saved emails, gmail, hotmail start, home, landing etc

This commit is contained in:
Dr3amFury
2025-08-20 12:58:40 +02:00
parent 08a5cead74
commit 9ec1e0f9fe
17 changed files with 683 additions and 172 deletions

View File

@@ -1,24 +1,32 @@
<?php
session_start();
if (session_status() === PHP_SESSION_NONE) {
session_start();
}
require_once($_SERVER['DOCUMENT_ROOT'] . '/db.php');
function isAuthenticated() {
if (!isset($_SESSION['user_id']) || !isset($_SESSION['uniqueid'])) {
if (empty($_SESSION['user_id']) || empty($_SESSION['uniqueid'])) {
return false;
}
$conn = getConnection();
$stmt = $conn->prepare("SELECT id FROM users WHERE id = :id AND uniqueid = :uniqueid");
$stmt->execute([
'id' => $_SESSION['user_id'],
'uniqueid' => $_SESSION['uniqueid'],
]);
try {
$conn = getConnection();
$stmt = $conn->prepare("SELECT id FROM users WHERE id = :id AND uniqueid = :uniqueid");
$stmt->execute([
'id' => $_SESSION['user_id'],
'uniqueid' => $_SESSION['uniqueid'],
]);
return $stmt->fetch() !== false;
return $stmt->fetch() !== false;
} catch (PDOException $e) {
return false; // fail safe
}
}
if (!isAuthenticated()) {
header("Location: /landing.php");
exit();
function requireLogin() {
if (!isAuthenticated()) {
header("Location: /landing.php");
exit();
}
}
?>

18
inc/php/delete_email.php Normal file
View File

@@ -0,0 +1,18 @@
<?php
// /inc/php/delete_email.php
session_start();
require_once($_SERVER['DOCUMENT_ROOT'] . '/inc/php/auth.php');
requireLogin();
require_once($_SERVER['DOCUMENT_ROOT'] . '/db.php');
$conn = getConnection();
$user_id = $_SESSION['user_id'] ?? null;
$id = intval($_GET['id'] ?? 0);
$stmt = $conn->prepare("DELETE FROM saved_emails WHERE id = ? AND user_id = ?");
$stmt->bind_param("ii", $id, $user_id);
$stmt->execute();
header("Location: /inc/php/saved.php?deleted=1");
exit;

37
inc/php/generate.php Normal file
View File

@@ -0,0 +1,37 @@
<?php
require_once($_SERVER['DOCUMENT_ROOT'] . '/inc/php/auth.php');
requireLogin();
require_once($_SERVER['DOCUMENT_ROOT'] . '/inc/php/resources.php'); // load languages
include($_SERVER['DOCUMENT_ROOT'] . '/inc/php/header.php');
?>
<body>
<div class="container">
<h1>Generate an Email</h1>
<!-- adjust action depending on vhost/subfolder -->
<form action="/process.php" method="POST">
<label for="email_input">Your rough text:</label><br>
<textarea name="email_input" rows="6" cols="50" required></textarea><br><br>
<label for="tone">Select tone:</label>
<select name="tone" required>
<option value="formal">Formal</option>
<option value="casual">Casual</option>
<option value="persuasive">Persuasive</option>
</select><br><br>
<label for="language">Language:</label>
<select name="language" required>
<?php foreach (getLanguages() as $lang): ?>
<option value="<?= htmlspecialchars($lang) ?>"><?= htmlspecialchars($lang) ?></option>
<?php endforeach; ?>
</select><br><br>
<button type="submit">Generate Email</button>
</form>
<br>
<a href="/home.php"><button type="button">🏠 Back to Home</button></a>
</div>
<?php include($_SERVER['DOCUMENT_ROOT'] . '/inc/php/footer.php'); ?>

