LAYOUT: updated icons from Lance
[e-DoKo.git] / index.php
index 8e21ae620399c846c3e3716f35a7f01e6de9cfc5..0b16cd698dac4b463cad7365ddc5975b46550f4e 100644 (file)
--- a/index.php
+++ b/index.php
@@ -1,9 +1,6 @@
 <?php
 error_reporting(E_ALL);
 
-global $REV;
-$REV  ="\$Rev$";
-
 include_once("config.php");      
 include_once("output.php");      /* html output only */
 include_once("db.php");          /* database only */
@@ -12,7 +9,27 @@ include_once("functions.php");   /* the rest */
 /* check if some variables are set in the config file, else set defaults */
 if(!isset($EmailName))
      $EmailName="[DoKo] ";
-
+if(isset($EMAIL_REPLY))
+  {
+    ini_set("sendmail_from",$EMAIL_REPLY);
+  }
+if(!isset($ADMIN_NAME))
+  {
+    output_header();
+    echo "<h1>Setup not completed</h1>";
+    echo "You need to set \$ADMIN_NAME in config.php.";
+    output_footer(); 
+    exit(); 
+  }    
+if(!isset($ADMIN_EMAIL))
+  {
+    output_header();
+    echo "<h1>Setup not completed</h1>";
+    echo "You need to set \$ADMIN_EMAIL in config.php. ".
+      "If something goes wrong an email will send to this address.";
+    output_footer(); 
+    exit(); 
+  }
 
 /* in case work has to be done on the database or other section we can
  * shut down the server and tell people to come back later 
@@ -28,7 +45,8 @@ if(0)
 if(DB_open()<0)
   {
     output_header();
-    echo "Database error, can't connect...";
+    echo "Database error, can't connect... Please wait a while and try again. ".
+      "If the problem doesn't go away feel free to contact $ADMIN_NAME at $ADMIN_EMAIL.";
     output_footer(); 
     exit(); 
   }
@@ -43,7 +61,7 @@ if(myisset("new"))
     output_form_for_new_game($names);
   }
 /*check if everything is ready to set up a new game */
- else if( myisset("PlayerA", "PlayerB","PlayerC","PlayerD","dullen","schweinchen" ))
+ else if( myisset("PlayerA", "PlayerB","PlayerC","PlayerD","dullen","schweinchen","call" ))
   {
     $PlayerA = $_REQUEST["PlayerA"];
     $PlayerB = $_REQUEST["PlayerB"];
@@ -52,7 +70,8 @@ if(myisset("new"))
 
     $dullen      = $_REQUEST["dullen"];
     $schweinchen = $_REQUEST["schweinchen"];
-    
+    $call        = $_REQUEST["call"];
+
     $EmailA  = DB_get_email_by_name($PlayerA);
     $EmailB  = DB_get_email_by_name($PlayerB);
     $EmailC  = DB_get_email_by_name($PlayerC);
@@ -62,6 +81,7 @@ if(myisset("new"))
       {
        echo "couldn't find one of the names, please start a new game";
        output_footer();
+       DB_close();
        exit();
       }
     
@@ -71,18 +91,9 @@ if(myisset("new"))
     $useridD  = DB_get_userid_by_name($PlayerD);
     
     /* create random numbers */
-    $randomNR       = create_array_of_random_numbers();
+    $randomNR       = create_array_of_random_numbers($useridA,$useridB,$useridC,$useridD);
     $randomNRstring = join(":",$randomNR);
-    
-    /* get ruleset information or create new one */
-    $ruleset = DB_get_ruleset($dullen,$schweinchen);
-    if($ruleset <0) 
-      {
-       echo "Error defining ruleset: $ruleset";
-       output_footer();
-       exit();
-      };
-    
+        
     /* create game */
     $followup = NULL;
     if(myisset("followup") )
@@ -92,21 +103,33 @@ if(myisset("new"))
        $ruleset = DB_get_ruleset_by_gameid($followup); /* just copy ruleset from old game, 
                                                         this way no manipulation is possible */
        if($session)
-         mysql_query("INSERT INTO Game VALUES (NULL, NULL, '$randomNRstring', 'normal', NULL,NULL,'1','pre',".
+         mysql_query("INSERT INTO Game VALUES (NULL, NULL, '$randomNRstring', 'normal', NULL,NULL,'1',NULL,'pre',".
                      "'$ruleset','$session' ,NULL)");
        else
          {
            /* get max session */
            $max = DB_get_max_session();
            $max++;
-           mysql_query("INSERT INTO Game VALUES (NULL, NULL, '$randomNRstring', 'normal', NULL,NULL,'1','pre',".
-                       "'$ruleset','$max' ,NULL)");
            mysql_query("UPDATE Game SET session='".$max."' WHERE id=".DB_quote_smart($followup));
+           mysql_query("INSERT INTO Game VALUES (NULL, NULL, '$randomNRstring', 'normal', NULL,NULL,'1',NULL,'pre',".
+                       "'$ruleset','$max' ,NULL)");
          }
       }
     else
-      mysql_query("INSERT INTO Game VALUES (NULL, NULL, '$randomNRstring', 'normal', NULL,NULL,'1','pre', ".
+      {
+       /* get ruleset information or create new one */
+       $ruleset = DB_get_ruleset($dullen,$schweinchen,$call);
+       if($ruleset <0) 
+         {
+           myerror("Error defining ruleset: $ruleset");
+           output_footer();
+           DB_close();
+           exit();
+         };
+       
+       mysql_query("INSERT INTO Game VALUES (NULL, NULL, '$randomNRstring', 'normal', NULL,NULL,'1',NULL,'pre', ".
                  "'$ruleset',NULL ,NULL)");
+      }
     $game_id = mysql_insert_id();
     
     /* create hash */
@@ -172,6 +195,7 @@ else if(myisset("cancle","me"))
        echo "Can't find you in the database, please check the url.<br />\n";
        echo "perhaps the game has been cancled, check by login in <a href=\"$host\">here</a>.";
        output_footer();
+       DB_close();
        exit();
       }
     
@@ -217,6 +241,7 @@ else if(myisset("me"))
        echo "Can't find you in the database, please check the url.<br />\n";
        echo "perhaps the game has been cancled, check by login in <a href=\"$host\">here</a>.";
        output_footer();
+       DB_close();
        exit();
       }
 
@@ -229,6 +254,7 @@ else if(myisset("me"))
     $mystatus = DB_get_status_by_hash($me);
     $mypos    = DB_get_pos_by_hash($me);
     $myhand   = DB_get_handid_by_hash($me);
+    $session  = DB_get_session_by_gameid($gameid);
 
     /* get prefs and save them */
     DB_get_PREF($myid);
@@ -243,7 +269,9 @@ else if(myisset("me"))
 
