WebOrbiton
v2.0.0.0

Publisium

64 lines · 2.7 KB
  1. <?php
  2. ​
  3. declare(strict_types=1);
  4. ​
  5. $action = $_POST['action'] ?? '';
  6. $reader = UserAuth::user();
  7. ​
  8. if ($action === 'update_profile') {
  9. $displayName = trim((string) ($_POST['display_name'] ?? ''));
  10. $newPassword = (string) ($_POST['new_password'] ?? '');
  11. ​
  12. $params = ['display_name' => $displayName !== '' ? $displayName : $reader['display_name'], 'id' => $reader['id']];
  13. ​
  14. if ($newPassword !== '') {
  15. if (strlen($newPassword) < 8) {
  16. return Language::get('account_password_too_short', 'Your new password needs at least 8 characters.');
  17. }
  18. $newHash = password_hash($newPassword, PASSWORD_DEFAULT);
  19. $statement = Database::users()->prepare(
  20. 'UPDATE user_accounts SET display_name = :display_name, password_hash = :hash WHERE id = :id'
  21. );
  22. $statement->execute($params + ['hash' => $newHash]);
  23. UserAuth::passwordChanged((int) $reader['id'], $newHash);
  24. } else {
  25. $statement = Database::users()->prepare(
  26. 'UPDATE user_accounts SET display_name = :display_name WHERE id = :id'
  27. );
  28. $statement->execute($params);
  29. }
  30. ​
  31. return Language::get('account_profile_saved', 'Your profile is saved.');
  32. }
  33. ​
  34. if ($action === 'update_consents' && SiteFront::settings()['account_consents_enabled'] === '1') {
  35. $consentTypes = ['analytics', 'ads_personalization'];
  36. $db = Database::users();
  37. ​
  38. foreach ($consentTypes as $type) {
  39. $granted = isset($_POST['consent_' . $type]) ? 1 : 0;
  40. ​
  41. $existingStatement = $db->prepare(
  42. 'SELECT id FROM user_consents WHERE user_account_id = :user_id AND consent_type = :type ORDER BY id DESC LIMIT 1'
  43. );
  44. $existingStatement->execute(['user_id' => $reader['id'], 'type' => $type]);
  45. $existing = $existingStatement->fetch();
  46. ​
  47. if ($existing) {
  48. $statement = $db->prepare(
  49. 'UPDATE user_consents SET is_granted = :granted, granted_at = IF(:granted_check = 1, NOW(), granted_at), revoked_at = IF(:granted_check2 = 0, NOW(), NULL) WHERE id = :id'
  50. );
  51. $statement->execute(['granted' => $granted, 'granted_check' => $granted, 'granted_check2' => $granted, 'id' => $existing['id']]);
  52. } else {
  53. $statement = $db->prepare(
  54. 'INSERT INTO user_consents (user_account_id, consent_type, is_granted, granted_at) VALUES (:user_id, :type, :granted, IF(:granted_check = 1, NOW(), NULL))'
  55. );
  56. $statement->execute(['user_id' => $reader['id'], 'type' => $type, 'granted' => $granted, 'granted_check' => $granted]);
  57. }
  58. }
  59. ​
  60. return Language::get('account_preferences_saved', 'Your choices are saved.');
  61. }
  62. ​
  63. return null;
  64. ​