· 9 years ago · Oct 11, 2016, 07:46 PM
1<?php
2require('../../../includes/config.php');
3require('../../../structure/database.php');
4require('../../../structure/base.php');
5require('../../../structure/user.php');
6
7$database = new database($db_host, $db_name, $db_user, $db_password);
8$base = new base($database);
9$user = new user($database);
10
11//set some basic vars
12$username = $user->getUsername($_COOKIE['user'], 2);
13$rank = $user->getRank($username);
14?>
15<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
16<html xmlns:IE>
17
18<head>
19 <meta http-equiv="Expires" content="0">
20 <meta http-equiv="Pragma" content="no-cache">
21 <meta http-equiv="Cache-Control" content="no-cache">
22 <meta name="MSSmartTagsPreventParsing" content="TRUE">
23 <meta http-equiv="Content-Type" content="text/html; charset=EUC-JP">
24 <title><?php echo $data['wb_title']; ?></title>
25 <link href="../../../css/basic-3.css" rel="stylesheet" type="text/css" media="all">
26 <link href="../../../css/main/title-5.css" rel="stylesheet" type="text/css" media="all">
27 <script src="http://code.jquery.com/jquery-latest.min.js"></script>
28 <link rel="shortcut icon" href="../../../img/favicon.ico"/>
29 <?php include('../../../includes/google_analytics.html'); ?>
30 <style>
31 fieldset {
32 text-align: left;
33 border: 2px solid #625437;
34 width: 95%;
35 position: relative;
36 margin: 10px;
37 padding-left: 10px;
38 background-color: transparent;
39 }
40
41 legend {
42 color: #625437;
43 font-weight: bold;
44 font-size: 15px;
45 }
46
47 label {
48 display: block;
49 height: 20px;
50 text-align: center;
51 }
52
53 textarea {
54 display: block;
55 width: 200px;
56 height: 100px;
57 }
58
59 </style>
60 <script type="text/javascript">
61 function goBack() {
62 window.history.back();
63 }
64 </script>
65</head>
66
67<div id="body">
68 <?php //$base->getNavBar($username, $path, $rank); ?>
69
70 <div style="text-align: center; background: none;">
71 <div class="titleframe e">
72 <b>Password Support</b><br/>
73 <a href="../../../index">ScapeRune Home</a>
74 </div>
75 </div>
76</div>
77
78<div class="frame e" style="overflow:auto;">
79 <?php
80 //make sure user doesn't already have a recovery request submitted
81 $database->processQuery("SELECT * FROM `tracking` WHERE " . time() . " - `time` < 7200 AND `ip` = ? LIMIT 1", array($_SERVER['REMOTE_ADDR']), false);
82
83 if ($database->getRowCount() >= 1) {
84 echo '<center>Oops! You have already submitted a recovery request.<br /><br /> <a href="../../../index"Main Menu</a></center>';
85
86 } elseif (!isset($_POST['username'])) {
87 ?>
88 <!-- <form action="recover_password" method="POST">
89 <input type="text" name="username" maxlength="12"><input type="submit" value="Continue">
90 </form> -->
91 <?php
92 } elseif (!$user->doesExist($_POST['username'])) {
93 echo 'No user exists with that username!<br /> <input type="button" value="Back" onclick="goBack()" />';
94 } else {
95
96 $questions[] = array();
97 $questions[0] = 'Where was your first vacation?:';
98 $questions[1] = 'Who was your first best friend?:';
99 $questions[2] = 'What was your first pets name?:';
100 $questions[3] = 'Who was your first boyfriend/girlfriend?:';
101 $questions[4] = 'What color was your first bedroom?:';
102 $questions[5] = 'Who is your favorite musical artist?';
103
104 //extract data
105 $data = $database->processQuery("SELECT * FROM `recoveries` WHERE `id` = ? LIMIT 1", array($user->getIdByName($_POST['username'])), false);
106
107 if ($database->getRowCount() == 0 || $user->getUsername($_COOKIE['user'], 2) == $_POST['username']) {
108 echo 'Temporarily disabled! <input type="button" value="Back" onclick="goBack()" />';
109 } elseif (!isset($_POST['answer'])) {
110 ?>
111 <fieldset class="question">
112 <legend>Important Information</legend>
113 This form will allow you to request that a new password is set for your account.<br/><br/>
114 <img style="float: left" src="/img/title2/lock.gif">
115 <span style="font-weight: bold; color: rgb(255, 187, 34);">Want to be back in game sooner? If you want to get back in game quickly, here are a few tips:</span><br/><br/>
116
117 Please answer all the questions below to confirm that you are the real owner of the account.<br/><br/>
118 Enter the earliest and most specific information about the account that you can.<br/><br/>
119 Take the time to remember as much detail as possible. The more detail you give us, <b>the quicker you
120 can be
121 back in game</b>
122 <br/><br/>
123 If you really don't know the answer to a question, leave the answer box blank.<br/><br/>
124 <b>Remember:</b> The more questions you answer correctly, the sooner you can be back in game!
