· 10 years ago · Apr 03, 2016, 08:03 PM
1<?php
2
3
4
5include "_inc.php";
6
7$thispage="register"; // important to uniquely identify this page
8$thispagename = "$lang_register";
9$showadwarning=0;
10
11include "_top.php";
12include "_nav.php";
13echo wput("<!-- <priority> 0.3 </priority> -->");
14// for this page only
15include "_bad_captcha.php";
16
17
18if ($loginuser>0) {
19
20 echo "$lang_nocreatewhileloggedin.\n";
21}
22
23$fldmod = " size=35 "; // modify the form field input tags
24if ($browserismobile) $fldmod=" size=25 "; // narrower browser screen on a phone
25$flmod2 = " size=17 "; // for the captcha
26
27$processmore=1; // assume doing the full registration form or processing unless we see activation code
28
29// activate and secretcode are get variables
30// that indicate that we are trying to activate
31// an existing account
32@$gu = "".$_GET["activate"];
33@$gs = "".$_GET["secretcode"];
34
35// shortening the get variables to act and sc but
36// maintaining support for the old ones
37@$gu2 = "".$_GET["act"];
38@$gs2 = "".$_GET["sc"];
39// in the event both are present (This Should Not Happen)
40// then the new ones will be examined.
41if (!empty($gu2)) {
42 $gu=$gu2; $gs=$gs2;
43}
44// end changes to shortening get variables
45
46
47if (!empty($gu)) {
48 $processmore=0; // all we are doing is activation bc of presence of activate and secretcode in get variables
49 // so don't process more
50 $conn = new mysqli($dbhost, $dbuser, $dbpass, $dbdatabase);
51 $sql = "SELECT * ";
52 $sql = $sql."FROM user WHERE username='".forsql($gu)."' AND secretcode='".forsql($gs)."';";
53 $result = $conn->query($sql);
54 $row = $result->fetch_assoc();
55 if ($result->num_rows > 0) {
56 if ($row['disabled']!="0") {
57 // then account is disabled.
58 echo "Sorry, the operation failed.\n";
59 } else {
60 // then this is a successfull activation
61 echo activated_text($row['firstname']); // takes language into account
62 $sql = "UPDATE user SET active='1' WHERE username='".forsql($gu)."';";
63 $result = $conn->query($sql);
64 $sql = "UPDATE user SET updated='".datestamper()."' WHERE username='".forsql($gu)."';";
65 $result = $conn->query($sql);
66
67 }
68 } else {
69 echo "$lang_activationfailed.\n";
70 }
71}
72
73if ((!$loginuser>0) && ($processmore==1)) {
74 // prepare variables
75 $fuser=""; $ffirst="";$flast=""; $femail="";$fpw="";$fpw2="";
76 $uerr=""; $uerr2=""; $uerr3=""; $fnerr=""; $lnerr = ""; $emerr = ""; $pwerr="";
77 $pwmerr=""; $pwlenerr="";$pwsimpleerror="";$ueerr="";$emexerr=""; $ageerror = ""; $dateerror = "";
78 $fdayofbirth = ""; $fmonthofbirth = ""; $fyearofbirth=""; $fage=""; $fdate="";
79 $fsecurity=""; $fhash=""; $captchaerror=""; $captchauseagain=""; $cpass=""; $fterms=""; $terr="";
80
81 // handle our cases.
82 $skip=1; // means an error occurred or no data, show the form instead of create account
83
84 @$makingnew = $_POST["action"];
85 // echo "Evaluating: ".$makingnew."<br>\n";
86 if ($makingnew=="yes") {
87 // first case, input detected, possibly create account
88 $fuser=inputclean($_POST["username"]); $ffirst=inputclean(str_replace("'","’",$_POST["first"]));
89 $flast=inputclean(str_replace("'","’",$_POST["last"])); $femail=strtolower(inputclean($_POST["email"]));
90 $fpw=$_POST["pw1"]; $fpw2=$_POST["pw2"]; // i don't think we need to clean the passwords, rather preserve them
91 $fdayofbirth=$_POST["birthday"]; $fmonthofbirth=$_POST["birthmonth"]; $fyearofbirth=$_POST["birthyear"];
92 $fage = floor((time() - strtotime($fyearofbirth."-".$fmonthofbirth."-".$fdayofbirth)) / 31556926);
93 $fdate=right("0000".$fyearofbirth,4).right("00".$fmonthofbirth,2).right("00".$fdayofbirth,2);
94 $fsecurity=$_POST["security"]; $fhash=$_POST["hash"];
95 @$fterms=$_POST['terms'];
96
97 // echo "Birthdate string: ".$fdate."<br>\n";
98
99 $skip=0; // so far no reason to skip adding this user; no errors found.