     $RULES["dullen"]      = $r[2];
     $RULES["schweinchen"] = $r[3];
-    
+    $RULES["call"]        = $r[4];
+
+
     /* get some infos about the game */
     $gametype   = DB_get_gametype_by_gameid($gameid);
     $gamestatus = DB_get_game_status_by_gameid($gameid);
@@ -263,7 +291,27 @@ else if(myisset("me"))
     echo "Rules: <br />\n";
     echo "10ofhearts : ".$r[2]."<br />\n";
     echo "schweinchen: ".$r[3]."<br />\n";
+    echo "call:        ".$r[4]."<br />\n";
     echo "</div>\n";
+
+    /* output extra division in case this game is part of a session */
+    if($session)
+      {
+       echo "<div class=\"session\">\n".
+         "This game is part of session $session: \n";
+       $hashes = DB_get_hashes_by_session($session,$myid);
+       $i = 1;
+       foreach($hashes as $hash)
+         {
+           if($hash == $me)
+             echo "$i ";
+           else 
+             echo "<a href=\"".$host."?me=".$hash."\">$i</a> ";
+           $i++;
+         }
+       echo "</div>\n";
+      }
+
     
     /* does anyone have both foxes */
     $GAME["schweinchen"]=0; 
@@ -333,7 +381,7 @@ else if(myisset("me"))
                  display_card($card,$PREF["cardset"]);
                echo "</p>\n";   
                
-               check_for_sickness($me,$mycards);
+               output_check_for_sickness($me,$mycards);
                
                /* move on to the next stage*/
                DB_set_hand_status_by_hash($me,'check');
@@ -352,7 +400,7 @@ else if(myisset("me"))
          /* all these variables have a pre-selected default,
           * so we should never get here,
           * unless a user tries to cheat ;) */
-         echo "something went wrong...please contact the admin.";
+         echo "something went wrong during the setup...please contact the $ADMIN_NAME at $ADMIN_EMAIL.";
        }
       else
        {
@@ -399,35 +447,43 @@ else if(myisset("me"))
                " is playing solo, this game will be canceled.<br />\n";
              DB_set_sickness_by_hash($me,"nines");
            }
-       }
-
-      echo " Ok, done with checking, please go to the <a href=\"$host?me=$me\">next step of the setup</a>.<br />";
-
-      /* move on to the next stage*/
-      DB_set_hand_status_by_hash($me,'poverty');
-
-      /* check if everyone has reached this stage, send out email */
-      $userids = DB_get_all_userid_by_gameid($gameid);
-      $ok=1;
-      foreach($userids as $user)
-       {
-         $userstat = DB_get_hand_status_by_userid_and_gameid($user,$gameid);
-         if($userstat!='poverty' && $userstat!='play')
-           $ok=0;
+         
+         echo " Ok, done with checking, please go to the <a href=\"$host?me=$me\">next step of the setup</a>.<br />";
+         
+         /* move on to the next stage*/
+         DB_set_hand_status_by_hash($me,'poverty');
+         
+         /* check if everyone has reached this stage, send out email */
+         $userids = DB_get_all_userid_by_gameid($gameid);
+         $ok = 1;
+         foreach($userids as $user)
+           {
+             $userstat = DB_get_hand_status_by_userid_and_gameid($user,$gameid);
+             if($userstat!='poverty' && $userstat!='play')
+               {
+                 $ok = 0;
+                 DB_set_player_by_gameid($gameid,$user);
+               }
+           };
+         if($ok)
+           {
+             /* reset player = everyone has to do something now */
+             DB_set_player_by_gameid($gameid,NULL);
+             
+             foreach($userids as $user)
+               {
+                 $To       = DB_get_email_by_userid($user);
+                 $userhash = DB_get_hash_from_gameid_and_userid($gameid,$user);
+                 if($userhash != $me)
+                   {
+                     $message = "Everyone finish the questionary in game $gameid, ".
+                       "please visit this link now to continue: \n".
+                       " ".$host."?me=".$userhash."\n\n" ;
+                     mymail($To,$EmailName." finished setup in game $gameid",$message);
+                   }
+               };
+           };
        };
-      if($ok)
-       foreach($userids as $user)
-         {
-           $To = DB_get_email_by_userid($user);
-           $userhash =DB_get_hash_from_gameid_and_userid($gameid,$user);
-           if($userhash!=$me)
-             {
-               $message = "Everyone finish the questionary in game $gameid, ".
-                          "please visit this link now to continue: \n".
-                          " ".$host."?me=".$userhash."\n\n" ;
-               mymail($To,$EmailName." finished setup",$message);
-             }
-         };
 
       break;
 
@@ -441,12 +497,12 @@ else if(myisset("me"))
       
       /* check if everyone has reached this stage */
       $userids = DB_get_all_userid_by_gameid($gameid);
-      $ok=1;
+      $ok = 1;
       foreach($userids as $user)
        {
          $userstat = DB_get_hand_status_by_userid_and_gameid($user,$gameid);
          if($userstat!='poverty' && $userstat!='play')
-           $ok=0;
+           $ok = 0;
        };
 
       if(!$ok)
@@ -466,15 +522,13 @@ else if(myisset("me"))
          $startplayer = DB_get_startplayer_by_gameid($gameid);
 
          /* check for different sickness and just output a general info */
-
-         
-         $nines = 0;
+         $nines   = 0;
          $poverty = 0;
          $wedding = 0;
-         $solo = 0;
+         $solo    = 0;
          foreach($userids as $user)
            {
-             $name = DB_get_name_by_userid($user);
+             $name     = DB_get_name_by_userid($user);
              $usersick = DB_get_sickness_by_userid_and_gameid($user,$gameid);
              if($usersick == 'nines')
                {
@@ -501,7 +555,6 @@ else if(myisset("me"))
 
          /* now check which sickness comes first and set the gametype to it */
 
-         /* gamestatus == normal, => cancel game */
          if($gametype == "solo")
            {
              /* do nothing */
@@ -529,13 +582,14 @@ else if(myisset("me"))
              echo "The game has been canceled because ".DB_get_name_by_userid($nines).
                " has five or more nines and nobody is playing solo.\n";
              output_footer();
+             DB_close();
              exit();
            }
-         else if($poverty==1)
+         else if($poverty==1) /* one person has poverty */
            {
              DB_set_gametype_by_gameid($gameid,"poverty");
              $gametype = "poverty";
-             $who=DB_get_sickness_by_gameid($gameid);
+             $who      = DB_get_sickness_by_gameid($gameid);
              if(!$who)
                {
                  $firstsick = DB_get_sickness_by_pos_and_gameid(1,$gameid);
@@ -545,11 +599,11 @@ else if(myisset("me"))
                    DB_set_sickness_by_gameid($gameid,1); /* who needs to be asked first */
                }
            }
-         else if($poverty==2)
+         else if($poverty==2) /* two people have poverty */
            {
              DB_set_gametype_by_gameid($gameid,"dpoverty");
              $gametype = "dpoverty";
-             $who=DB_get_sickness_by_gameid($gameid);
+             $who      = DB_get_sickness_by_gameid($gameid);
              if(!$who)
                {
                  $firstsick = DB_get_sickness_by_pos_and_gameid(1,$gameid);
@@ -691,10 +745,11 @@ else if(myisset("me"))
                    {
                      $To       = DB_get_email_by_pos_and_gameid($who,$gameid);
                      $userhash = DB_get_hash_from_game_and_pos($gameid,$who);
-                     
+                     DB_set_player_by_gameid($gameid,$who);
+
                      $message = "Someone has poverty, it's your turn to decide, if you want to take the trump. Please visit:".
                        " ".$host."?me=".$userhash."\n\n" ;
-                     mymail($To,$EmailName." poverty",$message);
+                     mymail($To,$EmailName." poverty (game $gameid)",$message);
                    }
 
