-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathcreateUser.php
More file actions
65 lines (53 loc) · 1.76 KB
/
createUser.php
File metadata and controls
65 lines (53 loc) · 1.76 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
<?php
/*
This file is part of WanderWiki project.
WanderWiki project is free software: you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
the Free Software Foundation, either version 3 of the License, or
(at your option) any later version.
WanderWiki is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.
You should have received a copy of the GNU General Public License
along with WanderWiki. If not, see <http://www.gnu.org/licenses/>.
*/
/*
This script creates a user in the WanderWiki database
*/
/* Cleaning the $_GET array of any security harmful code */
require("clean.inc.php");
$_CLEAN = clean($_GET);
/* Verification of the sent parameters */
if(!(isset($_CLEAN['email_adr'])&&isset($_CLEAN['pseudo'])&&isset($_CLEAN['security'])))
{
die('Missing arguments');
}
if($_CLEAN['email_adr']==NULL)
{
die('Missing email adresse');
}
if($_CLEAN['pseudo']==NULL)
{
die('Missing pseudo');
}
/* Connexion to database */
require("infoDB.inc.php");
$mysqli = new mysqli($host,$user,$password,$dbname);
if ($mysqli->connect_error)
{
die('Connexion error (' . $mysqli->connect_errno . ') ' . $mysqli->connect_error);
}
/* Preparation and sending of the query */
$query="INSERT INTO `users` ( `account`, `pseudo`, `security` )
VALUES ('".$_CLEAN['email_adr']."','".$_CLEAN['pseudo']."',".$_CLEAN['security'].")";
if($mysqli->query($query))
{
/* Send the id associated with the created user */
echo 'success/'.$mysqli->insert_id;
}
else
{
die('Request error (' . $mysqli->errno . ') '. $mysqli->error);
}
$mysqli->close();