100
101 if (!$fterms=="yes") {
102 $skip=1;
103 $terr = "<font color=red>$lang_termserr</font><br>";
104 }
105 if (empty($fuser)) {
106 $skip=1;
107 $uerr = "<br><font color=red>$lang_uerr</font>";
108 }
109 if (strlen($fuser) >$max_user_len) {
110 $skip=1;
111 $uerr3 = "<br><font color=red>$lang_uerr3</font>";
112 }
113
114 if ( usernamecheck($fuser) ) { } else {
115 $skip=1;
116 $uerr2 = "<br><font color=red>$lang_uerr2</font>";
117 }
118
119
120 if (empty($ffirst)) {
121 $skip=1;
122 $fnerr = "<br><font color=red>$lang_fnerr</font>";
123 }
124 if (empty($flast)) {
125 $skip=1;
126 $lnerr = "<br><font color=red>$lang_lnerr</font>";
127 }
128 if (!filter_var($femail, FILTER_VALIDATE_EMAIL)) {
129 $skip=1;
130 $emerr = "<br><font color=red>$lang_email_error</font>";
131 }
132 if ($fpw.$fpw2=="") {
133 $skip=1;
134 $pwerr = "<br><font color=red>$lang_no_pw_error</font>";
135 }
136 if ($fpw==$fpw2) { } else {
137 $skip=1;
138 $pwmerr = "<br><font color=red>$lang_pwmatch_error</font>";
139 }
140 if ((strlen($fpw)<$min_pw_chars)) {
141 $skip=1;
142 $pwlenerr = "<br><font color=red>$lang_pw_short_error</font>";
143 }
144
145 $chars = str_split($fpw); $chars = array_unique($chars); $num_unique_chars = count($chars);
146 if ( (strlen($fpw) > 0 ) && ($num_unique_chars<2) ) {
147 $skip=1;
148 $pwsimpleerror = "<br><font color=red>$lang_pw_simple_error</font>";
149 }
150
151
152
153 if ($fage<18) {
154 $skip=1;
155 $ageerror = "<br><font color=red>$lang_ageerror</font>";
156 }
157
158 if ( ( ($fdayofbirth<1) || ($fdayofbirth>31) ) ||
159 ( ($fmonthofbirth<1) || ($fmonthofbirth>12) ) ||
160 ( ($fyearofbirth<1890) || ($fyearofbirth>date("Y")) ) ) {
161 $dateerror = "<br><font color=red>$lang_dateerror</font>";
162 }
163
164
165 if (bad_captcha_compare($fsecurity, $fhash)) {
166 $cpass=1;
167 $captchauseagain=$fhash;
168 } else {
169 $cpass=0;
170 $captchauseagain="";
171 }
172
173 // check the captcha
174 //$cpass=0; // assume fail
175 //for ($c=1;$c<=$numcaptcha;$c++) {
176 //echo "[checking captcha ".$captcha[$c]." against fhash $fhash] ";
177 // if ($captcha[$c]==$fhash) {
178 //echo "[Found it] [Checking ".strtoupper($captchax[$c])." against the entered ".strtoupper($fsecurity)."] ";
179 // if (strtoupper($captchax[$c])==strtoupper($fsecurity)) {
180 //echo "[They MATCH.] ";
181 // $captchauseagain=$c;
182 // $cpass=1;
183 // }
184 // }
185 // }
186
187 if ($cpass==0) {
188 $skip=1;
189 $captchaerror = "<br><font color=red>$lang_captchaerror</font>";
190 }
191
192 // echo "<br>Skip is $skip<br>\n";
193 // user/email already exists?