                  /* this user is done */
@@ -737,7 +792,8 @@ else if(myisset("me"))
                  $r      = mysql_fetch_array($result,MYSQL_NUM);
                  if(!$r)
                    {
-                     die("error in poverty");
+                     myerror("error in poverty");
+                     die();
                    };
                  if($r[0]==12)
                    {
@@ -770,13 +826,13 @@ else if(myisset("me"))
                            {
                              $To       = DB_get_email_by_pos_and_gameid($who,$gameid);
                              $userhash = DB_get_hash_from_game_and_pos($gameid,$who);
-                             
+                             DB_set_player_by_gameid($gameid,$who);
+
                              $message = "Someone has poverty, it's your turn to decide, ".
                                         "if you want to take the trump. Please visit:".
                                         " ".$host."?me=".$userhash."\n\n" ;
-                             mymail($To,$EmailName." poverty",$message);
+                             mymail($To,$EmailName." poverty (game $gameid)",$message);
                            }
-
                        }
                      
                      /* this user is done */
@@ -786,13 +842,13 @@ else if(myisset("me"))
                      DB_set_hand_status_by_hash($hash,'play');
 
                      /* set party to re, unless we had dpoverty, in that case check if we need to set re/contra*/
-                     $re_set=0;
+                     $re_set = 0;
                      foreach($userids as $user)
                        {
-                         $userhash =DB_get_hash_from_gameid_and_userid($gameid,$user);
-                         $party=DB_get_party_by_hash($userhash);
+                         $userhash = DB_get_hash_from_gameid_and_userid($gameid,$user);
+                         $party    = DB_get_party_by_hash($userhash);
                          if($party=="re")
-                           $re_set=1;
+                           $re_set = 1;
                        }
                      if($re_set)
                        {
@@ -803,7 +859,7 @@ else if(myisset("me"))
                        {
                          foreach($userids as $user)
                            {
-                             $userhash =DB_get_hash_from_gameid_and_userid($gameid,$user);
+                             $userhash = DB_get_hash_from_gameid_and_userid($gameid,$user);
                              if($userhash==$hash||$userhash==$me)
                                DB_set_party_by_hash($userhash,"re");
                              else
@@ -837,22 +893,21 @@ else if(myisset("me"))
                {
                  foreach($userids as $user)
                    {
-                     $name = DB_get_name_by_userid($user);
+                     $name     = DB_get_name_by_userid($user);
                      $usersick = DB_get_sickness_by_userid_and_gameid($user,$gameid);
                      
                      if($usersick=="poverty")
                        {
-                         $hash =DB_get_hash_from_gameid_and_userid($gameid,$user);
-                         $cards=DB_get_hand($hash);
-                         $nrtrump=count_trump($cards);
+                         $hash    = DB_get_hash_from_gameid_and_userid($gameid,$user);
+                         $cards   = DB_get_hand($hash);
+                         $nrtrump = count_trump($cards);
                          /* count trump */
                          if($nrtrump<4)
                            echo "Player $name has $nrtrump trump. Do you want to take them?".
                              "<a href=\"index.php?me=$me&amp;trump=$user\">yes</a> <br />";
                        }
                    }
-                 echo "I don't want to take any trump: ".
-                   "<a href=\"index.php?me=$me&amp;trump=no\">yes</a> <br />";
+                 echo "<a href=\"index.php?me=$me&amp;trump=no\">No,way I take those trump...</a> <br />";
 
                  echo "Your cards are: <br />\n";
                  $mycards = DB_get_hand($me);
@@ -870,66 +925,64 @@ else if(myisset("me"))
                  else
                    echo "it's not your turn yet to decide if you want to take the trump or not.";
                }
-             /*
-              *    yes, display number of trump and user's hand, ask if he wants to take it 
-              *      no, set whom-to-ask to next player, email next player, cancle game if no next player
-              *      yes -> link to new page:display all cards, ask for N return cards
-              *          set re/contra 
-              *        
-              */
            };
-       }
-      /* check if no one wanted to take trump, in that case the gamesickness would be set to 5 or 50 */
-      $who = DB_get_sickness_by_gameid($gameid);
-      if($who==5 || $who==50)
-       {
-         $message = "Hello, \n\n".
-           "Game $gameid has been cancled since nobody wanted to take the trump.\n";
-         
-         $userids = DB_get_all_userid_by_gameid($gameid);
-         foreach($userids as $user)
+         /* check if no one wanted to take trump, in that case the gamesickness would be set to 5 or 50 */
+         $who = DB_get_sickness_by_gameid($gameid);
+         if($who==5 || $who==50)
            {
-             $To = DB_get_email_by_userid($user);
-             mymail($To,$EmailName."game $gameid cancled (poverty not resolved)",$message);
+             $message = "Hello, \n\n".
+               "Game $gameid has been cancled since nobody wanted to take the trump.\n";
+             
+             $userids = DB_get_all_userid_by_gameid($gameid);
+             foreach($userids as $user)
+               {
+                 $To = DB_get_email_by_userid($user);
+                 mymail($To,$EmailName."game $gameid cancled (poverty not resolved)",$message);
+               }
+             
+             /* delete everything from the dB */
+             DB_cancel_game($me);
+             
+             echo "<p style=\"background-color:red\";>Game $gameid has been cancled.<br /><br /></p>";
+             output_footer();
+             DB_close();
+             exit();
            }
          
-         /* delete everything from the dB */
-         DB_cancel_game($me);
-         
-         echo "<p style=\"background-color:red\";>Game $gameid has been cancled.<br /><br /></p>";
-         output_footer();
-         exit();
-       }
-
-      /* check if all players are ready to play */
-      $ok=1;
-      foreach($userids as $user)
-       if(DB_get_hand_status_by_userid_and_gameid($user,$gameid)!='play')
-         $ok=0;
-
-      if($ok)
-       {
-         /* only set this after all poverty, etc. are handled*/
-         DB_set_game_status_by_gameid($gameid,'play');
-
-         /* email startplayer */
-         $startplayer = DB_get_startplayer_by_gameid($gameid);
-         $email       = DB_get_email_by_pos_and_gameid($startplayer,$gameid);
-         $hash        = DB_get_hash_from_game_and_pos($gameid,$startplayer);
+         /* check if all players are ready to play */
+         $ok = 1;
+         foreach($userids as $user)
+           if(DB_get_hand_status_by_userid_and_gameid($user,$gameid)!='play')
+             {
+               $ok = 0;
+               DB_set_player_by_gameid($gameid,$user);
+             }
          
