-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathsignup_back.php
64 lines (63 loc) · 2.67 KB
/
signup_back.php
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
<?php
include('db_conn.php');
error_reporting(0);
$error = 0;
if (isset($_POST['signupButton'])) {
$captcha = $_POST['g-recaptcha-response'];
if (!$captcha) {
$error = 1;
} else {
$db = new mysqli(DB_HOST, DB_USER, DB_PASS, DB_NAME);
if ($db->connect_errno > 0) {
die('Unable to connect to database [' . $db->connect_error . ']');
}
$username = $_POST['inputUsername'];
$email = $_POST['inputEmail'];
$password = md5($_POST['inputPassword']);
$first_name = $_POST['firstName'];
$last_name = $_POST['lastName'];
$date = $_POST['Year'] . "-" . $_POST['Month'] . "-" . $_POST['Date'];
$image = $_POST['image'];
$exists = 0;
$error = '';
$username = stripslashes($username);
$password = stripslashes($password);
$first_name = stripslashes( $first_name);
$last_name = stripslashes( $last_name);
$email = stripslashes( $email);
$email = $db->real_escape_string( $email);
$username = $db->real_escape_string($username);
$password = $db->real_escape_string($password);
$first_name = $db->real_escape_string( $first_name);
$last_name = $db->real_escape_string( $last_name);
$image = base64_encode(file_get_contents(addslashes($_FILES[ 'inputImage']['tmp_name'])));
$fields = array('inputUsername', 'inputEmail', 'firstName', 'lastName');
if (!filter_var($email, FILTER_VALIDATE_EMAIL)) {
$exists = 4;
}
foreach ($fields as $fieldname) { //Loop trough each field
if (!isset($_POST[$fieldname]) || empty($_POST[$fieldname])) {
$exists = 1;
}
}
$result = $db->query("SELECT username from user WHERE username = '{$username}' LIMIT 1");
if ($result->num_rows == 1) $exists = 3;
$result = $db->query("SELECT email from user WHERE email = '{$email}' LIMIT 1");
if ($result->num_rows == 1) $exists = 5;
if(!getimagesize($_FILES[ 'inputImage']['tmp_name'])){
$exists = 6;
}
if($exists == 0) {
$sql = "INSERT INTO `user` (`id`, `username`, `email`, `password`, `fname`, `lname`, `date_of_birth`, `picture`, `type`)
VALUES (NULL, '{$username}', '{$email}', '{$password}', '{$first_name}', '{$last_name}', '{$date}','{$image}' , 2)";
if ($db->query($sql)) {
header("location: signin.php");
} else {
echo "<p>MySQL error no {$db->errno} : {$db->error}</p>";
exit();
}
}
$db->close();
}
}
?>