This commit is contained in:
2023-08-07 10:09:29 +02:00
parent f6ee043099
commit b7cf477965

View File

@@ -4,12 +4,13 @@ $mysqllogin = json_decode(file_get_contents("secrets/MysqlLogin.json"), false);
$mysqli = new mysqli('localhost', $mysqllogin->DBUser, $mysqllogin->DBPassword, $mysqllogin->DBName); $mysqli = new mysqli('localhost', $mysqllogin->DBUser, $mysqllogin->DBPassword, $mysqllogin->DBName);
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
$action = $_POST["action"]; $action = $_POST["action"];
if($action == "login"){ if($action == "login"){
$uname = $_POST["username"]; $uname = $_POST["username"];
$pwd = $_POST["password"]; $pwd = $_POST["password"];
$stmt1 = $mysqli->prepare("SELECT `Password, ID, FullName, Nickname, CanSeeFullNames, CanSeeOthersComments, IsAdmin FROM Users WHERE Username = %s;"); $stmt1 = $mysqli->prepare("SELECT Password, ID, FullName, Nickname, CanSeeFullNames, CanSeeOthersComments, IsAdmin FROM Users WHERE Username = %s;");
$stmt1->bind_param('s', $uname); $stmt1->bind_param('s', $uname);
$stmt1->bind_result($pwdhash, $uid, $fullname, $nick, $fullnamepriv, $otherscommentspriv, $adminpriv); $stmt1->bind_result($pwdhash, $uid, $fullname, $nick, $fullnamepriv, $otherscommentspriv, $adminpriv);
$stmt1->execute(); $stmt1->execute();
@@ -260,6 +261,6 @@ else{
echo "Not logged in"; echo "Not logged in";
return; return;
} }
}
?> ?>