-         if($hash!=$me)
+         if($ok)
            {
-             /* email startplayer) */
-             $message = "It's your turn now in game $gameid.\n".
-               "Use this link to play a card: ".$host."?me=".$hash."\n\n" ;
-             mymail($email,$EmailName."ready, set, go... ",$message);
+             /* only set this after all poverty, etc. are handled*/
+             DB_set_game_status_by_gameid($gameid,'play');
+             
+             /* email startplayer */
+             $startplayer = DB_get_startplayer_by_gameid($gameid);
+             $email       = DB_get_email_by_pos_and_gameid($startplayer,$gameid);
+             $hash        = DB_get_hash_from_game_and_pos($gameid,$startplayer);
+             $who         = DB_get_userid_by_email($email);
+             DB_set_player_by_gameid($gameid,$who);
+             
+             if($hash!=$me)
+               {
+                 /* email startplayer) */
+                 $message = "It's your turn now in game $gameid.\n".
+                   "Use this link to play a card: ".$host."?me=".$hash."\n\n" ;
+                 mymail($email,$EmailName."ready, set, go... (game $gameid) ",$message);
+               }
+             else
+               echo " Please, <a href=\"$host?me=$me\">start</a> the game.<br />";      
            }
          else
-           echo " Please, <a href=\"$host?me=$me\">start</a> the game.<br />";  
+           echo "\n <br />";    
        }
-      else
-       echo "\n <br />";        
-
       break;
     case 'play':
     case 'gameover': 
@@ -944,14 +997,14 @@ else if(myisset("me"))
        */
       
       $gametype = DB_get_gametype_by_gameid($gameid);
-      $GT = $gametype;
+      $GT       = $gametype;
       if($gametype=="solo")
        {
          $gametype = DB_get_solo_by_gameid($gameid);
-         $GT = $gametype." ".$GT;
+         $GT       = $gametype." ".$GT;
        }
       else
-       $gametype="normal";
+       $gametype = "normal";
       
       set_gametype($gametype); /* this sets the $CARDS variable */
       
@@ -984,7 +1037,8 @@ else if(myisset("me"))
                            "        Hand.party as party, ".
                            "        Hand.sickness as sickness, ".
                            "        Hand.point_call, ".
-                           "        User.last_login ".
+                           "        User.last_login, ".
+                           "        Hand.hash        ".
                            "FROM Hand ".
                            "LEFT JOIN User ON User.id=Hand.user_id ".
                            "WHERE Hand.game_id='".$gameid."' ".
@@ -1001,68 +1055,109 @@ else if(myisset("me"))
          $sickness  = $r[4];
          $call      = $r[5];
          $lastlogin = strtotime($r[6]);
-         
+         $hash      = $r[7];
+
          $offset = DB_get_user_timezone($user);
          $zone   = return_timezone($offset);
          date_default_timezone_set($zone);
 
          echo " <span class=\"table".($pos-1)."\">\n";
-         echo " $name ";
+         if(!$debug)
+           echo " $name \n";
+         else
+           {
+             echo "<a href=\"".$host."?me=".$hash."\">$name</a>\n";
+           }
          /* add hints for poverty, wedding, solo, etc */
          if($GT=="poverty" && $party=="re")
            if($sickness=="poverty")
              {
                $userhash = DB_get_hash_from_gameid_and_userid($gameid,$user);
-               $cards = DB_get_all_hand($userhash);
-               $trumpNR = count_trump($cards);
+               $cards    = DB_get_all_hand($userhash);
+               $trumpNR  = count_trump($cards);
                if($trumpNR)
-                 echo "(poverty < trump back)";
+                 echo "<img src=\"pics/button/poverty_trump_button.png\" class=\"button\" alt=\"poverty < trump back\" />";
                else
-                 echo "(poverty <)";
+                 echo "<img src=\"pics/button/poverty_notrump_button.png\" class=\"button\" alt=\"poverty <\" />";
              }
            else
-             echo "(poverty >)";
+             echo "<img src=\"pics/button/poverty_partner_button.png\" class=\"button\" alt=\"poverty >\" />";
 
          if($GT=="dpoverty")
            if($party=="re")
              if($sickness=="poverty")
                {
                $userhash = DB_get_hash_from_gameid_and_userid($gameid,$user);
-               $cards = DB_get_all_hand($userhash);
-               $trumpNR = count_trump($cards);
+               $cards    = DB_get_all_hand($userhash);
+               $trumpNR  = count_trump($cards);
                if($trumpNR)
-                 echo "(poverty A < trump back)";
+                 echo "<img src=\"pics/button/poverty_trump_button.png\" class=\"button\" alt=\"poverty < trump back\" />";
                else
-                 echo "(poverty A <)";
+                 echo "<img src=\"pics/button/poverty_notrump_button.png\" class=\"button\" alt=\"poverty <\" />";
                }
              else
-               echo "(poverty A >)";
+               echo "<img src=\"pics/button/poverty_partner_button.png\" class=\"button\" alt=\"poverty >\" />";
            else
              if($sickness=="poverty")
                {
                $userhash = DB_get_hash_from_gameid_and_userid($gameid,$user);
-               $cards = DB_get_all_hand($userhash);
-               $trumpNR = count_trump($cards);
+               $cards    = DB_get_all_hand($userhash);
+               $trumpNR  = count_trump($cards);
                if($trumpNR)
-                 echo "(poverty B < trump back)";
+                 echo "<img src=\"pics/button/poverty2_trump_button.png\" class=\"button\" alt=\"poverty2 < trump back\" />";
                else
-                 echo "(poverty B <)";
+                 echo "<img src=\"pics/button/poverty2_notrump_button.png\" class=\"button\" alt=\"poverty2 <\" />";
                }
              else
-               echo "(poverty B >)";
+               echo "<img src=\"pics/button/poverty2_partner_button.png\" class=\"button\" alt=\"poverty2 >\" />";
              
          if($GT=="wedding" && $party=="re")
              if($sickness=="wedding")
-               echo "(wedding  +)";
+               echo "<img src=\"pics/button/wedding_button.png\" class=\"button\" alt=\"wedding\" />";
              else
-               echo "(wedding)";
+               echo "<img src=\"pics/button/wedding_partner_button.png\" class=\"button\" alt=\"wedding partner\" />";
          
-         if(substr_compare($GT,"solo",0,4)==0 && $party=="re")
-            echo "($GT)";
+         if(ereg("solo",$GT) && $party=="re")
+           {
+             if(ereg("queen",$GT))
+               echo "<img src=\"pics/button/queensolo_button.png\" class=\"button\" alt=\"$GT\" />";
+             else if(ereg("jack",$GT))
+               echo "<img src=\"pics/button/jacksolo_button.png\" class=\"button\" alt=\"$GT\" />";
+             else if(ereg("club",$GT))
+               echo "<img src=\"pics/button/clubsolo_button.png\" class=\"button\" alt=\"$GT\" />";
+             else if(ereg("spade",$GT))
+               echo "<img src=\"pics/button/spadesolo_button.png\" class=\"button\" alt=\"$GT\" />";
+             else if(ereg("heart",$GT))
+               echo "<img src=\"pics/button/heartsolo_button.png\" class=\"button\" alt=\"$GT\" />";
+             else if(ereg("trumpless",$GT))
+               echo "<img src=\"pics/button/notrumpsolo_button.png\" class=\"button\" alt=\"$GT\" />";
+             else if(ereg("trump",$GT))
+               echo "<img src=\"pics/button/trumpsolo_button.png\" class=\"button\" alt=\"$GT\" />";
+           }
 
