X-Git-Url: https://git.nubati.net/cgi-bin/gitweb.cgi?p=e-DoKo.git;a=blobdiff_plain;f=include%2Ffunctions.php;h=cb784575d783fc344077c3db9d8d78cbe1964433;hp=8bcdede83f587cbfd42abe44f299364741a6680b;hb=14f6017a5b84d70320bde9d6e074ea8ac948a85e;hpb=29c87287965ad3b88ffd49419d7a7423feda00fa diff --git a/include/functions.php b/include/functions.php index 8bcdede..cb78457 100644 --- a/include/functions.php +++ b/include/functions.php @@ -30,36 +30,36 @@ function config_check() /* check if some variables are set in the config file, else set defaults */ if(!isset($EmailName)) - $EmailName="[DoKo] "; + $EmailName='[DoKo] '; if(isset($EMAIL_REPLY)) { - ini_set("sendmail_from",$EMAIL_REPLY); + ini_set('sendmail_from',$EMAIL_REPLY); } if(!isset($ADMIN_NAME)) { output_header(); - echo "

Setup not completed

"; - echo "You need to set \$ADMIN_NAME in config.php."; + echo '

Setup not completed

'; + echo 'You need to set $ADMIN_NAME in config.php.'; output_footer(); exit(); } if(!isset($ADMIN_EMAIL)) { output_header(); - echo "

Setup not completed

"; - echo "You need to set \$ADMIN_EMAIL in config.php. ". - "If something goes wrong an email will be send to this address."; + echo '

Setup not completed

'; + echo 'You need to set $ADMIN_EMAIL in config.php. '. + 'If something goes wrong an email will be send to this address.'; output_footer(); exit(); } if(!isset($DB_work)) { output_header(); - echo "

Setup not completed

"; - echo "You need to set \$DB_work in config.php. ". - "If this is set to anything else than 0, the game will be suspended and one can work safely on the database. ". - "A message will be displayed that it will probably take about N minutes, with N being the number \$DB_work is set to. ". - "The default should be 0 for the game to work."; + echo '

Setup not completed

'; + echo 'You need to set $DB_work in config.php. '. + 'If this is set to anything else than 0, the game will be suspended and one can work safely on the database. '. + 'A message will be displayed that it will probably take about N minutes, with N being the number $DB_work is set to. '. + 'The default should be 0 for the game to work.'; output_footer(); exit(); } @@ -1650,4 +1650,53 @@ function get_user_token($userid) return $token; } +function verify_password($email, $password) +{ + /* verify password, if old password has length 32 assume it's an old md5, else use new password scheme */ + /* return 0 if verified, else return error code + * 1 can't find email + * 2 can't calculate correct hash + * 3 misc error + */ + + /* check user email by getting his id */ + $userid = DB_get_userid('email',$email); + if(!$userid) + return 1; + + /* test for temporary passwords, only valid for one date (tested in the DB) */ + $tmppasswd = md5($password); + if(DB_check_recovery_passwords($tmppasswd,$email)) + return 0; + + /* get saved password */ + $existingpassword = DB_get_passwd_by_userid($userid); + + if(strlen($existingpassword)==32) /* old password type */ + { + if ($existingpassword == md5($password)) + { + /* update password to new crypt version */ + // create a password hash using the crypt function, need php 5.3 for this + // create and random salt + $salt = substr(str_replace('+', '.', base64_encode(sha1(microtime(true), true))), 0, 22); + // hash incoming password using 12 rounds of blowfish + $hash = crypt($password, '$2y$12$' . $salt); + if(strlen($hash)>13) + DB_query("UPDATE User SET password='$hash' where id='$userid'"); + else + return 2; + + return 0; + } + } + else + { + if ($existingpassword == crypt($password, $existingpassword)) + return 0; + }; + + return 3; +} + ?>