v1.0.0.1
StocketBase
- <?php
-
- declare(strict_types=1);
-
- if (count(get_included_files()) === 1) {
- http_response_code(403);
- exit;
- }
-
- $action = $_POST['action'] ?? '';
- $reader = UserAuth::user();
-
- if ($action === 'update_profile') {
- $displayName = mb_substr(trim((string) ($_POST['display_name'] ?? '')), 0, 100);
- $newPassword = (string) ($_POST['new_password'] ?? '');
- $currentPassword = (string) ($_POST['current_password'] ?? '');
-
- $params = ['display_name' => $displayName !== '' ? $displayName : $reader['display_name'], 'id' => $reader['id']];
-
- if ($newPassword !== '') {
- if (strlen($newPassword) < 8) {
- return Language::get('auth_password_too_short', 'Password must be at least 8 characters.');
- }
- if (!UserAuth::verifyPassword((int) $reader['id'], $currentPassword)) {
- return Language::get('account_current_password_wrong', 'Your current password is incorrect.');
- }
- $statement = Database::users()->prepare(
- 'UPDATE user_accounts SET display_name = :display_name, password_hash = :hash WHERE id = :id'
- );
- $statement->execute($params + ['hash' => password_hash($newPassword, PASSWORD_DEFAULT)]);
- session_regenerate_id(true);
- UserAuth::refreshPasswordFingerprint((int) $reader['id']);
- } else {
- $statement = Database::users()->prepare(
- 'UPDATE user_accounts SET display_name = :display_name WHERE id = :id'
- );
- $statement->execute($params);
- UserAuth::refreshPasswordFingerprint((int) $reader['id']);
- }
-
- return Language::get('account_profile_updated', 'Profile updated.');
- }
-
- if ($action === 'update_consents') {
- $consentTypes = ['analytics', 'ads_personalization'];
- $db = Database::users();
-
- foreach ($consentTypes as $type) {
- $granted = isset($_POST['consent_' . $type]) ? 1 : 0;
-
- $existingStatement = $db->prepare(
- 'SELECT id FROM user_consents WHERE user_account_id = :user_id AND consent_type = :type ORDER BY id DESC LIMIT 1'
- );
- $existingStatement->execute(['user_id' => $reader['id'], 'type' => $type]);
- $existing = $existingStatement->fetch();
-
- if ($existing) {
- $statement = $db->prepare(
- 'UPDATE user_consents SET is_granted = :granted, granted_at = IF(:granted_check = 1, NOW(), granted_at), revoked_at = IF(:granted_check2 = 0, NOW(), NULL) WHERE id = :id'
- );
- $statement->execute(['granted' => $granted, 'granted_check' => $granted, 'granted_check2' => $granted, 'id' => $existing['id']]);
- } else {
- $statement = $db->prepare(
- 'INSERT INTO user_consents (user_account_id, consent_type, is_granted, granted_at) VALUES (:user_id, :type, :granted, IF(:granted_check = 1, NOW(), NULL))'
- );
- $statement->execute(['user_id' => $reader['id'], 'type' => $type, 'granted' => $granted, 'granted_check' => $granted]);
- }
- }
-
- return Language::get('account_preferences_updated', 'Preferences updated.');
- }
-
- return null;
-