%PDF- %PDF-
| Direktori : /home/riacommer/public_html/api/ |
| Current File : /home/riacommer/public_html/api/reset.php |
<?php
include_once("../admin/api/db.php");
if(isset($_POST["gid"])){
$gid = $_POST["gid"];
$pwd = sha1($_POST["pwd"]);
$cpwd = sha1($_POST["cpwd"]);
if($pwd!=$cpwd){
header("Location: http://".$_SERVER['HTTP_HOST'] . str_replace("/api", "", dirname($_SERVER['PHP_SELF']))."/reset.php?gid=".$gid."&f=3", true);
} else {
$sql = "SELECT * FROM sa_customer WHERE pwd='$gid'";
$mysql_result = mysql_query($sql, $connection);
$num_rows = mysql_num_rows($mysql_result);
if($num_rows>=1){
echo 'got record';
while($row = mysql_fetch_array($mysql_result)){
$rid = $row["id"];
$sqlReset = "UPDATE sa_customer SET pwd='$cpwd' WHERE id='$rid'";
mysql_query($sqlReset);
echo 'update';
//send email reset password / UPDATE
header("Location: http://".$_SERVER['HTTP_HOST'] . str_replace("/api", "", dirname($_SERVER['PHP_SELF']))."/login.php?f=reset", true);
}
} else {
//invalid reset failed to reset
header("Location: http://".$_SERVER['HTTP_HOST'] . str_replace("/api", "", dirname($_SERVER['PHP_SELF']))."/reset.php?f=2", true);
}
}
} else {
header("Location: http://" .$_SERVER['HTTP_HOST'] . str_replace("/api", "", dirname($_SERVER['PHP_SELF'])) ."/400.php");
}
?>