ponepaste/admin/index.php

67 lines
1.9 KiB
PHP
Raw Normal View History

2021-07-10 19:18:17 +01:00
<?php
2021-08-13 16:54:06 -04:00
define('IN_PONEPASTE', 1);
2021-08-22 22:05:26 -04:00
require_once(__DIR__ . '/../includes/common.php');
2021-07-10 19:18:17 +01:00
2021-11-02 08:46:40 -04:00
use PonePaste\Models\AdminLog;
if ($current_user === null || !$current_user->admin) {
header('Location: ..');
die();
}
2021-07-10 19:18:17 +01:00
if ($_SERVER['REQUEST_METHOD'] == 'POST') {
2021-11-02 08:46:40 -04:00
if (password_verify($_POST['password'], $current_user->admin_password_hash)) {
updateAdminHistory($current_user, AdminLog::ACTION_LOGIN);
$_SESSION['admin_login'] = true;
2021-08-13 16:54:06 -04:00
header("Location: dashboard.php");
exit();
} else {
2021-11-02 08:46:40 -04:00
updateAdminHistory($current_user, AdminLog::ACTION_FAIL_LOGIN);
$msg = '<div class="paste-alert alert6" style="text-align:center;">
2021-11-02 08:46:40 -04:00
Wrong Password
2021-07-10 19:18:17 +01:00
</div>';
}
2021-07-10 19:18:17 +01:00
}
?>
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
<meta name="viewport" content="width=device-width, initial-scale=1">
2021-11-02 08:46:40 -04:00
<title>PonePaste - Authenticate</title>
<link href="css/paste.css" rel="stylesheet">
2021-08-06 10:59:47 -04:00
<style>
body {
background: #F5F5F5;
}
</style>
</head>
2021-07-10 19:18:17 +01:00
<body>
<div class="login-form">
<?php
if (isset($msg)) {
echo $msg;
}
?>
<form action="." method="post">
2021-07-10 19:18:17 +01:00
<div class="top">
2021-11-02 08:46:40 -04:00
<h1>PonePaste Admin Authentication</h1>
2021-07-10 19:18:17 +01:00
</div>
<div class="form-area">
<div class="group">
2021-11-02 08:46:40 -04:00
<input type="text" class="form-control" id="username" name="username" disabled="disabled" value="<?= pp_html_escape($current_user->username); ?>">
<i class="fa fa-user"></i>
</div>
<div class="group">
<input type="password" class="form-control" id="password" name="password" placeholder="Password"
value="">
<i class="fa fa-key"></i>
</div>
2021-11-02 08:46:40 -04:00
<button type="submit" class="btn btn-default btn-block">Authenticate</button>
2021-07-10 19:18:17 +01:00
</div>
</form>
</div>
2021-07-10 19:18:17 +01:00
</body>
</html>