BUGFIX: reusing old randomnumbers didn't work
[e-DoKo.git] / index.php
index 2c0045dc3480ea316a8762de432924c44ff14427..fef72fdd78fc02bc20b62c04093e30cc6bb4afaf 100644 (file)
--- a/index.php
+++ b/index.php
@@ -51,11 +51,21 @@ if(DB_open()<0)
     exit(); 
   }
 
+/* start a session, if it is not already running */
+session_start();
+
 /* done major error checking, output header of HTML page */
 output_header();
 
 /* check if we want to start a new game */
-if(myisset("new"))
+if(myisset("logout"))
+  {
+    session_unset();
+    session_destroy();
+    $_SESSION = array();
+    echo "you are now logged out!";
+  }
+else if(myisset("new"))
   {
     $names = DB_get_all_names();
     output_form_for_new_game($names);
@@ -204,7 +214,7 @@ else if(myisset("cancle","me"))
     /* get some information from the DB */
     $gameid   = DB_get_gameid_by_hash($me);
     $myname   = DB_get_name_by_hash($me);
-    
+
     /* check if game really is old enough */
     $result = mysql_query("SELECT mod_date from Game WHERE id='$gameid' " );
     $r = mysql_fetch_array($result,MYSQL_NUM);
@@ -245,6 +255,9 @@ else if(myisset("me"))
        exit();
       }
 
+    if(isset($_SESSION["name"]))
+      output_status($_SESSION["name"]);
+
     /* the user had done something, update the timestamp */
     DB_update_user_timestamp($myid);
     
@@ -289,9 +302,9 @@ else if(myisset("me"))
       echo " Gametype: $GT <br />\n";
     
     echo "Rules: <br />\n";
-    echo "10ofhearts : ".$r[2]."<br />\n";
-    echo "schweinchen: ".$r[3]."<br />\n";
-    echo "call:        ".$r[4]."<br />\n";
+    echo "10ofhearts : ".$RULES["dullen"]      ."<br />\n";
+    echo "schweinchen: ".$RULES["schweinchen"] ."<br />\n";
+    echo "call:        ".$RULES["call"]        ."<br />\n";
     echo "</div>\n";
 
     /* output extra division in case this game is part of a session */
@@ -339,24 +352,30 @@ else if(myisset("me"))
     switch($mystatus)
       {
       case 'start':
-       check_want_to_play($me);
-       /* move on to the next stage*/
-       DB_set_hand_status_by_hash($me,'init');
-       break;
+       if( !myisset("in") )
+         {
+           output_check_want_to_play($me);
+           break;
+         }
+       else
+         {
+           /* move on to the next stage*/
+           DB_set_hand_status_by_hash($me,'init');
+         }
       case 'init':
        /* first check if everything went ok  in the last step
         * if not, send user back, if yes, check what he did
         */
        if( !myisset("in") )
          {
-           echo "<p> you need to answer the <a href=\"$host?me=$me\">question</a>.</p>";
+           echo "<p> You need to answer the <a href=\"$host?me=$me\">question</a>.</p>";
            DB_set_hand_status_by_hash($me,'start');
          }
        else
          {
            if($_REQUEST["in"] == "no")
              {
-               /* cancle the game */
+               /* cancel the game */
                $message = "Hello, \n\n".
                  "the game has been canceled due to the request of one of the players.\n";
                
@@ -372,7 +391,7 @@ else if(myisset("me"))
              }
            else
              {
-               echo "thanks for joining the game...";
+               echo "Thanks for joining the game...";
                
                $mycards = DB_get_hand($me);
                sort($mycards);
@@ -393,17 +412,20 @@ else if(myisset("me"))
       /* ok, user is in the game, saw his cards and selected his vorbehalt
        * so first we check what he selected
        */
-      echo "Processing what you selected in the last step...<br />";
-
       if(!myisset("solo","wedding","poverty","nines") )
        {
          /* all these variables have a pre-selected default,
           * so we should never get here,
-          * unless a user tries to cheat ;) */
-         echo "something went wrong during the setup...please contact the $ADMIN_NAME at $ADMIN_EMAIL.";
+          * unless a user tries to cheat ;)
+          * can also happen if user reloads the page!
+          */
+         echo "<p> You need to answer the <a href=\"$host?me=$me&in=yes\">questions</a>.</p>";
+         DB_set_hand_status_by_hash($me,'init');
        }
       else
        {
+         echo "Processing what you selected in the last step...<br />";
+      
          /* check if this sickness needs to be handled first */
          $gametype    = DB_get_gametype_by_gameid($gameid);
          $startplayer = DB_get_startplayer_by_gameid($gameid);
@@ -493,7 +515,7 @@ else if(myisset("me"))
        * set that one in the Game table
        * tell people about it.
        */
-      echo "<br /> Checking if someone else selected solo, nines or wedding or poverty.<br />";
+      echo "<br /> Checking if someone else selected solo, nines, wedding or poverty.<br />";
       
