This commit is contained in:
marc-go
2026-04-14 20:00:21 +02:00
parent 8bfa783d9d
commit f2bb74dd12
63 changed files with 22576 additions and 252 deletions

50
api/login/getcookies.php Normal file
View File

@@ -0,0 +1,50 @@
<?php
ini_set("display_errors", 1);
ini_set("display_startup_errors", 1);
error_reporting(E_ALL);
require "../api.php";
$api = new spamhasiApi();
$db = $api->getDB();
if ($_SERVER["REQUEST_METHOD"] == "POST") {
if (!isset($_POST["username"]) || !isset($_POST["passwd"])) {
die("Username or Password are missing");
}
$user = $_POST["username"];
$passwd = hash("sha256", $_POST["passwd"]);
$sql = "SELECT username, passwd FROM users WHERE username = :username AND passwd = :passwd";
$stmt = $db->prepare($sql);
$stmt->execute([
':username' => $user,
':passwd' => $passwd
]);
$result = $stmt->fetch(PDO::FETCH_ASSOC);
if ($result) {
$config = $api->getConf();
$session["session_id"] = $api->generateSessionID();
$device_id = rand(1, 999);
$json[$device_id] = $session;
file_put_contents($config["PATH"] . "/tmp/user_sessions/" . $user . ".json", json_encode($json));
setcookie("session_id", $session["session_id"], time() + 3600, "/");
setcookie("device_id", $device_id, time() + 3600, "/");
setcookie("username", $user, time() + 3600, "/");
header("Location: /opfer.html");
exit;
}else{
header("Location: /login.php?passwdIsFalse=true");
exit;
}
}
?>