          /* add point calls */
          if($call!=NULL)
-           echo " $party $call ";
+           {
+             if($party=="re")
+               echo "<img src=\"pics/button/re_button.png\" class=\"button\" alt=\"re\" />";
+             else
+               echo "<img src=\"pics/button/contra_button.png\" class=\"button\" alt=\"contra\" />";
+             switch($call)
+               {
+               case "0":
+                 echo "<img src=\"pics/button/0_button.png\" class=\"button\" alt=\"0\" />";
+                 break;
+               case "30":
+                 echo "<img src=\"pics/button/30_button.png\" class=\"button\" alt=\"30\" />";
+                 break;
+               case "60":
+                 echo "<img src=\"pics/button/60_button.png\" class=\"button\" alt=\"60\" />";
+                 break;
+               case "90":
+                 echo "<img src=\"pics/button/90_button.png\" class=\"button\" alt=\"90\" />";
+                 break;
+               }
+           }
 
          echo "<br />\n";
          echo " local time: ".date("Y-m-d H:i:s")."<br />\n";
@@ -1087,8 +1182,7 @@ else if(myisset("me"))
                            "LEFT JOIN Comment ON Play.id=Comment.play_id ".
                            "WHERE Trick.game_id='".$gameid."' ".
                            "ORDER BY Trick.id,sequence ASC");
-      $trickNR = 1;
-      
+      $trickNR   = 1;
       $lasttrick = DB_get_max_trickid($gameid);
       
       $play = array(); /* needed to calculate winner later  */
@@ -1169,14 +1263,14 @@ else if(myisset("me"))
       /* whos turn is it? */
       if($seq==4)
        {
-         $winner = get_winner($play,$gametype); /* returns the position */
-         $next = $winner;
+         $winner    = get_winner($play,$gametype); /* returns the position */
+         $next      = $winner;
          $firstcard = ""; /* new trick, no first card */
        }
       else
        {
          $next = $pos+1;
-         if($next==5) $next=1;
+         if($next==5) $next = 1;
        }
       
       /* my turn?, display cards as links, ask for comments*/
@@ -1202,25 +1296,24 @@ else if(myisset("me"))
            {
              $comment = "";
 
-             /* mark card as played */
-             mysql_query("UPDATE Hand_Card SET played='true' WHERE hand_id='$handid' AND card_id=".
-                         DB_quote_smart($card));
-
              /* update Game timestamp */
              DB_update_game_timestamp($gameid);
 
-             /* check if a call was made */
-             if(myisset("call120") && $_REQUEST["call120"] == "yes")
+             /* check if a call was made, must do this before we set the card status to played */
+             if(myisset("call120") && $_REQUEST["call120"] == "yes" && can_call(120,$me))
                $result = mysql_query("UPDATE Hand SET point_call='120' WHERE hash='$me' ");
-             if(myisset("call90")  && $_REQUEST["call90"]  == "yes")
+             if(myisset("call90")  && $_REQUEST["call90"]  == "yes" && can_call(90,$me))
                $result = mysql_query("UPDATE Hand SET point_call='90'  WHERE hash='$me' ");
-             if(myisset("call60")  && $_REQUEST["call60"]  == "yes")
+             if(myisset("call60")  && $_REQUEST["call60"]  == "yes" && can_call(60,$me))
                $result = mysql_query("UPDATE Hand SET point_call='60'  WHERE hash='$me' ");
-             if(myisset("call30")  && $_REQUEST["call30"]  == "yes")
+             if(myisset("call30")  && $_REQUEST["call30"]  == "yes" && can_call(30,$me))
                $result = mysql_query("UPDATE Hand SET point_call='30'  WHERE hash='$me' ");
-             if(myisset("call0")   && $_REQUEST["call0"]   == "yes")
+             if(myisset("call0")   && $_REQUEST["call0"]   == "yes" && can_call(0,$me))
                $result = mysql_query("UPDATE Hand SET point_call='0'   WHERE hash='$me' ");
                
+             /* mark card as played */
+             mysql_query("UPDATE Hand_Card SET played='true' WHERE hand_id='$handid' AND card_id=".
+                         DB_quote_smart($card));
 
              /* check for schweinchen */
              //echo "schweinchen = ".$GAME["schweinchen"]." --$card-<br />";
@@ -1277,6 +1370,30 @@ else if(myisset("me"))
                        }
                    }
                }
+
+             /* if sequence == 4, set winner of the trick, count points and set the next player */
+             if($sequence==4)
+               {
+                 $play   = DB_get_cards_by_trick($trickid);
+                 $winner = get_winner($play,$gametype); /* returns the position */
+
+                 if($winner>0)
+                   mysql_query("UPDATE Trick SET winner='$winner' WHERE id='$trickid'");
+                 else
+                   echo "ERROR during scoring";
+
+                 if($debug)
+                   echo "DEBUG: position $winner won the trick <br />";
+
+                 /* who is the next player? */
+                 $next = $winner;
+               }
+             else
+               {
+                 $next = DB_get_pos_by_hash($me)+1;
+               }
+             if($next==5) $next=1;
+
              
              /* check for coment */
              if(myisset("comment"))
@@ -1311,107 +1428,67 @@ else if(myisset("me"))
                  $done=0;
              
              if($done)
+               DB_set_game_status_by_gameid($gameid,"gameover");
+
+             /* email next player, if game is still running */
+             if(DB_get_game_status_by_gameid($gameid)=='play')
                {
-                 DB_set_game_status_by_gameid($gameid,"gameover");
-                 /* get score for last trick 
-                  * all other tricks are handled a few lines further down*/
-                 $play   = DB_get_cards_by_trick($trickid);
-                 $winner = get_winner($play,$gametype); /* returns the position */
-                 /* get points of last trick and save it */
-                 $points = 0;
-                 foreach($play as $card)
-                   $points = $points + card_value($card["card"]);
-                 $winnerid = DB_get_handid_by_gameid_and_position($gameid,$winner);
-                 if($winnerid>0)
-                   mysql_query("INSERT INTO Score VALUES (NULL, '$gameid', '$winnerid', '$points')");
-                 else
-                   echo "ERROR during scoring";
+                 $next_hash = DB_get_hash_from_game_and_pos($gameid,$next);
+                 $email     = DB_get_email_by_hash($next_hash);
+                 $who       = DB_get_userid_by_email($email);
+                 DB_set_player_by_gameid($gameid,$who);
                  