       /* check if everyone has reached this stage */
       $userids = DB_get_all_userid_by_gameid($gameid);
@@ -635,7 +657,7 @@ else if(myisset("me"))
          foreach($userids as $user)
            {
              /* userids are sorted by position... 
-              * so output whatever the firstone has, then whatever the next one has
+              * so output whatever the first one has, then whatever the next one has
               * stop when the sickness is the same as the gametype 
               */
              
@@ -1167,12 +1189,28 @@ else if(myisset("me"))
        }
       echo  "</div>\n";
 
+      /* get time from the last action of the game */
+      $result  = mysql_query("SELECT mod_date from Game WHERE id='$gameid' " );
+      $r       = mysql_fetch_array($result,MYSQL_NUM);
+      $gameend = time() - strtotime($r[0]);
+
+      /* handel comments in case player didn't play a card, allow comments a week after the end of the game */
+      if( (!myisset("card") && $mystatus=='play') || ($mystatus=='gameover' && ($gameend < 60*60*24*7)) )
+       if(myisset("comment"))
+         {
+           $comment = $_REQUEST["comment"];
+           $playid = DB_get_current_playid($gameid);
+           
+           if($comment != "")
+             DB_insert_comment($comment,$playid,$myid);
+         };  
+
       /* get everything relevant to display the tricks */
       $result = mysql_query("SELECT Hand_Card.card_id as card,".
                            "       Hand.position as position,".
                            "       Play.sequence as sequence, ".
                            "       Trick.id, ".
-                           "       Comment.comment, ".
+                           "       GROUP_CONCAT(CONCAT('<span>',User.fullname,': ',Comment.comment,'</span>') SEPARATOR '\n' ), ".
                            "       Play.create_date, ".
                            "       Hand.user_id ".
                            "FROM Trick ".
@@ -1180,8 +1218,10 @@ else if(myisset("me"))
                            "LEFT JOIN Hand_Card ON Play.hand_card_id=Hand_Card.id ".
                            "LEFT JOIN Hand ON Hand_Card.hand_id=Hand.id ".
                            "LEFT JOIN Comment ON Play.id=Comment.play_id ".
+                           "LEFT JOIN User On User.id=Comment.user_id ".
                            "WHERE Trick.game_id='".$gameid."' ".
-                           "ORDER BY Trick.id,sequence ASC");
+                           "GROUP BY Trick.id, sequence ".
+                           "ORDER BY Trick.id, sequence  ASC");
       $trickNR   = 1;
       $lasttrick = DB_get_max_trickid($gameid);
       
@@ -1278,7 +1318,7 @@ else if(myisset("me"))
        $myturn = 1;
       else
        $myturn = 0;
-      
+
       /* do we want to play a card? */
       if(myisset("card") && $myturn)
        {
@@ -1294,8 +1334,6 @@ else if(myisset("me"))
          
          if($handcardid) /* everything ok, play card  */
            {
-             $comment = "";
-
              /* update Game timestamp */
              DB_update_game_timestamp($gameid);
 
@@ -1315,26 +1353,26 @@ else if(myisset("me"))
              mysql_query("UPDATE Hand_Card SET played='true' WHERE hand_id='$handid' AND card_id=".
                          DB_quote_smart($card));
 
+             /* get trick id or start new trick */
+             $a = DB_get_current_trickid($gameid);
+             $trickid  = $a[0];
+             $sequence = $a[1];
+             $tricknr  = $a[2];
+             
+             $playid = DB_play_card($trickid,$handcardid,$sequence);
+
              /* check for schweinchen */
-             //echo "schweinchen = ".$GAME["schweinchen"]." --$card-<br />";
              if($card == 19 || $card == 20 )
                {
                  $GAME["schweinchen"]++;
                  if($GAME["schweinchen"]==3 && $RULES["schweinchen"]=="second" )
-                   $comment="Schweinchen! ";
+                   DB_insert_comment("Schweinchen! ",$playid,$myid);
                  if($RULES["schweinchen"]=="both" )
-                   $comment="Schweinchen! ";
-                 if ($debug) echo "schweinchen = ".$GAME["schweinchen"]." ---<br />";
+                   DB_insert_comment("Schweinchen! ",$playid,$myid);
+                 if ($debug) 
+                   echo "schweinchen = ".$GAME["schweinchen"]." ---<br />";
                }
 