194 if ($skip==0) {
195 $conn = new mysqli($dbhost, $dbuser, $dbpass, $dbdatabase);
196 $sql = "SELECT * ";
197 $sql = $sql."FROM user WHERE username='".forsql($fuser)."';";
198 $result = $conn->query($sql);
199
200 if ($result->num_rows > 0) {
201 // username already exists
202 $skip=1;
203 $ueerr = "<br><font color=red>$lang_userexists_error</font>";
204 }
205 $sql = "SELECT * ";
206 $sql = $sql."FROM user WHERE LOWER(email)='".strtolower(forsql($femail))."';";
207 $result = $conn->query($sql);
208
209 if ($result->num_rows > 0) {
210
211 $skip=1;
212 $emexerr = "<br><font color=red>$lang_email_exists_error</font>";
213 }
214 }
215 //
216 // echo "Button detected.\n";
217 //
218
219
220 }
221
222 // if we're here and skip=0 then we can create the user and send the email.
223 // otherwise, show the form.
224
225
226 if ($skip==1) {
227 // no input/invalid input, show form
228 echo "<center><br><table border=1 cellpadding=5><tr><td bgcolor=$colorlogin>\n";
229 echo "<a name=top>$lang_create_account</a><br><br>\n";
230 echo "<font size=-1><i>$lang_all_fields_required</i></font><br>";
231 echo "<form class=formregular method=post action=\"".$scriptself."\" onsubmit=\"submitting.disabled = true; return true;\">\n";
232 if ($botdetected) {
233 // deliberately invalid username input box - calls itself "user" instead of "username"
234 // this is so detected bots will (ideally) fail to register. only "username" is detected.
235 // of course has no effect on bots faking user agent
236 echo "$lang_username:$uerr $uerr2 $ueerr $uerr3<br><input class=formregular value=\"$fuser\" type=text $fldmod name=user><br><br>";
237 } else {
238 echo "$lang_username:$uerr $uerr2 $ueerr $uerr3<br><input class=formregular value=\"$fuser\" type=text $fldmod name=username><br><br>";
239 }
240 echo "$lang_first_name:$fnerr<br><input class=formregular value=\"$ffirst\" type=text $fldmod name=first><br><br>";
241 echo "$lang_last_name:$lnerr<br><input class=formregular value=\"$flast\" type=text $fldmod name=last><br><br>";
242
243 if ($lang=="es") {
244 echo "$lang_enterdob:$ageerror $dateerror<br>";
245 echo "<span title=\"$lang_dayhelp\">";
246 echo "<input class=formregular value=\"$fdayofbirth\" name=birthday type=text size=2 placeholder=\"".$lang_dayabbrev."\"> - ";
247 echo "</span><span title=\"$lang_monthhelp\">";
248 echo "<select class=formregular name=birthmonth><option value=0>$lang_selectmonth</option>";
249 for ($m = 1 ; $m < 13 ; $m++) {
250 echo "<option ";
251 if ($m==$fmonthofbirth) {
252 echo " selected ";
253 }
254 echo " value=".$m.">".monthname($m)."</option>";
255 }
256 echo "</select>";
257 echo "</span><span title=\"$lang_yearhelp\">";
258 echo " - <input class=formregular value=\"$fyearofbirth\" type=text name=birthyear size=4 Placeholder=\"".$lang_yearabbrev."\"><br>\n";
259 echo "</span>";
260 if ($fage>0) {
261 echo $fage." years old<br>";
262 }
263 echo "<center><font size=-2><i>$lang_ageerror</i></font><br></center>";
264 }
265
266 if ($lang=="en") { // enter date of birth for ENGLISH (day-month-year)
267 echo "$lang_enterdob_western:$ageerror $dateerror<br>";
268 echo "<span title=\"$lang_monthhelp\">";
269 echo "<select class=formregular name=birthmonth><option value=0>$lang_selectmonth</option>";
270 for ($m = 1 ; $m < 13 ; $m++) {
271 echo "<option ";
272 if ($m==$fmonthofbirth) {
273 echo " selected ";
274 }
275 echo " value=".$m.">".monthname($m)."</option>";
276 }
277 echo "</select>";
278 echo "</span><span title=\"$lang_dayhelp\">";
