NEW FEATURE: password recovery is now working
[e-DoKo.git] / index.php
index 1db07ce06bc033677d817052623054d74cbd4b1d..83ada9ad8080b2482582b2cd135c8829bc0033d4 100644 (file)
--- a/index.php
+++ b/index.php
@@ -9,6 +9,10 @@ include_once("functions.php");   /* the rest */
 /* check if some variables are set in the config file, else set defaults */
 if(!isset($EmailName))
      $EmailName="[DoKo] ";
+if(isset($EMAIL_REPLY))
+  {
+    ini_set("sendmail_from",$EMAIL_REPLY);
+  }
 
 /* in case work has to be done on the database or other section we can
  * shut down the server and tell people to come back later 
@@ -1042,12 +1046,12 @@ else if(myisset("me"))
                $cards    = DB_get_all_hand($userhash);
                $trumpNR  = count_trump($cards);
                if($trumpNR)
-                 echo "(poverty < trump back)";
+                 echo "<img src=\"pics/button/poverty_trump_button.png\" class=\"button\" alt=\"poverty < trump back\" />";
                else
-                 echo "(poverty <)";
+                 echo "<img src=\"pics/button/poverty_notrump_button.png\" class=\"button\" alt=\"poverty <\" />";
              }
            else
-             echo "(poverty >)";
+             echo "<img src=\"pics/button/poverty_partner_button.png\" class=\"button\" alt=\"poverty >\" />";
 
          if($GT=="dpoverty")
            if($party=="re")
@@ -1057,12 +1061,12 @@ else if(myisset("me"))
                $cards    = DB_get_all_hand($userhash);
                $trumpNR  = count_trump($cards);
                if($trumpNR)
-                 echo "(poverty A < trump back)";
+                 echo "<img src=\"pics/button/poverty_trump_button.png\" class=\"button\" alt=\"poverty < trump back\" />";
                else
-                 echo "(poverty A <)";
+                 echo "<img src=\"pics/button/poverty_notrump_button.png\" class=\"button\" alt=\"poverty <\" />";
                }
              else
-               echo "(poverty A >)";
+               echo "<img src=\"pics/button/poverty_partner_button.png\" class=\"button\" alt=\"poverty >\" />";
            else
              if($sickness=="poverty")
                {
@@ -1070,25 +1074,60 @@ else if(myisset("me"))
                $cards    = DB_get_all_hand($userhash);
                $trumpNR  = count_trump($cards);
                if($trumpNR)
-                 echo "(poverty B < trump back)";
+                 echo "<img src=\"pics/button/poverty2_trump_button.png\" class=\"button\" alt=\"poverty2 < trump back\" />";
                else
-                 echo "(poverty B <)";
+                 echo "<img src=\"pics/button/poverty2_notrump_button.png\" class=\"button\" alt=\"poverty2 <\" />";
                }
              else
-               echo "(poverty B >)";
+               echo "<img src=\"pics/button/poverty2_partner_button.png\" class=\"button\" alt=\"poverty2 >\" />";
              
          if($GT=="wedding" && $party=="re")
              if($sickness=="wedding")
-               echo "(wedding  +)";
+               echo "<img src=\"pics/button/wedding_button.png\" class=\"button\" alt=\"wedding\" />";
              else
-               echo "(wedding)";
+               echo "<img src=\"pics/button/wedding_partner_button.png\" class=\"button\" alt=\"wedding partner\" />";
          
          if(ereg("solo",$GT) && $party=="re")
-            echo "($GT)";
+           {
+             if(ereg("queen",$GT))
+               echo "<img src=\"pics/button/queensolo_button.png\" class=\"button\" alt=\"$GT\" />";
+             else if(ereg("jack",$GT))
+               echo "<img src=\"pics/button/jacksolo_button.png\" class=\"button\" alt=\"$GT\" />";
+             else if(ereg("club",$GT))
+               echo "<img src=\"pics/button/clubsolo_button.png\" class=\"button\" alt=\"$GT\" />";
+             else if(ereg("spade",$GT))
+               echo "<img src=\"pics/button/spadesolo_button.png\" class=\"button\" alt=\"$GT\" />";
+             else if(ereg("heart",$GT))
+               echo "<img src=\"pics/button/heartsolo_button.png\" class=\"button\" alt=\"$GT\" />";
+             else if(ereg("trumpless",$GT))
+               echo "<img src=\"pics/button/notrumpsolo_button.png\" class=\"button\" alt=\"$GT\" />";
+             else if(ereg("trump",$GT))
+               echo "<img src=\"pics/button/diamandsolo_button.png\" class=\"button\" alt=\"$GT\" />";
+           }
 