-             /* get trick id or start new trick */
-             $a = DB_get_current_trickid($gameid);
-             $trickid  = $a[0];
-             $sequence = $a[1];
-             $tricknr  = $a[2];
-             
-             $playid = DB_play_card($trickid,$handcardid,$sequence);
-             
              /* if sequence == 4 check who one in case of wedding */
              if($sequence == 4 && $GT == "wedding") 
                {
@@ -1394,19 +1432,21 @@ else if(myisset("me"))
                }
              if($next==5) $next=1;
 
-             
              /* check for coment */
              if(myisset("comment"))
                {
-                 $comment.=$_REQUEST["comment"];
+                 $comment = $_REQUEST["comment"];
+                 if($comment != "")
+                   DB_insert_comment($comment,$playid,$myid);
                };  
-             if($comment != "")
-               DB_insert_comment($comment,$playid,$myid);
-
+             
              /* display played card */
              echo "<div class=\"card\">";
              echo " you played  <br />";
+             /* display comments */
              display_card($card,$PREF["cardset"]);
+             if($comment!="")
+               echo "       <br /> Your comment:<br /><span class=\"comment\">".$comment."</span>\n";
              echo "</div>\n";
              
              /*check if we still have cards left, else set status to gameover */
@@ -1466,7 +1506,7 @@ else if(myisset("me"))
                                " LEFT JOIN Hand_Card ON Hand_Card.id=Play.hand_card_id".
                                " LEFT JOIN Card ON Card.id=Hand_Card.card_id".
                                " WHERE Hand.game_id='$gameid'".
-                               " GROUP BY User.fullname" );
+                               " GROUP BY Hand.party" );
                  $message .= "\nTotals:\n";
                  while( $r = mysql_fetch_array($result,MYSQL_NUM))
                    $message .= "    ".$r[0]." ".$r[1]."\n";
@@ -1505,7 +1545,7 @@ else if(myisset("me"))
       $mycards = mysort($mycards,$gametype);
       echo "<div class=\"mycards\">\n";
       
-      if($myturn && !myisset("card"))
+      if($myturn && !myisset("card") && $mystatus=='play' )
        {
          echo "Hello ".$myname.", it's your turn!  <br />\n";
          echo "Your cards are: <br />\n";
@@ -1524,37 +1564,43 @@ else if(myisset("me"))
                display_link_card($card,$PREF["cardset"]);
            }
          
-         if( can_call(120,$me) )
-             echo " re/contra (120):".
-               " <input type=\"radio\" name=\"call120\" value=\"yes\" /> ";
-         if( can_call(90,$me) )
-             echo " 90:".
-               " <input type=\"radio\" name=\"call90\" value=\"yes\" /> ";
-         if( can_call(60,$me) )
-             echo " 60:".
-               " <input type=\"radio\" name=\"call60\" value=\"yes\" /> ";
-         if( can_call(30,$me) )
-             echo " 30:".
-               " <input type=\"radio\" name=\"call30\" value=\"yes\" /> ";
-         if( can_call(0,$me) )
-             echo " 0:".
-               " <input type=\"radio\" name=\"call0\" value=\"yes\" /> ".
-               " no call:".
-               " <input type=\"radio\" name=\"call0\" value=\"no\" /> ";
-
-         echo "<br />\nA short comments:<input name=\"comment\" type=\"text\" size=\"30\" maxlength=\"50\" />\n";
+         output_form_calls($me);
+         
+         echo "<br />\nA short comment:<input name=\"comment\" type=\"text\" size=\"30\" maxlength=\"100\" />\n";
          echo "<input type=\"hidden\" name=\"me\" value=\"$me\" />\n";
-         echo "<input type=\"submit\" value=\"move\" />\n";
+         echo "<input type=\"submit\" value=\"submit\" />\n";
          echo "</form>\n";
        }
-      else if($mystatus=='play')
-       {
+      else if($mystatus=='play' )
+       {         
          echo "Your cards are: <br />\n";
          foreach($mycards as $card) 
            display_card($card,$PREF["cardset"]);
+
+         echo "<form  action=\"index.php?me=$me\" method=\"post\">\n";
+         output_form_calls($me);
+         echo "<br />\nA short comment:<input name=\"comment\" type=\"text\" size=\"30\" maxlength=\"100\" />\n";
+         echo "<input type=\"hidden\" name=\"me\" value=\"$me\" />\n";
+         echo "<input type=\"submit\" value=\"submit\" />\n";
+         echo "</form>\n";
+
        }
       else if($mystatus=='gameover')
        {
+         /* get time from the last action of the game */
+         $result  = mysql_query("SELECT mod_date from Game WHERE id='$gameid' " );
+         $r       = mysql_fetch_array($result,MYSQL_NUM);
+         $gameend = time() - strtotime($r[0]);
+         
+         if( $gameend < 60*60*24*7 )
+           {
+             echo "<form  action=\"index.php?me=$me\" method=\"post\">\n";
+             echo "<br />\nA short comment:<input name=\"comment\" type=\"text\" size=\"30\" maxlength=\"100\" />\n";
+             echo "<input type=\"hidden\" name=\"me\" value=\"$me\" />\n";
+             echo "<input type=\"submit\" value=\"submit\" />\n";
+             echo "</form>\n";
+           }
+
          $oldcards = DB_get_all_hand($me);
          $oldcards = mysort($oldcards,$gametype);
          echo "Your cards were: <br />\n";
@@ -1577,13 +1623,14 @@ else if(myisset("me"))
                   foreach($oldcards as $card)
                     display_card($card,$PREF["cardset"]);
                 }
-            }
+            };
        }
       echo "</div>\n";
       