279 echo " <input class=formregular value=\"$fdayofbirth\" name=birthday type=text size=2 placeholder=\"".$lang_dayabbrev."\">";
280 echo "</span><span title=\"$lang_yearhelp\">";
281 echo " <b>,</b> <input class=formregular value=\"$fyearofbirth\" type=text name=birthyear size=4 Placeholder=\"".$lang_yearabbrev."\"><br>\n";
282 echo "</span>";
283 if ($fage>0) {
284 echo $fage." years old<br>";
285 }
286 echo "<center><font size=-2><i>$lang_ageerror</i></font><br></center>";
287 } // END enter date of birth for ENGLISH (day-month-year)
288
289
290
291 echo "<br>e-mail:$emerr $emexerr<br><input class=formregular type=text value=\"$femail\" $fldmod name=email><br><br>";
292 echo "$lang_password:$pwerr $pwmerr $pwlenerr $pwsimpleerror<br><input class=formregular value=\"$fpw\" $fldmod type=password name=pw1><br><br>";
293 echo "$lang_password ($lang_again):<br><input class=formregular value=\"$fpw2\" $fldmod type=password name=pw2><br><br>";
294
295 // captcha getter
296 $thiscap=rand(1,$bad_captcha_count);
297
298 if ($cpass=="1") {
299 $ourcaptcha=$captchauseagain;
300 } else {
301 $fsecurity="";
302 $ourcaptcha=$bad_captcha[$thiscap];
303 }
304
305 echo "<table width=100% border=0><tr><td>";
306 echo "$lang_seccode: $captchaerror<br><input class=formregular type=text $flmod2 name=security validation=\"Crypt 1.0;\" value=\"$fsecurity\"></td>";
307 echo "<td><img border=1 alt=\"$lang_seccode\" src=".$imagepath."security/".$ourcaptcha.".png width=200></td>";
308 echo "</tr></table><br>\n";
309 echo "<input class=formregular type=hidden name=hash value=".$ourcaptcha.">";
310 echo "$terr<input type=checkbox value=yes name=terms> $lang_termsokay<br><br>";
311 echo "<input class=formregular type=hidden name=action value=yes>";
312 echo "<input class=formregular type=submit name=submitting value=\"$lang_create_account\"></form>\n";
313 echo "</td></tr></table></center>\n";
314 echo "<br><center>$lang_email_nevershare</center>";
315 echo "<br><center>$lang_nosignup</center>\n";
316 echo "<br><hr><br>\n";
317 echo "<font size=-1>";
318
319 // setting agreementlinks=rel tells _termsinc.php / _privacyinc.php
320 // to link to other parts of the page (#top #terms #privacy) rather
321 // than linking to terms.php, privacy.php, etc., because we're
322 // putting the sign-up form, terms, and privacy all on one page
323 // and this allows navigation within that page without losing content
324 // of the sign-up form.
325 $agreementlinks="rel";
326 $backto = $lang_signupform; // what we are coming back to
327
328 echo "<a name=terms></a>";
329 include "_termsinc.php";
330 echo "<br><hr><br>\n";
331 echo "<a name=privacy></a>";
332 include "_privacyinc.php";
333 } else {
334 // create account
335
336 // make activation code
337 $scode = rand();
338
339 // get our next user code based on whether we are on dvl or production
340 if ($detectedserver=="lwb") {
341 $sql = "select code from user order by (code + 0) desc limit 1;";
342 $result = $conn->query($sql);
343 $row = $result->fetch_assoc();
344 $ourcode = $row["code"]+1;
345 if ($ourcode < 1000000) {
346 $ourcode=1000000;
347 }
348 } else {
349 $sql = "select code from user where (code + 0) < 1000000 order by (code + 0) desc limit 1;";
350 $result = $conn->query($sql);
351 $row = $result->fetch_assoc();
352 $ourcode = $row["code"]+1;
353 } // $ourcode now contains a unique code number for this record
354 // *todo* fix huge race condition here
355
356 $userip=get_user_ip();