          /* add point calls */
          if($call!=NULL)
-           echo " $party $call ";
+           {
+             if($party=="re")
+               echo "<img src=\"pics/button/re_button.png\" class=\"button\" alt=\"re\" />";
+             else
+               echo "<img src=\"pics/button/contra_button.png\" class=\"button\" alt=\"contra\" />";
+             switch($call)
+               {
+               case "0":
+                 echo "<img src=\"pics/button/0_button.png\" class=\"button\" alt=\"0\" />";
+                 break;
+               case "30":
+                 echo "<img src=\"pics/button/30_button.png\" class=\"button\" alt=\"30\" />";
+                 break;
+               case "60":
+                 echo "<img src=\"pics/button/60_button.png\" class=\"button\" alt=\"60\" />";
+                 break;
+               case "90":
+                 echo "<img src=\"pics/button/90_button.png\" class=\"button\" alt=\"90\" />";
+                 break;
+               }
+           }
 
          echo "<br />\n";
          echo " local time: ".date("Y-m-d H:i:s")."<br />\n";
@@ -1377,7 +1416,7 @@ else if(myisset("me"))
 
                  foreach($userids as $user)
                    $all[] = DB_get_email_by_userid($user);
-                 $TO = implode(",",$all);
+                 $To = implode(",",$all);
 
                  $help = "\n\n (you can use reply all on this email to reach all the players.)\n";
                  mymail($To,$EmailName."game over (game $gameid) part 1(2)",$message.$help);
@@ -1604,16 +1643,49 @@ else if(myisset("me"))
         
         if($ok)
           {
-            echo "Hmm, you forgot your passwort...nothing I can do at the moment:(  ";
-            echo " you need to email Arun for now... in the future it will be all automated and an ";
-            echo "email with a new password will go to $email.";
+            /* check how many entries in recovery table */
+            $number = DB_get_number_of_passwords_recovery($uid);
+            
+            /* if less than N recent ones, add a new one and send out email */
+            if( $number < 5 )
+              {
+                echo "Ok, I send you a new password. <br />";
+                if($number >1)
+                  echo "N.B. You tried this already $number times during the last day and it will only work ".
+                    " 5 times during a day.<br />";
+                echo "The new password will be valid for one day, make sure you reset it to something else.<br />";
+                echo "Back to the  <a href=\"$host\">main page</a>.";
+                
+                $TIME  = (string) time(); /* to avoid collisions */
+                $hash  = md5("Anewpassword".$email.$TIME);
+                $newpw = substr($hash,1,8);
+                
+                $message = "Someone (hopefully you) requested a new password. \n".
+                  "You can use this email and the following password: \n".
+                  "   $newpw    \n".
+                  "to log into the server. The new password is valid for 24h, so make\n".
+                  "sure you reset your password to something new. Your old password will\n".
+                  " also still be valid until you set a new one\n";
+                mymail($email,$EmailName."recovery ",$message);
+                
+                DB_set_recovery_password($uid,md5($newpw));
+              }
+            else
+              {
+                echo "Sorry you already tried 5 times during the last 24h.<br />".
+                  "You need to use one of those passwords or wait to get a new one.<br />";
+                echo "Back to the <a href=\"$host\">main page</a>.";
+              }
           }
         else
           {
             if($email=="")
-              echo "you need to give me an email address!";
+              echo "You need to give me an email address! <br />".
+                "Please try <a href=\"$host\">again</a>.";
             else
-              echo "couldn't find a player with this email, please contact Arun, if you think this is a mistake";
+              echo "Couldn't find a player with this email! <br />".
+                "Please contact Arun, if you think this is a mistake <br />".
+                "or else try <a href=\"$host\">again</a>.";
           } 
        }
      else 
@@ -1644,11 +1716,48 @@ else if(myisset("me"))
                     $result = mysql_query("UPDATE User_Prefs SET value=".DB_quote_smart($setpref).
                                           " WHERE user_id='$uid' AND pref_key='cardset'" );
                   else
-                    $result = mysql_query("INSERT INTO User_Prefs VALUES(NULL,'$uid','cardset',".DB_quote_smart($setpref).")");
+                    $result = mysql_query("INSERT INTO User_Prefs VALUES(NULL,'$uid','cardset',".
+                                          DB_quote_smart($setpref).")");
                   echo "Ok, changed you preferences for the cards.\n";
                   break;
                 }
             }
+          else if(myisset("passwd"))
+            {
+              if( $_REQUEST["passwd"]=="ask" )
+                {
+                  /* reset password form*/
+                  output_password_recovery($email,$password);         
+                }
+              else if($_REQUEST["passwd"]=="set")
+                {
+                  /* reset password */
+                  $ok = 1;
+
+                  /* check if old password matches */
+                  if($password != md5($_REQUEST["password0"]))
+                    $ok = -1;
+                  /* check if new passwords are types the same twice */
+                  if($_REQUEST["password1"] != $_REQUEST["password2"] )
+                    $ok = -2;
+                  
+                  switch($ok)
+                    {
+                    case '-2':
+                      echo "The new passwords don't match. <br />";
+                      break;
+                    case '-1':
+                      echo "The old password is not correct. <br />";
+                      break;
+                    case '1':
+                      echo "Changed the password.<br />";
+                      mysql_query("UPDATE User SET password='".md5($_REQUEST["password1"]).
+                                  "' WHERE id=".DB_quote_smart($uid));
+                      break;
+                    }
+                  /* set password */
+                }
+            }
           else /* output default user page */
             {
               $time = DB_get_user_timestamp($uid);