-                 /* email all players */
+                 $message = "A card has been played in game $gameid.\n\n".
+                   "It's your turn  now.\n".
+                   "Use this link to play a card: ".$host."?me=".$next_hash."\n\n" ;
+                 mymail($email,$EmailName."a card has been played in game $gameid",$message);
+               }
+             else /* send out final email */
+               {
                  /* individual score */
-                 $result = mysql_query("SELECT fullname, SUM(score), Hand.party FROM Score".
-                                       " LEFT JOIN Hand ON Hand.id=hand_id".
-                                       " LEFT JOIN User ON Hand.user_id=User.id".
-                                       " WHERE Hand.game_id=$gameid".
-                                       " GROUP BY fullname" );
-                 $message = "The game is over. Thanks for playing :)\n";
+                 $result = mysql_query("SELECT User.fullname, IFNULL(SUM(Card.points),0), Hand.party FROM Hand".
+                               " LEFT JOIN Trick ON Trick.winner=Hand.position AND Trick.game_id=Hand.game_id".
+                               " LEFT JOIN User ON User.id=Hand.user_id".
+                               " LEFT JOIN Play ON Trick.id=Play.trick_id".
+                               " LEFT JOIN Hand_Card ON Hand_Card.id=Play.hand_card_id".
+                               " LEFT JOIN Card ON Card.id=Hand_Card.card_id".
+                               " WHERE Hand.game_id='$gameid'".
+                               " GROUP BY User.fullname" );
+                 $message  = "The game is over. Thanks for playing :)\n";
+                 $message .= "Final score:\n";
                  while( $r = mysql_fetch_array($result,MYSQL_NUM))
-                   $message .= " FINAL SCORE: ".$r[0]."(".$r[2].") ".$r[1]."\n";
-                 $message .= "\nIf your not in the list above your score is zero...\n\n";
-
-                 $result = mysql_query("SELECT Hand.party, SUM(score) FROM Score".
-                                       " LEFT JOIN Hand ON Hand.id=hand_id".
-                                       " LEFT JOIN User ON Hand.user_id=User.id".
-                                       " WHERE Hand.game_id=$gameid".
-                                       " GROUP BY Hand.party" );
-                 $message .= "\n";
+                   $message .= "   ".$r[0]."(".$r[2].") ".$r[1]."\n";
+
+                 $result = mysql_query("SELECT  Hand.party, IFNULL(SUM(Card.points),0) FROM Hand".
+                               " LEFT JOIN Trick ON Trick.winner=Hand.position AND Trick.game_id=Hand.game_id".
+                               " LEFT JOIN User ON User.id=Hand.user_id".
+                               " LEFT JOIN Play ON Trick.id=Play.trick_id".
+                               " LEFT JOIN Hand_Card ON Hand_Card.id=Play.hand_card_id".
+                               " LEFT JOIN Card ON Card.id=Hand_Card.card_id".
+                               " WHERE Hand.game_id='$gameid'".
+                               " GROUP BY User.fullname" );
+                 $message .= "\nTotals:\n";
                  while( $r = mysql_fetch_array($result,MYSQL_NUM))
-                   $message .= " FINAL SCORE: ".$r[0]." ".$r[1]."\n";
+                   $message .= "    ".$r[0]." ".$r[1]."\n";
                  
-                 /* check who wants to be CC'ed on the email */
-                 $h = array();
-                 $header = "";
+                 /* send out final email */
+                 $all = array();
+
                  foreach($userids as $user)
-                   {
-                     $result = mysql_query("SELECT value from User_Prefs".
-                                           " WHERE user_id='$user' AND pref_key='ccemail'" );
-                     $r = mysql_fetch_array($result,MYSQL_NUM);
-                     if($r && $r[0]=="yes")
-                       $h[]   = DB_get_email_by_userid($user);
-                   }
-                 if(sizeof($h))
-                   $header = "CC: ".join(",",$h)."\r\n";
-                 
+                   $all[] = DB_get_email_by_userid($user);
+                 $To = implode(",",$all);
+
+                 $help = "\n\n (you can use reply all on this email to reach all the players.)\n";
+                 mymail($To,$EmailName."game over (game $gameid) part 1(2)",$message.$help);
+
                  foreach($userids as $user)
                    {
                      $To   = DB_get_email_by_userid($user);
                      $hash = DB_get_hash_from_gameid_and_userid($gameid,$user);
-                     $mymessage = $message."Use this link to have a look at the game: ".$host."?me=".$hash."\n\n" ;
-                     mymail($To,$EmailName."game over (game $gameid)",$mymessage,$header);
-                   }
-               }
-             
-             
-             /* email next player */
-             if(DB_get_game_status_by_gameid($gameid)=='play')
-               {
-                 if($sequence==4)
-                   {
-                     $play   = DB_get_cards_by_trick($trickid);
-                     $winner = get_winner($play,$gametype); /* returns the position */
                      
-                     /* get points of last trick and save it, last trick is handled 
-                      * a few lines further up  */
-                     $points = 0;
-                     foreach($play as $card)
-                       $points = $points + card_value($card["card"]);
-                     
-                     $winnerid = DB_get_handid_by_gameid_and_position($gameid,$winner);
-                     if($winnerid>0)
-                       mysql_query("INSERT INTO Score VALUES (NULL, '$gameid', '$winnerid', '$points')");
-                     else
-                       echo "ERROR during scoring";
-                     
-                     if($debug)
-                       echo "DEBUG: $winner got $points <br />";
-                     
-                     /* who is the next player? */
-                     $next = $winner;
-                   }
-                 else
-                   {
-                     $next = DB_get_pos_by_hash($me)+1;
+                     $link = "Use this link to have a look at game $gameid: ".$host."?me=".$hash."\n\n" ;
+                     mymail($To,$EmailName."game over (game $gameid) part 2(2)",$link);
                    }
-                 if($next==5) $next=1;
-                 
-                 /* email next player */
-                 $next_hash = DB_get_hash_from_game_and_pos($gameid,$next);
-                 $email     = DB_get_email_by_hash($next_hash);
-                 
-                 $message = "A card has been played in game $gameid.\n\n".
-                   "It's your turn  now.\n".
-                   "Use this link to play a card: ".$host."?me=".$next_hash."\n\n" ;
-                 mymail($email,$EmailName."a card has been played",$message);            
                }
            }
          else
@@ -1461,7 +1538,9 @@ else if(myisset("me"))
                " <input type=\"radio\" name=\"call30\" value=\"yes\" /> ";
          if( can_call(0,$me) )
              echo " 0:".
-               " <input type=\"radio\" name=\"call0\" value=\"yes\" /> ";
+               " <input type=\"radio\" name=\"call0\" value=\"yes\" /> ".
+               " no call:".
+               " <input type=\"radio\" name=\"call0\" value=\"no\" /> ";
 
          echo "<br />\nA short comments:<input name=\"comment\" type=\"text\" size=\"30\" maxlength=\"50\" />\n";
          echo "<input type=\"hidden\" name=\"me\" value=\"$me\" />\n";
@@ -1481,10 +1560,28 @@ else if(myisset("me"))
          echo "Your cards were: <br />\n";
          foreach($oldcards as $card) 
            display_card($card,$PREF["cardset"]);
+         
+         $userids = DB_get_all_userid_by_gameid($gameid);
+          foreach($userids as $user)
+            {
+              $userhash = DB_get_hash_from_gameid_and_userid($gameid,$user);
+             
+              if($userhash!=$me)
+                {
+                  echo "<br />";
+                 
+                  $name = DB_get_name_by_userid($user);
+                  $oldcards = DB_get_all_hand($userhash);
+                  $oldcards = mysort($oldcards,$gametype);
+                  echo "$name's cards were: <br />\n";
+                  foreach($oldcards as $card)
+                    display_card($card,$PREF["cardset"]);
+                }
+            }
        }
       echo "</div>\n";
       