       /* if the game is over do some extra stuff, therefore exit the swtich statement if we are still playing*/
       if($mystatus=='play')
        break;
+
       /* the following happens only when the gamestatus is 'gameover' */
       /* check if game is over, display results */
       if(DB_get_game_status_by_gameid($gameid)=='play')
@@ -1653,13 +1700,21 @@ else if(myisset("me"))
     exit();
  } 
 /* user status page */ 
- else if(myisset("email","password"))
+else if( myisset("email","password") || isset($_SESSION["name"]) )
    {
      /* test id and password, should really be done in one step */
-     $email     = $_REQUEST["email"];
-     $password  = $_REQUEST["password"];
+     if(!isset($_SESSION["name"]))
+       {
+        $email     = $_REQUEST["email"];
+        $password  = $_REQUEST["password"];
+       }
+     else
+       {
+        $name = $_SESSION["name"];
+        $email     = DB_get_email_by_name($name);
+        $password  = DB_get_passwd_by_name($name);
+       };
      
-
      if(myisset("forgot"))
        {
         $ok = 1;
@@ -1762,7 +1817,8 @@ else if(myisset("me"))
                   $ok = 1;
 
                   /* check if old password matches */
-                  if($password != md5($_REQUEST["password0"]))
+                  $oldpasswd = md5($_REQUEST["password0"]);
+                  if(!( ($password == $oldpasswd) || DB_check_recovery_passwords($oldpasswd,$email) ))
                     $ok = -1;
                   /* check if new passwords are types the same twice */
                   if($_REQUEST["password1"] != $_REQUEST["password2"] )
@@ -1787,12 +1843,18 @@ else if(myisset("me"))
             }
           else /* output default user page */
             {
-              $time = DB_get_user_timestamp($uid);
-              $unixtime =strtotime($time);
+              $time     = DB_get_user_timestamp($uid);
+              $unixtime = strtotime($time);
               
-              $offset = DB_get_user_timezone($uid);
-              $zone = return_timezone($offset);
+              $offset   = DB_get_user_timezone($uid);
+              $zone     = return_timezone($offset);
               date_default_timezone_set($zone);
+
+              $myname = DB_get_name_by_email($email);
+              $_SESSION["name"] = $myname;
+
+              if(isset($_SESSION["name"]))
+                output_status($_SESSION["name"]);
               
               /* display links to settings */
               output_user_settings($email,$password);
@@ -1867,7 +1929,7 @@ else if(myisset("me"))
         }
        else
         {
-          echo "Sorry email and password don't match <br />";
+          echo "Sorry email and password don't match. Please <a href=\"$host\">try again</a>. <br />";
         }
      };
      output_footer();
@@ -1903,7 +1965,7 @@ else if(myisset("me"))
         if($r)
           echo " added you to the database";
         else
-          echo " something went wrong";
+          echo " something went wrong, couldn't add you to the database, please contact $ADMIN_NAME at $ADMIN_EMAIL.";
        }
    }
 /* default login page */