357 $useragent=tickclean($_SERVER['HTTP_USER_AGENT']);
358 // actual user agent parsing, look here -> http://davidwalsh.name/user-agent-parser
359
360 $sql = "INSERT INTO user (password,username,firstname,lastname,level,";
361 $sql .= "email,active,secretcode,preferred_language,code,created,updated,";
362 $sql .= "dob,signup_ip,signup_browser) VALUES";
363 $sql .= " ('".password_hash($fpw, PASSWORD_DEFAULT)."','";
364 $sql .= forsql($fuser)."','".forsql($ffirst)."'";
365 $sql .= ",'".forsql($flast)."','0','".strtolower(forsql($femail))."','0','".$scode."','";
366 $sql .= $lang."','".$ourcode."','".datestamper()."','".datestamper()."'";
367 $sql .= ",'".$fdate."','".$userip."','".$useragent."');";
368 $result = $conn->query($sql);
369 // echo "User add results: ".$sql."<br><br>pw1: ".$fpw."<br><br>pw2: ".$fpw2;
370 //
371 //
372 // compose e-mail
373
374 $eml=welcomeemail($lang);
375 $emlhtml=welcomeemail($lang,"html");
376
377 echo "<br><br>".thanks_link($femail,$lang)." \n";
378
379
380 // $result = mail($femail,"Welcome - $pn",$eml);
381 // echo "<br><br><br>Reminder: Email turned off.";
382
383 $mail = new PHPMailer;
384
385 // all these $smtpetc variables are set in _siteinc.php based on which host we are running on
386
387 $mail->isSMTP(); // Set mailer to use SMTP
388 $mail->SMTPOptions = array (
389 'ssl' => array(
390 'verify_peer' => false,
391 'verify_peer_name' => false,
392 'allow_self_signed' => true)); // for some reason this is necessary on wisdom but not on the thinkpad.
393 $mail->Host = $smtphost; // Specify main and backup SMTP servers
394 $mail->SMTPAuth = true; // Enable SMTP authentication
395 $mail->Username = $smtpuser; // SMTP username
396 $mail->Password = $smtppassword; // SMTP password
397 $mail->CharSet = 'UTF-8'; // required for accented characters
398
399 if ( ($smtpsecure!="no") && ($smtpsecure!="") ) {
400 $mail->SMTPSecure = $smtpsecure; // Enable encryption, 'tls', 'ssl' accepted
401 }
402
403 if ($smtpaltport=="yes") {
404 $mail->Port = $smtpport;
405 }
406
407 // $mail->From = 'no-reply@thelotterystation.com';
408 $mail->From = $smtpuser;
409 $mail->FromName = $pn;
410 // $mail->SMTPDebug = "4";
411 // $mail->addAddress($femail, $ffirst." ".$flast); // Add a recipient
412 $mail->addAddress($femail); // Add a recipient
413 // $mail->addAddress('ellen@example.com'); // Name is optional
414 $mail->addReplyTo('no-reply@thelotterystation.com', 'No Reply');
415 // $mail->addCC('cc@example.com');
416 // $mail->addBCC('bcc@example.com');
417
418 // $mail->WordWrap = 79; // Set word wrap to 50 -er, 79- characters
419 // wonder how well it works without this? 5 oct 2015
420
421 // $mail->addAttachment('/var/tmp/file.tar.gz'); // Add attachments
422 // $mail->addAttachment('/tmp/image.jpg', 'new.jpg'); // Optional name
423
424 $mail->Subject = "$lang_welcome - $pn ($flast, $ffirst/$fuser)";
425
426 $mail->isHTML(true); // Set email format to HTML
427 // $mail->Body = 'This is the HTML message body <b>in bold!</b>';
428 $mail->Body = $emlhtml;
429 $mail->AltBody = $eml;
430 // $mail->AltBody = 'This is the body in plain text for non-HTML mail clients';
431 // $mail->Body = $eml;
432
433 if(!$mail->send()) {
434 echo '[Error: Message could not be sent. ';
435 echo 'Mailer Error: ' . $mail->ErrorInfo;
436 echo ' - please <a href=contact.php>contact us</a> about this error.]';
437 } else {
438 echo '[Message has been sent.]';
439 }
440
441 } // end if skip==1
442} // end if loginuser>0 || processmore==1
443include "_bot.php";
444?>