-      /* check if we need to set status to 'gameover' is done during playing of the card */
+      /* if the game is over do some extra stuff, therefore exit the swtich statement if we are still playing*/
       if($mystatus=='play')
        break;
       /* the following happens only when the gamestatus is 'gameover' */
@@ -1497,29 +1594,41 @@ else if(myisset("me"))
        {
          echo "the game is over now...<br />\n";
          
-         $result = mysql_query("SELECT fullname, SUM(score), Hand.party FROM Score".
-                               " LEFT JOIN Hand ON Hand.id=hand_id".
-                               " LEFT JOIN User ON Hand.user_id=User.id".
-                               " WHERE Hand.game_id=$gameid".
-                               " GROUP BY fullname" );
+         $result = mysql_query("SELECT User.fullname, IFNULL(SUM(Card.points),0), Hand.party FROM Hand".
+                               " LEFT JOIN Trick ON Trick.winner=Hand.position AND Trick.game_id=Hand.game_id".
+                               " LEFT JOIN User ON User.id=Hand.user_id".
+                               " LEFT JOIN Play ON Trick.id=Play.trick_id".
+                               " LEFT JOIN Hand_Card ON Hand_Card.id=Play.hand_card_id".
+                               " LEFT JOIN Card ON Card.id=Hand_Card.card_id".
+                               " WHERE Hand.game_id='$gameid'".
+                               " GROUP BY User.fullname" );
+         echo "Final Score:<br />\n".
+           " <table>\n";;
          while( $r = mysql_fetch_array($result,MYSQL_NUM))
-           echo " FINAL SCORE: ".$r[0]."(".$r[2].") ".$r[1]."<br />";
-         
-         $result = mysql_query("SELECT Hand.party, SUM(score) FROM Score".
-                               " LEFT JOIN Hand ON Hand.id=hand_id".
-                               " LEFT JOIN User ON Hand.user_id=User.id".
-                               " WHERE Hand.game_id=$gameid".
+           echo "  <tr><td>  ".$r[0]."</td><td>(".$r[2].")</td><td> ".$r[1]."</td></tr>";
+         echo "</table>\n";
+
+
+         $result = mysql_query("SELECT Hand.party, IFNULL(SUM(Card.points),0) FROM Hand".
+                               " LEFT JOIN Trick ON Trick.winner=Hand.position AND Trick.game_id=Hand.game_id".
+                               " LEFT JOIN User ON User.id=Hand.user_id".
+                               " LEFT JOIN Play ON Trick.id=Play.trick_id".
+                               " LEFT JOIN Hand_Card ON Hand_Card.id=Play.hand_card_id".
+                               " LEFT JOIN Card ON Card.id=Hand_Card.card_id".
+                               " WHERE Hand.game_id='$gameid'".
                                " GROUP BY Hand.party" );
+         echo "Totals:<br />\n".
+           " <table> \n";
          while( $r = mysql_fetch_array($result,MYSQL_NUM))
-           echo " FINAL SCORE: ".$r[0]." ".$r[1]."<br />\n";
-
+           echo "  <tr><td>".$r[0]."</td><td> ".$r[1]."</td></tr>\n";
+         echo "</table>\n";
          
          $session = DB_get_session_by_gameid($gameid);
          $result  = mysql_query("SELECT id,create_date FROM Game".
                                 " WHERE session=$session".
                                 " ORDER BY create_date DESC".
                                 " LIMIT 1");
-         $r=-1;
+         $r = -1;
          if($result)
            $r = mysql_fetch_array($result,MYSQL_NUM);
          
@@ -1532,9 +1641,10 @@ else if(myisset("me"))
        }
       break;
     default:
-      echo "error in testing the status";
+      myerror("error in testing the status");
     }
     output_footer();
+    DB_close();
     exit();
  } 
 /* user status page */ 
@@ -1547,24 +1657,57 @@ else if(myisset("me"))
 
      if(myisset("forgot"))
        {
-        $ok=1;
+        $ok = 1;
 
         $uid = DB_get_userid_by_email($email);
         if(!$uid)
-          $ok=0;
+          $ok = 0;
         
         if($ok)
           {
-            echo "Hmm, you forgot your passwort...nothing I can do at the moment:(  ";
-            echo " you need to email Arun for now... in the future it will be all automated and an ";
-            echo "email with a new password will go to $email.";
+            /* check how many entries in recovery table */
+            $number = DB_get_number_of_passwords_recovery($uid);
+            
+            /* if less than N recent ones, add a new one and send out email */
+            if( $number < 5 )
+              {
+                echo "Ok, I send you a new password. <br />";
+                if($number >1)
+                  echo "N.B. You tried this already $number times during the last day and it will only work ".
+                    " 5 times during a day.<br />";
+                echo "The new password will be valid for one day, make sure you reset it to something else.<br />";
+                echo "Back to the  <a href=\"$host\">main page</a>.";
+                
+                $TIME  = (string) time(); /* to avoid collisions */
+                $hash  = md5("Anewpassword".$email.$TIME);
+                $newpw = substr($hash,1,8);
+                
+                $message = "Someone (hopefully you) requested a new password. \n".
+                  "You can use this email and the following password: \n".
+                  "   $newpw    \n".
+                  "to log into the server. The new password is valid for 24h, so make\n".
+                  "sure you reset your password to something new. Your old password will\n".
+                  " also still be valid until you set a new one\n";
+                mymail($email,$EmailName."recovery ",$message);
+                
+                DB_set_recovery_password($uid,md5($newpw));
+              }
+            else
+              {
+                echo "Sorry you already tried 5 times during the last 24h.<br />".
+                  "You need to use one of those passwords or wait to get a new one.<br />";
+                echo "Back to the <a href=\"$host\">main page</a>.";
+              }
           }
         else
           {
             if($email=="")
-              echo "you need to give me an email address!";
+              echo "You need to give me an email address! <br />".
+                "Please try <a href=\"$host\">again</a>.";
             else
-              echo "couldn't find a player with this email, please contact Arun, if you think this is a mistake";
+              echo "Couldn't find a player with this email! <br />".
+                "Please contact Arun, if you think this is a mistake <br />".
+                "or else try <a href=\"$host\">again</a>.";
           } 
        }
      else 
@@ -1573,10 +1716,10 @@ else if(myisset("me"))
        if(strlen($password)!=32)
         $password = md5($password);
        
