· 10 years ago · Jan 15, 2016, 07:09 AM
1<?php
2header("Access-Control-Allow-Origin: *");
3// When mistakes happen we want the notice returned not the warning. The Warning means nothing to the end user, but we will use the notice
4// to return information to the user. You should really log the errors though so you have them.
5//==MAN1==
6error_reporting(E_ERROR);
7
8/*
9STEP 1 MySQL Connection Details
10If you do not know the following information you will need to get it from your web host.
11It will most likely be the same as your cPanel login information.
12Server should stay as localhost unless this file and your MySQL are on different servers (not recommended).
13*/
14//==MAN2==
15$hostname = "localhost"; //This is probably correct
16$username = "no"; // Your MySQL username
17$password = "no"; // Your MySQL Password
18$database = "no"; // The name of your database
19$table = "no"; // Your actual table to hold the data
20//$table2 = ""; //You can use multiple tables to organize your database!
21
22// Make a MySQL Connection no changes need to be made here
23//==MAN3==
24$dbh = new PDO("mysql:host=$hostname; dbname=$database", $username, $password);
25$dbh->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
26$dbh->setAttribute(PDO::ATTR_EMULATE_PREPARES, false);
27/*
28STEP 2 Potential Variables passed from URL - list them all here.
29*/
30//==MAN4==
31$f = $_POST['f']; //na=new account sv=save ld=load information and au=authorize access
32$pname = $_POST['n'];
33$pip = $_POST['ip'];
34$pnp = $_POST['np'];
35$pop = $_POST['op'];
36$psp = $_POST['sp'];
37$pword = $_POST['pass'];
38
39//==MAN5==
40$salt = "no"; // CHANGE THIS TO SOMETHING SECRET
41$epword = crypt($pword,$salt); // This encrypts the password and sets it to a variable.
42
43//==MAN6==
44//Functions Start
45
46//This function will create a new user account or save file
47//==MAN7==
48function create_account($dbh,$table,$pip,$pnp,$pop,$psp,$epword,$pname) //declare function Part between () is all the variables you will need for this function.
49{
50try
51 {
52 $stmt = $dbh->prepare("INSERT INTO $table (p_name, p_word, p_ip, p_np, p_op, p_sp) VALUES (:pname, :pword, :pip, :pnp, :pop, :psp)"); //Prepare statement for instert
53 $stmt ->bindparam(':pname', $pname, PDO::PARAM_STR); //Build inserts array
54 $stmt ->bindparam(':pword', $epword, PDO::PARAM_STR);
55 $stmt ->bindparam(':pip', $pip, PDO::PARAM_STR);
56 $stmt ->bindparam(':pnp', $pnp, PDO::PARAM_STR);
57 $stmt ->bindparam(':pop', $pop, PDO::PARAM_STR);
58 $stmt ->bindparam(':psp', $psp, PDO::PARAM_STR);
59 $stmt->execute(); //Execute array
60 echo "1"; //Everything worked!
61 }
62 catch (PDOExecption $ex)
63 {
64 echo "0"; //Something went wrong :(
65 }
66 $dbh = null;
67}
68
69// This function will save information to an existing account
70//==MAN8==
71function save_info($dbh, $table, $pname, $pip, $pnp, $pop, $psp)
72{
73try
74 {
75 $stmt = $dbh->prepare("UPDATE $table SET p_ip=?, p_np=?,p_op=?,p_sp=? WHERE p_name=?");
76 $stmt->execute(array($pip,$pnp,$pop,$psp,$pname));
77 echo "1";
78 }
79 catch (PDOExecption $ex)
80 {
81 echo "0";
82 }
83 $dbh = null;
84}
85
86// This function will pull account information
87//==MAN9==
88function load_info($dbh,$table,$pname)
89{
90 {
91 $stmt = $dbh->query("SELECT * FROM $table WHERE p_name = '$pname'");
92 $result = $stmt->fetchObject();
93 echo $result->p_name.",".$result->p_ip. "," .$result->p_np. "," .$result->p_op. "," . $result->p_sp;
94 $dbh = null;
95 }
96}
97// This function will simply check if a user exists in the system - useful to authorize their access.
98//==MAN10==
99function auth($dbh, $table, $epword, $pname)
100{
101 $stmt = $dbh->query("SELECT COUNT(*) from $table WHERE p_name = '$pname' AND p_word = '$epword'");
102 $result = $stmt->fetchColumn();
103
104 if ($result <= 0)
105 {
106 echo '0';
107 }
108 else
109 {
110 echo '1';
111 }
112}
113// This function is used for nothing more than testing that the script and database are working.
114//==MAN11==
115function connection_test($dbh,$table,$pname)
116{
117 $stmt = $dbh->query("SELECT COUNT(*) from $table");
118 $result = $stmt->fetchColumn();
119
120 if ($result <= 0)
121 {
122 echo 'Could not communicate with database. Check your setup, username & pass, or your database is empty.';
123 }
124 else
125 {
126 echo 'Everything seems good you have '. $result .' row(s) in your database!';
127 }
128}
129
130// This determines which function to call based on the $f parameter passed in the URL.
131//==MAN12==
132switch($f)
133{
134 case na: create_account($dbh,$table,$pip,$pnp,$pop,$psp,$epword,$pname); break;
135 case sv: save_info($dbh, $table,$pname,$pip,$pnp,$pop,$psp); break;
136 case ld: load_info($dbh,$table,$pname); break;
137 case au: auth($dbh,$table,$epword,$pname); break;
138 case ts: connection_test($dbh,$table,$pname); break;
139 default: echo"error";
140}
141
142?>