125 </fieldset>
126 <br/>
127
128 <fieldset class="question">
129 <legend>Answer Recovery Questions</legend>
130 <p style="text-align: center">If you have set these, you must try to answer at least three. Recovery
131 answers
132 have a minimum length of 3 characters.
133 Recovery answers can only contain the characters A-Z, 0-9 and accented characters such as é or
134 ü.
135 Other characters will not count towards the length.</p>
136
137 <label><b>I have not set any recovery questions</b>
138 <input type="checkbox" class="input_control" value="subject"/></label>
139
140 <form action="recover_password" method="POST">
141 <input type="hidden" name="username" value="<?php echo $_POST['username']; ?>">
142 <table cellpadding="6" style="margin-left:auto;margin-right:auto;">
143 <?php
144 $i = 0;
145 foreach ($questions as $question) {
146 $i++;
147 ?>
148 <tr>
149 </tr>
150 <tr>
151 <td><?php echo $question; ?> 
152 <input type="text" class="textbox" name="answer[]" maxlength="40"
153 style="display: block;"></td>
154 </tr>
155 <?php
156 }
157 ?>
158 </table>
159 <input type="submit" value="Submit Recovery">
160 </form>
161 </fieldset>
162
163 <fieldset class="question">
164 <legend>Your New Password</legend>
165 <p style="text-align: center">These must match exactly for the appeal to proceed.<br/>
166 For advice on setting a good password, please click <a style="color: rgb(255, 187, 34);"
167 target="_blank"
168 href="/kbase/viewarticle7564.html?article_id=2087">here</a>
169 (Opens in a new window).</p>
170 <table>
171 <tr>
172 <td style="vertical-align: middle"><b>Enter a new password for your account: <input type="text"
173 name="username"></b>
174 </td>
175 </tr>
176 <tr>
177 <td style="vertical-align: middle"><b>          Please
178 enter it again: <input type="text" name="username"></b></td>
179 </tr>
180 </table>
181 </fieldset>
182
183 <fieldset class="question">
184 <legend>Other Details</legend>
185 When did you create this account?
186 <table>
187 <tr>
188 <td style="vertical-align: middle">
189 If you have any other details which would help you prove your ownership of this
190 account, please enter them here.<br/>
191 Please <b>do not</b> provide us with any of this following personal information, your full
192 name, home
193 address, email address or telephone number.<br/><br/>
194 <span class='textcounter' id="counter1">You have 300 characters remaining</span>
195 </td>
196 <td>
197 <textarea style="height: 120px; width: 450px;" class="textlimited"
198 data-textcounterid="counter1" maxlength="300" rows="4" cols="50"></textarea><br/>
199 </td>
200 </tr>
201 </table>
202 </fieldset>
203
204 <?php
205 } else {
206 //validate answers
207 $errors = array();
208 $answers = $_POST['answer'];
209 $i = 0;
210
211 foreach ($answers as $answer) {
212 $i++;
213
214 if (strlen($answer) < 3 || strlen($answer) > 35) {
215 $errors[] = 'Question #' . $i . ' must be at least three characters and no more than 26 characters.';
216 }
217
218 if (preg_match('#[^a-zA-Z0-9$/^[\p{L}-]*$/u ]#', $answer)) {
219 $errors[] = 'Question #' . $i . ' contains illegal characters.';
220 }
221 }
222
223 if (count($errors) >= 1) {
224 //back button
225 ?>
226 <center><input type="button" value="Back" onclick="goBack()"/></center> <?php
227
228 //display errors
229 foreach ($errors as $error) {
230 echo $error . '<br/>';
231 }
232 } else {
233 //generate a tracking ID
234 $rand_hash = $base->randomString(11);
235 $tracking_id = substr($rand_hash, 0, 3) . '-' . substr($rand_hash, 4, 3) . '-' . substr($rand_hash, 7, 3);
236