-       $ok=1;
+       $ok  = 1;
        $uid = DB_get_userid_by_email_and_password($email,$password);
        if(!$uid)
-        $ok=0;
+        $ok = 0;
        
        if($ok)
         {
@@ -1595,24 +1738,46 @@ else if(myisset("me"))
                     $result = mysql_query("UPDATE User_Prefs SET value=".DB_quote_smart($setpref).
                                           " WHERE user_id='$uid' AND pref_key='cardset'" );
                   else
-                    $result = mysql_query("INSERT INTO User_Prefs VALUES(NULL,'$uid','cardset',".DB_quote_smart($setpref).")");
+                    $result = mysql_query("INSERT INTO User_Prefs VALUES(NULL,'$uid','cardset',".
+                                          DB_quote_smart($setpref).")");
                   echo "Ok, changed you preferences for the cards.\n";
                   break;
-                case "ccemail":
-                  $result = mysql_query("SELECT * from User_Prefs".
-                                        " WHERE user_id='$uid' AND pref_key='ccemail'" );
-                  if( mysql_fetch_array($result,MYSQL_NUM))
-                    if($PREF["ccemail"]=="yes")
-                      $result = mysql_query("UPDATE User_Prefs SET value=".DB_quote_smart("no").
-                                            " WHERE user_id='$uid' AND pref_key='ccemail'" );
-                    else
-                      $result = mysql_query("UPDATE User_Prefs SET value=".DB_quote_smart("yes").
-                                            " WHERE user_id='$uid' AND pref_key='ccemail'" );
-                  else
-                    $result = mysql_query("INSERT INTO User_Prefs VALUES(NULL,'$uid','ccemail',".DB_quote_smart("yes").")");
-                  echo "Ok, changed you preferences for being CC'ed on emails.\n";
-                  break;
-
+                }
+            }
+          else if(myisset("passwd"))
+            {
+              if( $_REQUEST["passwd"]=="ask" )
+                {
+                  /* reset password form*/
+                  output_password_recovery($email,$password);         
+                }
+              else if($_REQUEST["passwd"]=="set")
+                {
+                  /* reset password */
+                  $ok = 1;
+
+                  /* check if old password matches */
+                  if($password != md5($_REQUEST["password0"]))
+                    $ok = -1;
+                  /* check if new passwords are types the same twice */
+                  if($_REQUEST["password1"] != $_REQUEST["password2"] )
+                    $ok = -2;
+                  
+                  switch($ok)
+                    {
+                    case '-2':
+                      echo "The new passwords don't match. <br />";
+                      break;
+                    case '-1':
+                      echo "The old password is not correct. <br />";
+                      break;
+                    case '1':
+                      echo "Changed the password.<br />";
+                      mysql_query("UPDATE User SET password='".md5($_REQUEST["password1"]).
+                                  "' WHERE id=".DB_quote_smart($uid));
+                      break;
+                    }
+                  /* set password */
                 }
             }
           else /* output default user page */
@@ -1631,13 +1796,21 @@ else if(myisset("me"))
               
               DB_update_user_timestamp($uid);
               
-              echo "<p>these are your games that haven't started yet:<br />\n";
-              $result = mysql_query("SELECT Hand.hash,Hand.game_id,Game.mod_date from Hand".
+              echo "<p>These are your games that haven't started yet:<br />\n";
+              $result = mysql_query("SELECT Hand.hash,Hand.game_id,Game.mod_date,Game.player from Hand".
                                     " LEFT JOIN Game On Hand.game_id=Game.id".
                                     " WHERE Hand.user_id='$uid' AND Game.status='pre'" );
               while( $r = mysql_fetch_array($result,MYSQL_NUM))
                 {
                   echo "<a href=\"".$host."?me=".$r[0]."\">game #".$r[1]." </a>";
+                  if($r[3]==$uid || $r[3]==NULL)
+                    echo "(it's <strong>your</strong> turn)\n";
+                  else
+                    {
+                      $name = DB_get_name_by_userid($r[3]);
+                      echo "(it's $name's turn)\n";
+                    };
+                    
                   if(time()-strtotime($r[2]) > 60*60*24*30)
                     echo " The game has been running for over a month.".
                       " Do you want to cancel it? <a href=\"$host?cancle=1&amp;me=".$r[0]."\">yes</a>".
@@ -1646,13 +1819,23 @@ else if(myisset("me"))
                 }
               echo "</p>\n";
 
-              echo "<p>these are the games you are playing in:<br />\n";
-              $result = mysql_query("SELECT Hand.hash,Hand.game_id,Game.mod_date from Hand".
+              echo "<p>These are the games you are playing in:<br />\n";
+              $result = mysql_query("SELECT Hand.hash,Hand.game_id,Game.mod_date,Game.player from Hand".
                                     " LEFT JOIN Game On Hand.game_id=Game.id".
                                     " WHERE Hand.user_id='$uid' AND Game.status='play'" );
               while( $r = mysql_fetch_array($result,MYSQL_NUM))
                 {
                   echo "<a href=\"".$host."?me=".$r[0]."\">game #".$r[1]." </a>";
+                  if($r[3])
+                    {
+                      if($r[3]==$uid)
+                        echo "(it's <strong>your</strong> turn)\n";
+                      else
+                        {
+                          $name = DB_get_name_by_userid($r[3]);
+                          echo "(it's $name's turn)\n";
+                        };
+                    }
                   if(time()-strtotime($r[2]) > 60*60*24*30)
                     echo " The game has been running for over a month.".
                       " Do you want to cancel it? <a href=\"$host?cancle=1&amp;me=".$r[0]."\">yes</a>".
@@ -1662,16 +1845,16 @@ else if(myisset("me"))
               echo "</p>\n";
               
               
-              echo "<p>and these are your games that are already done:<br />Game: \n";
+              echo "<p>And these are your games that are already done:<br />Game: \n";
+              $output = array();
               $result = mysql_query("SELECT hash,game_id from Hand WHERE user_id='$uid' AND status='gameover'" );
               while( $r = mysql_fetch_array($result,MYSQL_NUM))
-                echo "<a href=\"".$host."?me=".$r[0]."\">#".$r[1]." </a>, ";
-              echo "</p>\n";
+                $output[] = "<a href=\"".$host."?me=".$r[0]."\">#".$r[1]." </a>";
+              echo implode(", ",$output)."</p>\n";
               
               $names = DB_get_all_names();
-              echo "<p>registered players:<br />\n";
-              foreach ($names as $name)
-                echo "$name, \n";
+              echo "<p>Registered players:<br />\n";
+              echo implode(", ",$names)."\n";
               echo "</p>\n";
               
               echo "<p>Want to start a new game? Visit <a href=\"".$host."?new\">this page.</a></p>";
@@ -1679,10 +1862,11 @@ else if(myisset("me"))
         }
        else
         {
-          echo "sorry email and password don't match <br />";
+          echo "Sorry email and password don't match <br />";
         }
      };
      output_footer();
+     DB_close();
      exit();
    }
 /* page for registration */
@@ -1727,7 +1911,14 @@ else if(myisset("me"))
        $game = mysql_fetch_array($r,MYSQL_NUM);     
        $done = mysql_fetch_array($r,MYSQL_NUM);     
      }
-     output_home_page($pre[0],$game[0],$done[0]);
+
+     $r=mysql_query("SELECT AVG(datediff(mod_date,create_date)) FROM Game where status='gameover' ");
+     if($r)
+       $avgage= mysql_fetch_array($r,MYSQL_NUM);     
+     else
+       $avgage[0]=0;
+
+     output_home_page($pre[0],$game[0],$done[0],$avgage[0]);
    }
 
 output_footer();