68. <ul>
  69. <?php foreach ($subscriptions as $subscription): ?>
  70. <?php $subscriptionEnd = !empty($subscription['current_period_end']) ? strtotime((string) $subscription['current_period_end']) : false; ?>
  71. <li><?= htmlspecialchars($settings['subscription_name'] !== '' ? $settings['subscription_name'] : ucfirst((string) $subscription['provider'])) ?> (<?= htmlspecialchars(Language::get('subscription_status_' . $subscription['status'], ucfirst(str_replace('_', ' ', (string) $subscription['status'])))) ?>)<?php if ($subscriptionEnd !== false): ?>, <?= htmlspecialchars(str_replace('{date}', date('Y-m-d', $subscriptionEnd), Language::get('account_subscription_until', 'until {date}'))) ?><?php endif; ?></li>
  72. <?php endforeach; ?>
  73. <?php if (empty($subscriptions)): ?>
  74. <li><?= htmlspecialchars(Language::get('account_no_subscriptions', 'You don’t have any subscriptions yet.')) ?></li>
  75. <?php endif; ?>
  76. </ul>
  77. ​
  78. <?php if ($settings['subscription_checkout_url'] !== '' && !UserAuth::hasActiveSubscription((int) $reader['id'])): ?>
  79. <?php
  80. $offerPrice = Currency::format((int) $settings['subscription_price_cents'], (string) $settings['subscription_currency']);
  81. $offerInterval = (string) $settings['subscription_interval'];
  82. ?>
  83. <div class="subscription-offer account-subscription-offer">
  84. <div class="subscription-offer-name"><?= htmlspecialchars($settings['subscription_name']) ?></div>
  85. <div class="subscription-offer-price"><?= htmlspecialchars($offerInterval === 'lifetime'
  86. ? $offerPrice . ' · ' . Language::get('subscription_one_time', 'one-time payment')
  87. : $offerPrice . ' / ' . ($offerInterval === 'year' ? Language::get('subscription_per_year', 'year') : Language::get('subscription_per_month', 'month'))) ?></div>
  88. <?php if ($settings['subscription_description'] !== ''): ?>
  89. <p class="subscription-offer-description"><?= htmlspecialchars($settings['subscription_description']) ?></p>
  90. <?php endif; ?>
  91. <a href="<?= htmlspecialchars(SiteFront::subscriptionCheckoutUrl((string) $reader['email'])) ?>" class="unlock-btn"><?= htmlspecialchars($offerInterval === 'lifetime' ? Language::get('article_buy_lifetime_button', 'Get lifetime access') : Language::get('article_subscribe_button', 'Subscribe')) ?></a>
  92. <p class="account-subscription-note"><?= htmlspecialchars(str_replace('{email}', (string) $reader['email'], Language::get('account_subscription_email_note', 'Pay with {email} so the subscription is linked to this account.'))) ?></p>
  93. </div>
  94. <?php endif; ?>
  95. ​
  96. <?php if ($settings['account_consents_enabled'] === '1'): ?>
  97. <h2><?= htmlspecialchars(Language::get('account_consents', 'Privacy consents')) ?></h2>
  98. <form method="post" style="max-width:420px;">
  99. <?= Csrf::field() ?>
  100. <input type="hidden" name="action" value="update_consents">
  101. <label style="display:block;margin:0 0 10px;"><input type="checkbox" name="consent_analytics" <?= !empty($consents['analytics']) ? 'checked' : '' ?>> <?= htmlspecialchars(Language::get('account_consent_analytics', 'Allow analytics, so we can see which articles people read')) ?></label>
  102. <label style="display:block;margin:0 0 10px;"><input type="checkbox" name="consent_ads_personalization" <?= !empty($consents['ads_personalization']) ? 'checked' : '' ?>> <?= htmlspecialchars(Language::get('account_consent_ads', 'Allow personalized ads')) ?></label>
  103. <button type="submit" class="unlock-btn" style="border:none;cursor:pointer;margin-top:14px;"><?= htmlspecialchars(Language::get('account_save', 'Save changes')) ?></button>
  104. </form>
  105. <?php endif; ?>
  106. ​
  107. <?php require __DIR__ . '/includes/front-footer.php'; ?>
  108. ​