Repository navigation
Expand file tree
/
Copy pathfriend.php
More file actions
179 lines (140 loc) · 6.73 KB
/
Copy pathfriend.php
File metadata and controls
179 lines (140 loc) · 6.73 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
<?php
session_start();
$mysql_connect = mysqli_connect("localhost", "id16543739_cdbat", "Cypress@12345", "id16543739_cypress");
// check if database connected properly
if(!$mysql_connect){
die(mysqli_connect_error());
}
include 'header.php';
// get user email
$email = $_SESSION['email'];
//user deleting account
if(isset($_POST['delete_account'])){
$reason = $_POST['delete_reason'];
$security = $_POST['security'];
// select everything from the table Accounts where the column email = userEmail and column password = userpassword
$sqlQuery = "SELECT * FROM Accounts WHERE email ='$email' AND security ='$security'";
// get query result
$queryResult = $mysql_connect -> query($sqlQuery);
$queryRows = mysqli_num_rows($queryResult);
// account found
if($queryRows == 1){
// add reason to database
$sqlQuery = "INSERT INTO delete_reasons (reason) VALUES ('$reason')";
$queryResult = $mysql_connect -> query($sqlQuery);
// delete all forms made by user
$sqlQuery = "DELETE FROM Forms WHERE email = '$email' AND ";
$queryResult = $mysql_connect -> query($sqlQuery);
// delete user account
$sqlQuery = "DELETE FROM Accounts WHERE email = '$email'";
// execute query result
$queryResult = $mysql_connect -> query($sqlQuery);
// log user out
unset($_SESSION['email']);
$message = "You successfully deleted your account.";
echo "<script type='text/javascript'>alert('$message');</script>";
// redirect
echo'
<script>
window.location.replace("https://cypress-cdbat.000webhostapp.com/index.php");
</script>
';
}else{
$message = "INCORRECT secret question. FAILED to DELETE ACCOUNT";
echo "<script type='text/javascript'>alert('$message');</script>"; }
}
?>
<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no">
<title>Account Settings</title>
</head>
<body style ="background-color:white;">
<?php
$sqlQuery = "SELECT * FROM Accounts WHERE email ='$email'";
// get query result
$queryResult = $mysql_connect -> query($sqlQuery);
foreach ($queryResult as $row){
?>
<div class="jumbotron" style ="background-color:white;">
<div class="bg order-1 order-md-2"></div>
<div class="contents order-2 order-md-1">
<div class="container">
<div class="row align-items-center justify-content-center">
<div class="col-md-7 py-5">
<h3><?php checkLanguage("Tell Your Friend About Us","Parlez de nous à votre ami");?></h3>
</p>
<form onsubmit = "return confirm_delete();" action="#" method="POST">
<div class="row">
<div class="col-md-12">
<div class="form-group first">
<label for="email"><?php checkLanguage("Email Address","Adresse e-mail");?></label>
<input type="email" class="form-control" value="<?php print($row['email']) ;?>" id="email" disabled>
</div>
</div>
</div>
<div class="row">
<div class="col-md-12">
<div class="form-group first">
<label for="friend_email"><?php checkLanguage("Friend Email Address","Adresse e-mail de l'ami");?></label>
<input type="input" class="form-control" name = "friend_email" id="friend_email" oninput ="stoppedTyping();">
</div>
</div>
</div>
<div class="row">
<div class="col-md-12">
<div class="form-group first">
<label for="damage-info"><b><?php checkLanguage("Email Message", "Message électronique"); ?></b>
</label>
<textarea id="email_message" name="email_message" class="form-control" rows=5
><?php checkLanguage("Hi friend, I found this awesome website that lets me report city damages and
vote in the next municipal election in Toronto. I thought I should share this with you as well.
https://cypress-cdbat.000webhostapp.com
Sincerely,",
"Salut ami, j'ai trouvé ce site Web génial qui me permet de signaler les dommages causés par la ville et
voter aux prochaines élections municipales à Toronto. J'ai pensé que je devrais également partager cela avec vous.
https://cypress-cdbat.000webhostapp.com
Sincèrement,")?>
<?php print($row['first_name']." ".$row['last_name']);?>
</textarea>
</div>
</div>
</div>
<!-- change to button -->
<button type="submit" class="btn px-5 btn-primary" id = "send_email" name = "send_email" ><?php checkLanguage("Send Email","Envoyer un e-mail");?></button>
<br>
<br>
<br>
<br>
</form>
<?php
if(isset($_POST['send_email'])){
$friend_email = $_POST['friend_email'];
$message = $_POST['email_message'];
// send email to friend
mail($friend_email,'Password Reset Cypress', $message, '$email');
$message = checkLanguageAlert("Email has been sent", "L'email a été envoyé");
echo "<script type='text/javascript'>alert('$message');</script>";
echo'
<script>
window.location.replace("https://cypress-cdbat.000webhostapp.com/index.php");
</script>
';
}
}
?>
</div>
</div>
</div>
</div>
</div>
</body>
<script src="scripts/friend.js"></script>
<script>
if ( window.history.replaceState ) {
window.history.replaceState( null, null, window.location.href );
}
</script>
</html>