WebOrbiton
v1.0.0.1

StocketBase

74 lines · 3.0 KB
  1. <?php
  2. ​
  3. declare(strict_types=1);
  4. ​
  5. if (count(get_included_files()) === 1) {
  6. http_response_code(403);
  7. exit;
  8. }
  9. ​
  10. $action = $_POST['action'] ?? '';
  11. $reader = UserAuth::user();
  12. ​
  13. if ($action === 'update_profile') {
  14. $displayName = mb_substr(trim((string) ($_POST['display_name'] ?? '')), 0, 100);
  15. $newPassword = (string) ($_POST['new_password'] ?? '');
  16. $currentPassword = (string) ($_POST['current_password'] ?? '');
  17. ​
  18. $params = ['display_name' => $displayName !== '' ? $displayName : $reader['display_name'], 'id' => $reader['id']];
  19. ​
  20. if ($newPassword !== '') {
  21. if (strlen($newPassword) < 8) {
  22. return Language::get('auth_password_too_short', 'Password must be at least 8 characters.');
  23. }
  24. if (!UserAuth::verifyPassword((int) $reader['id'], $currentPassword)) {
  25. return Language::get('account_current_password_wrong', 'Your current password is incorrect.');
  26. }
  27. $statement = Database::users()->prepare(
  28. 'UPDATE user_accounts SET display_name = :display_name, password_hash = :hash WHERE id = :id'
  29. );
  30. $statement->execute($params + ['hash' => password_hash($newPassword, PASSWORD_DEFAULT)]);
  31. session_regenerate_id(true);
  32. UserAuth::refreshPasswordFingerprint((int) $reader['id']);
  33. } else {
  34. $statement = Database::users()->prepare(
  35. 'UPDATE user_accounts SET display_name = :display_name WHERE id = :id'
  36. );
  37. $statement->execute($params);
  38. UserAuth::refreshPasswordFingerprint((int) $reader['id']);
  39. }
  40. ​
  41. return Language::get('account_profile_updated', 'Profile updated.');
  42. }
  43. ​
  44. if ($action === 'update_consents') {
  45. $consentTypes = ['analytics', 'ads_personalization'];
  46. $db = Database::users();
  47. ​
  48. foreach ($consentTypes as $type) {
  49. $granted = isset($_POST['consent_' . $type]) ? 1 : 0;
  50. ​
  51. $existingStatement = $db->prepare(
  52. 'SELECT id FROM user_consents WHERE user_account_id = :user_id AND consent_type = :type ORDER BY id DESC LIMIT 1'
  53. );
  54. $existingStatement->execute(['user_id' => $reader['id'], 'type' => $type]);
  55. $existing = $existingStatement->fetch();
  56. ​
  57. if ($existing) {
  58. $statement = $db->prepare(
  59. 'UPDATE user_consents SET is_granted = :granted, granted_at = IF(:granted_check = 1, NOW(), granted_at), revoked_at = IF(:granted_check2 = 0, NOW(), NULL) WHERE id = :id'
  60. );
  61. $statement->execute(['granted' => $granted, 'granted_check' => $granted, 'granted_check2' => $granted, 'id' => $existing['id']]);
  62. } else {
  63. $statement = $db->prepare(
  64. 'INSERT INTO user_consents (user_account_id, consent_type, is_granted, granted_at) VALUES (:user_id, :type, :granted, IF(:granted_check = 1, NOW(), NULL))'
  65. );
  66. $statement->execute(['user_id' => $reader['id'], 'type' => $type, 'granted' => $granted, 'granted_check' => $granted]);
  67. }
  68. }
  69. ​
  70. return Language::get('account_preferences_updated', 'Preferences updated.');
  71. }
  72. ​
  73. return null;
  74. ​