food-inventory/assets/php/utils.php
2019-11-10 15:36:37 +01:00

311 lines
8.5 KiB
PHP

<?php
$SESSION_COOKIE_NAME = "connection_id";
$MAX_COOKIE_LIFE = time() + 86400 * 30; // 30 days max
$MINIMAL_PASSWORD_LENGTH = 8;
$config_array = json_decode(file_get_contents("config.json", true));
$dsn = $config_array->{"kind"} . ":dbname="
. $config_array->{"dbname"} . ";host=" . $config_array->{"host"};
$PDO = new PDO($dsn, $config_array->{"user"}, $config_array->{"password"});
$PDO->query('SET CHARSET UTF8');
function is_https()
{
return (!empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off');
}
function generate_random_string()
{
return substr(str_shuffle(MD5(microtime())), 0, 32);
}
function connect_user($user_id, $long_expiration = true)
{
global $PDO, $SESSION_COOKIE_NAME, $MAX_COOKIE_LIFE;
// Set an expiration delay for the cookie
$delay = 86400;
if ($long_expiration === true) {
$delay = $MAX_COOKIE_LIFE;
}
// The session id is a 32-chars random string
$session_id = generate_random_string();
$sql = "INSERT INTO sessions(user_id, connection_eol, session_id)
VALUES (:user_id, :connection_eol, :session_id);";
$query = $PDO->prepare($sql);
$query->bindValue(":user_id", $user_id);
$query->bindValue(
":connection_eol",
date('Y-m-d H:i:s', strtotime("now + $delay seconds")), PDO::PARAM_STR
);
$query->bindValue(":session_id", $session_id);
if ($query->execute()) {
return setcookie(
$SESSION_COOKIE_NAME,
$session_id,
time() + $delay,
$secure = true
);
}
return false;
}
function clean_old_sessions()
{
global $PDO;
$sql = "DELETE FROM sessions WHERE connection_eol < CURRENT_TIMESTAMP();";
$query = $PDO->prepare($sql);
return $query->execute();
}
function disconnect()
{
global $PDO, $SESSION_COOKIE_NAME;
if (isset($_COOKIE[$SESSION_COOKIE_NAME])) {
$sql = "DELETE FROM sessions WHERE session_id = :session_id;";
$query = $PDO->prepare($sql);
$query->bindValue(":session_id", $_COOKIE[$SESSION_COOKIE_NAME]);
$query->execute();
setcookie($SESSION_COOKIE_NAME, "", time() - 3600);
}
}
function is_connected()
{
global $PDO, $SESSION_COOKIE_NAME;
if (isset($_COOKIE[$SESSION_COOKIE_NAME])) {
if (!clean_old_sessions()) {
return false;
}
$sql = "SELECT * FROM sessions INNER JOIN accounts ON sessions.user_id = accounts.id WHERE session_id = :session_id;";
$query = $PDO->prepare($sql);
$query->bindValue(":session_id", $_COOKIE[$SESSION_COOKIE_NAME]);
if ($query->execute()) {
if ($query->rowCount() === 1) {
return true;
} else {
disconnect();
return false;
}
} else {
return false;
}
}
return false;
}
function get_username_count($email)
{
global $PDO;
$sql = "SELECT email FROM accounts WHERE email = :email;";
$query = $PDO->prepare($sql);
$query->bindValue(":email", $email);
if ($query->execute()) {
return $query->rowCount();
}
return false;
}
function correct_email_password($email, $password)
{
global $PDO;
$sql = "SELECT email, password_hash FROM accounts WHERE email = :email;";
$query = $PDO->prepare($sql);
$query->bindValue(":email", $email);
if ($query->execute()) {
foreach ($query as $row) {
return password_verify($password, $row["password_hash"]);
}
}
return false;
}
function get_user_id_from_email($email)
{
global $PDO;
$sql = "SELECT id FROM accounts WHERE email = :email;";
$query = $PDO->prepare($sql);
$query->bindValue(":email", $email);
if ($query->execute()) {
foreach ($query as $row) {
return $row["id"];
}
}
return false;
}
function get_user_info_from_session_id($info)
{
global $PDO, $SESSION_COOKIE_NAME;
if (isset($_COOKIE[$SESSION_COOKIE_NAME])) {
$sql = "SELECT accounts.id AS id, email,
first_name, first_name,
last_name, public_id FROM accounts
INNER JOIN sessions
ON sessions.user_id = accounts.id
WHERE session_id = :session_id;";
