1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950 |
- <?php
-
-
- $params = array();
- parse_str($_POST['sign_in_data'], $params);
-
- if(!array_key_exists('email-login', $params) || !array_key_exists('password-login', $params)) {
- echo 400;
- }
- else {
-
- $email = $params['email-login'];
- $password = $params['password-login'];
-
- require_once('db_utils.php');
- $conn = db_connect();
-
-
- if(!($result = mysqli_query($conn, "SELECT * FROM user WHERE username = '$email'"))) {
- echo 400;
- }
- else {
- if(mysqli_num_rows($result) != 1) {
- echo 401;
- }
- else {
- $row = mysqli_fetch_array($result, MYSQLI_ASSOC);
- mysqli_free_result($result);
- $activated = $row['activated'];
- if($activated == FALSE)
- echo 402;
- else {
- $hash = $row['password'];
- $full_salt = substr($hash, 0, 29);
- $new_hash = crypt($password, $full_salt);
- if ($hash == $new_hash) {
- session_start();
- $_SESSION['userlogin'] = $email;
- echo 200;
- }
- else
- echo 401;
- }
- }
- }
-
- mysqli_free_result($result);
- db_close($conn);
- }
- ?>
|