2017-02-05 11:57:55 -06:00
|
|
|
<?php // cookies.php :: Handles cookies. (Mmm, tasty!)
|
|
|
|
|
|
|
|
function checkcookies() {
|
|
|
|
|
|
|
|
include("../config.php");
|
2017-02-05 11:58:57 -06:00
|
|
|
global $controlrow;
|
2017-02-05 11:57:55 -06:00
|
|
|
|
|
|
|
$row = false;
|
|
|
|
|
2017-02-05 11:58:57 -06:00
|
|
|
if (isset($_COOKIE[$controlrow["cookiename"]])) {
|
2017-02-05 11:57:55 -06:00
|
|
|
|
|
|
|
// COOKIE FORMAT:
|
|
|
|
// {ID} {USERNAME} {PASSWORDHASH} {REMEMBERME}
|
2017-02-05 11:58:57 -06:00
|
|
|
$theuser = explode(" ",$_COOKIE[$controlrow["cookiename"]]);
|
2017-02-05 11:57:55 -06:00
|
|
|
if (!is_numeric($theuser[0])) { err("Invalid cookie data (Error 0). Please clear cookies and log in again."); }
|
|
|
|
$row = dorow(doquery("SELECT * FROM {{table}} WHERE username='$theuser[1]' LIMIT 1", "accounts"));
|
|
|
|
if ($row == false) { err("Invalid cookie data (Error 1). Please clear cookies and log in again."); }
|
|
|
|
if ($row["id"] != $theuser[0]) { err("Invalid cookie data (Error 2). Please clear cookies and log in again."); }
|
|
|
|
if (md5($row["password"] . "--" . $dbsettings["secretword"]) !== $theuser[2]) { err("Invalid cookie data (Error 3). Please clear cookies and log in again."); }
|
|
|
|
|
|
|
|
// If we've gotten this far, cookie should be valid, so write a new one.
|
|
|
|
$newcookie = implode(" ",$theuser);
|
|
|
|
if ($theuser[3] == 1) { $expiretime = time()+31536000; } else { $expiretime = 0; }
|
2017-02-05 11:58:57 -06:00
|
|
|
setcookie ($controlrow["cookiename"], $newcookie, $expiretime, "/", $controlrow["cookiedomain"], 0);
|
2017-02-05 11:57:55 -06:00
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
return $row;
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
?>
|