$query = $PDO->prepare($sql);
$query->bindValue(":session_id", $_COOKIE[$SESSION_COOKIE_NAME]);
if ($query->execute())
foreach ($query as $row) {
switch ($info) {
case "id":
case "email":
case "first_name":
case "last_name":
case "public_id":
return $row[$info];
default;
break;
}
}
}
return false;
}
function add_user($email, $first_name, $last_name, $clear_password)
{
global $PDO;
$password_hash = password_hash($clear_password, PASSWORD_DEFAULT);
$sql = "INSERT INTO accounts(email, first_name, last_name, password_hash, public_id)
VALUES (:email, :first_name, :last_name, :password, :public_id);";
$query = $PDO->prepare($sql);
$query->bindValue(":email", $email);
$query->bindValue(":first_name", $first_name);
$query->bindValue(":last_name", $last_name);
$query->bindValue(":password", $password_hash);
$query->bindValue(":public_id", generate_random_string());
return $query->execute();
}
function change_user_password($user_id, $new_clear_password)
{
global $PDO;
$password_hash = password_hash($new_clear_password, PASSWORD_DEFAULT);
$sql = "UPDATE accounts SET password_hash = :password_hash WHERE accounts.id = :id";
$query = $PDO->prepare($sql);
$query->bindValue(":password_hash", $password_hash);
$query->bindValue(":id", $user_id, PDO::PARAM_INT);
return $query->execute();
}
function add_cupboard($name, $description)
{
global $PDO;
$sql = "INSERT INTO cupboards (name, description, owner_id, public_id)
VALUES (:name, :description, :owner_id, :public_id);";
$query = $PDO->prepare($sql);
$query->bindValue(":name", $name);
$query->bindValue(":description", $description);
$query->bindValue(":owner_id", get_user_info_from_session_id("id"));
$query->bindValue(":public_id", generate_random_string());
return $query->execute();
}
function does_cupboard_exist_from_id($id)
{
global $PDO;
$sql = "SELECT id FROM cupboards WHERE id = :id;";
$query = $PDO->prepare($sql);
$query->bindValue(":id", $id);
if ($query->execute()) {
return ($query->rowCount() === 1);
}
return false;
}
function add_product($name, $description, $expiration_date = NULL, $cupboard_id = NULL)
{
global $PDO;
$sql = "INSERT INTO products
(name, description, expiration_date, owner_id, cupboard_id, public_id)
VALUES
(:name, :description, :expiration_date, :owner_id, :cupboard_id, :public_id);";
$query = $PDO->prepare($sql);
$query->bindValue(":name", $name);
$query->bindValue(":description", $description);
if ($expiration_date === NULL) {
$query->bindValue(":expiration_date", NULL, PDO::PARAM_INT);
} else {
$query->bindValue(":expiration_date", $expiration_date);
}
if ($cupboard_id === NULL) {
$query->bindValue(":cupboard_id", NULL, PDO::PARAM_INT);
} else {
$query->bindValue(":cupboard_id", $cupboard_id);
}
$query->bindValue(":owner_id", get_user_info_from_session_id("id"));
$query->bindValue(":public_id", generate_random_string());
return $query->execute();
}
function get_users_products_array()
{
global $PDO;
$user_products = array();
$sql = "SELECT
id, name, description, expiration_date, added_date, cupboard_name, public_id
FROM products WHERE owner_id = :owner_id;";
$query = $PDO->prepare($sql);
$query->bindValue(":owner_id", get_user_info_from_session_id("id"));
if ($query->execute()) {
foreach ($query as $row) {
array_push($user_products, $row);
}
}
return $user_products;
}
function get_users_cupboards_array()
{
global $PDO;
$user_cupboards = array();
$sql = "SELECT
id, name, description, public_id
FROM products WHERE owner_id = :owner_id;";
$query = $PDO->prepare($sql);
$query->bindValue(":owner_id", get_user_info_from_session_id("id"));
if ($query->execute()) {
foreach ($query as $row) {
array_push($user_cupboards, $row);
}
}
return $user_cupboards;
}