2015-02-11 23:52:11 -05:00
|
|
|
<?php
|
2015-02-12 15:23:08 -05:00
|
|
|
session_start();
|
|
|
|
require_once("config.inc.php");
|
|
|
|
$yaptc_pagename = "Profile";
|
|
|
|
require_once($yaptc_inc . "header.inc.php");
|
|
|
|
require_once($yaptc_inc . "menu.inc.php");
|
|
|
|
// Is user logged in? If not, they shouldn't be here - kill all variables and redirect to login...
|
|
|
|
if (!isset($_SESSION['user_id']) || !isset($_SESSION['signature']) || !isset($_SESSION['loggedIn']) || $_SESSION['loggedIn'] != true || $_SESSION['signature'] != md5($_SESSION['user_id'] . $_SERVER['HTTP_USER_AGENT']))
|
|
|
|
{
|
|
|
|
session_start();
|
|
|
|
session_unset();
|
|
|
|
session_destroy();
|
|
|
|
header ("Refresh:3; url=login.php", true, 303);
|
|
|
|
echo "<h2 class=\"content-subhead\">You are not logged in!!!</h2>";
|
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
2015-02-18 05:13:53 -05:00
|
|
|
//********** BEGIN CONTENT **********//
|
|
|
|
|
|
|
|
$query = "SELECT users.id, users.password, users.created, users.username, users.firstname, users.lastname, users.email, usertypes.typename AS usertype FROM users, usertypes WHERE users.id = :id";
|
|
|
|
$stmt = $sql->prepare($query);
|
|
|
|
$stmt->execute(array(':id' => $_SESSION['user_id']));
|
|
|
|
$user = $stmt->fetchObject();
|
|
|
|
?>
|
|
|
|
<h2 class\"content-subhead">Profile Information</h2>
|
|
|
|
<p>You may make changes to your user profile below if you wish. Updates will take effect immediately on pressing "Save".</p>
|
|
|
|
<form class="pure-form pure-form-aligned" action="profile.php" method="post">
|
|
|
|
<fieldset>
|
|
|
|
<div class="pure-control-group">
|
|
|
|
<label for="username">Username</label>
|
|
|
|
<input type="text" name="username" maxlength="50" value="<?php echo $user->username; ?>" readonly>
|
|
|
|
</div>
|
|
|
|
<div class="pure-control-group">
|
|
|
|
<label for="created">Created</label>
|
|
|
|
<input type="text" name="created" value="<?php echo $user->created; ?>" readonly>
|
|
|
|
</div>
|
|
|
|
<div class="pure-control-group">
|
|
|
|
<label for="usertype">User Type</label>
|
|
|
|
<input type="text" name="usertype" maxlength="50" value="<?php echo $user->usertype; ?>" readonly>
|
|
|
|
</div>
|
|
|
|
<div class="pure-control-group">
|
|
|
|
<label for="firstname">First Name</label>
|
|
|
|
<input type="text" name="firstname" maxlength="50" value="<?php echo $user->firstname; ?>">
|
|
|
|
</div>
|
|
|
|
<div class="pure-control-group">
|
|
|
|
<label for="lastname">Last Name</label>
|
|
|
|
<input type="text" name="lastname" maxlength="50" value="<?php echo $user->lastname; ?>">
|
|
|
|
</div>
|
|
|
|
<div class="pure-control-group">
|
|
|
|
<label for="email">Email</label>
|
|
|
|
<input type="text" name="email" maxlength="100" value="<?php echo $user->email; ?>">
|
|
|
|
</div>
|
|
|
|
<div class="pure-controls">
|
|
|
|
<button type="submit" class="pure-button button-xlarge button-success">Save</button>
|
|
|
|
</div>
|
|
|
|
|
|
|
|
<?php
|
2015-02-12 15:23:08 -05:00
|
|
|
if (!empty($_POST)) {
|
|
|
|
$query = "UPDATE users SET firstname = :firstname, lastname = :lastname, email = :email WHERE id = :userid";
|
|
|
|
$stmt = $sql->prepare($query);
|
|
|
|
$stmt->execute(array(
|
|
|
|
':userid' => $_SESSION['user_id'],
|
|
|
|
':firstname' => $_POST['firstname'],
|
|
|
|
':lastname' => $_POST['lastname'],
|
|
|
|
':email' => $_POST['email']
|
|
|
|
));
|
|
|
|
header('Location: '.$_SERVER['PHP_SELF']);
|
|
|
|
exit;
|
|
|
|
}
|
|
|
|
echo "</fieldset>";
|
|
|
|
echo "</form>";
|
2015-02-11 23:52:11 -05:00
|
|
|
|
2015-02-12 15:23:08 -05:00
|
|
|
|
|
|
|
|
|
|
|
//********** END CONTENT **********//
|
2015-02-18 05:13:53 -05:00
|
|
|
}
|
2015-02-12 15:23:08 -05:00
|
|
|
require_once($yaptc_inc . "footer.inc.php");
|
2015-02-11 23:52:11 -05:00
|
|
|
?>
|