237 //create the recovery request
238 $database->processQuery("INSERT INTO `tracking` VALUES (null, ?, ?, NOW(), ?, ?, 0, ?, ?, ?, ?, ?, ?)", array($user->getIdByName($_POST['username']), $_SERVER['REMOTE_ADDR'], time(), $tracking_id, $answers[0], $answers[1], $answers[2], $answers[3], $answers[4], $answers[5]), false);
239
240 ?>
241 <fieldset class="question">
242 <legend>Success!</legend>
243 You have successfully submitted an account recovery request. Your request will be
244 reviewed and processed within the next 48 hours. To track your account recovery
245 progress you can use the <b>recovery tracking ID</b>.<br><br> <b>Please make
246 note</b> of the the tracking ID provided to you and store it in a <b>safe</b>,
247 <b>secure</b> location so you don't lose or forget it.</b>
248 </fieldset>
249 <br/>
250 <br/>
251 <b>Tracking ID: <?php echo $tracking_id; ?></b>
252
253 <?php
254 }
255 }
256 }
257 ?>
258 <br/>
259 <br/>
260
261 <script src="https://ajax.googleapis.com/ajax/libs/jquery/2.1.1/jquery.min.js"></script>
262 <script type="text/javascript">
263 //checks how many characters are remaining
264 // the selector below will catch the keyup events of elements decorated with class textlimited and have a maxlength
265 $('.textlimited[maxlength]').keyup(function () {
266 //get the fields limit
267 var maxLength = $(this).attr("maxlength");
268
269 // check if the limit is passed
270 if (this.value.length > maxLength) {
271 return false;
272 }
273
274 // find the counter element by the id specified in the source input element
275 var counterElement = $(".textcounter#" + $(this).data("textcounterid"));
276 // update counter 's text
277 counterElement.html("You have " + (maxLength - this.value.length) + " chararacters remaining");
278 });
279
280 //checks if the user has selected no recoveries and disables the textareas
281 $(document).ready(function () {
282 $('.input_control').change(function () {
283 $(".textbox").prop('disabled', this.checked);
284 $(".textarea").prop('disabled', this.checked);
285 });
286 $('.input_control').prop('checked', false);
287 $('.input_control').trigger('change');
288 });
289
290 // for future development
291 var months = [
292 {DaysInMonth: 31, Name: "January"},
293 {DaysInMonth: 31, Name: "February"},
294 {DaysInMonth: 31, Name: "March"},
295 {DaysInMonth: 31, Name: "April"},
296 {DaysInMonth: 31, Name: "May"},
297 {DaysInMonth: 31, Name: "June"},
298 {DaysInMonth: 31, Name: "July"},
299 {DaysInMonth: 31, Name: "August"},
300 {DaysInMonth: 31, Name: "September"},
301 {DaysInMonth: 31, Name: "October"},
302 {DaysInMonth: 31, Name: "November"},
303 {DaysInMonth: 31, Name: "December"}
304 ];
305 $(function () {
306 var monthSelector = $('select[name=month]');
307 $.each(months, function (index, month) {
308 $('<option></option>')
309 .attr('label', month.Name)
310 .attr('value', index)
311 .html(month.DaysInMonth)
312 .appendTo(monthSelector);
313 });
314
315 var yearSelector = $('select[name=ano]');
316 for (var year = 2015; year <= 2016; year++)
317 $('<option></option>')
318 .attr('label', year)
319 .attr('value', year)
320 .html(year)
321 .appendTo(yearSelector);
322 });
323
324 //limits the characters input in the 'other details' text area
325 function charLimit(limitField, limitNum) {
326 if (limitField.value.length > limitNum) {
327 limitField.value = limitField.value.substring(0, limitNum);
328 }
329 }
330 </script>
331 <div style="clear: both;"></div>
332</div>
333</div>
334</div>
335</div>
336
337<div class="tandc"><?php echo $data['wb_foot']; ?></div>
338</div>
339</body>
340</html>