/lenasys/0.1

To get this branch, use:
bzr branch http://gegoxaren.bato24.eu/bzr/lenasys/0.1

« back to all changes in this revision

Viewing changes to trunk/DuggaSys/changePassword/index.php

  • Committer: Henrik G.
  • Date: 2013-03-26 23:42:29 UTC
  • Revision ID: henrik.gustavsson@his.se-20130326234229-hkq5am6szg5g2akr
Added slider library

Show diffs side-by-side

added added

removed removed

Lines of Context:
8
8
        // echo "</pre>";
9
9
        
10
10
        //Passwordchangingcode
11
 
        if(isset($_POST['changePasswordSubmit'])) {
 
11
        if(isset($_POST['changePasswordSubmit'])){
 
12
                //////////////////////////
12
13
                $pdo = new PDO('mysql:dbname=dsystem;host=wwwlab.iki.his.se', 'dbsk', 'Tomten2009'); //ADD NEW USER WITH LESS PRIVILEGES?
13
 
                $pdo->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_WARNING);
 
14
        $pdo->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_WARNING);
 
15
        //////////////////////////
14
16
                $queryString = "SELECT Student.ssn FROM Student WHERE Student.loginName=:LOGIN AND Student.passw=:PASSW;";
15
17
 
16
 
                $stmt = $pdo->prepare($queryString);
17
 
                $stmt->bindParam(':LOGIN', $_POST['loginName']);
18
 
                $oldPassword=md5($_POST['password']);
 
18
        $stmt = $pdo->prepare($queryString);
 
19
        $stmt->bindParam(':LOGIN', $_POST['loginName']);
 
20
        $oldPassword=md5($_POST['password']);
19
21
                $stmt->bindParam(':PASSW', $oldPassword);
20
 
                $stmt->execute();
21
 
 
22
 
                if ($stmt->rowCount() == 1) { //Old password correct
 
22
 
 
23
        $stmt->execute();
 
24
 
 
25
        if ($stmt->rowCount() == 1) { //Old password correct
23
26
                        $student=$stmt->fetch(PDO::FETCH_ASSOC);
24
27
                        //Update password to new password
25
28
                        $updateString = "UPDATE Student 
32
35
                        $updateStmt->bindParam(':LOGIN', $_POST['loginName']);
33
36
                        $updateStmt->bindParam(':SSN', $student['ssn']);
34
37
                        $updateStmt->execute();
35
 
                        if($updateStmt->execute()) {
 
38
                        if($updateStmt->execute()){
36
39
                                $errorMsg="New password stored";
37
40
                        } else {
38
41
                                $errorMsg="ERROR: Failed to change password";