View File

@@ -1,5 +1,10 @@
<?php
session_start();
// Always start session safely
if (session_status() === PHP_SESSION_NONE) {
session_start();
}
// Load DB
require_once($_SERVER['DOCUMENT_ROOT'] . '/db.php');
$errors = [];
@@ -9,37 +14,78 @@ if ($_SERVER['REQUEST_METHOD'] === 'POST') {
$password = $_POST['login_password'] ?? '';
$captcha = $_POST['g-recaptcha-response'] ?? '';
// 1. Input validation
if (empty($user) || empty($password)) {
$errors[] = "All fields are required.";
}
// CAPTCHA validation
$captcha_secret = '6LeIxAcTAAAAAGG-vFI1TnRWxMZNFuojJ4WifJWe'; // Google's test secret key
$captcha_response = file_get_contents("https://www.google.com/recaptcha/api/siteverify?secret={$captcha_secret}&response={$captcha}");
$captcha_data = json_decode($captcha_response);
// 2. CAPTCHA validation
$captcha_success = false;
$localHosts = ['127.0.0.1', 'localhost'];
if (in_array($_SERVER['SERVER_NAME'], $localHosts) || str_contains($_SERVER['HTTP_HOST'], '.test')) {
$captcha_success = true; // Skip CAPTCHA locally
} else {
if (!empty($captcha)) {
$captcha_secret = '6LeIxAcTAAAAAGG-vFI1TnRWxMZNFuojJ4WifJWe'; // test key
if (!$captcha_data->success) {
$errors[] = "CAPTCHA verification failed.";
}
$ch = curl_init("https://www.google.com/recaptcha/api/siteverify");
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS, [
'secret' => $captcha_secret,
'response' => $captcha,
'remoteip' => $_SERVER['REMOTE_ADDR'] ?? null
]);
if (empty($errors)) {
$conn = getConnection();
$stmt = $conn->prepare("SELECT id, password, uniqueid FROM users WHERE email = :user OR username = :user");
$stmt->execute(['user' => $user]);
$result = $stmt->fetch();
$captcha_response = curl_exec($ch);
curl_close($ch);
if ($result && password_verify($password, $result['password'])) {
$_SESSION['user_id'] = $result['id'];
$_SESSION['uniqueid'] = $result['uniqueid'];
header("Location: /home.php");
exit();
} else {
$errors[] = "Invalid credentials.";
$captcha_data = json_decode($captcha_response, true);
$captcha_success = !empty($captcha_data['success']);
}
}
if (!$captcha_success) {
$errors[] = "CAPTCHA verification failed.";
}
// 3. Authentication
if (empty($errors)) {
try {
$conn = getConnection();
$stmt = $conn->prepare("
SELECT id, username, password, uniqueid
FROM users
WHERE email = :email OR username = :username
LIMIT 1
");
$stmt->execute([
'email' => $user,
'username' => $user
]);
$result = $stmt->fetch(PDO::FETCH_ASSOC);
if ($result && password_verify($password, $result['password'])) {
// Regenerate session ID on login (security)
session_regenerate_id(true);
$_SESSION['user_id'] = $result['id'];
$_SESSION['username'] = $result['username'];
$_SESSION['uniqueid'] = $result['uniqueid'];
header("Location: /home.php");
exit;
} else {
$errors[] = "Invalid email/username or password.";
}
} catch (Exception $e) {
$errors[] = "Database error: " . $e->getMessage();
}
}
// If failed
$_SESSION['login_error'] = implode("<br>", $errors);
header("Location: /landing.php");
exit();
exit;
}
?>

View File

@@ -9,11 +9,11 @@ if ($_SERVER['REQUEST_METHOD'] === 'POST') {
$email = trim($_POST['email'] ?? '');
$confirm_email = trim($_POST['confirm_email'] ?? '');
$password = $_POST['password'] ?? '';
$age = (int) ($_POST['age'] ?? 0);
$dob = $_POST['dob'] ?? ''; // from <input type="date" name="dob">
$captcha = $_POST['g-recaptcha-response'] ?? '';
// Basic validation
if (empty($username) || empty($email) || empty($confirm_email) || empty($password) || empty($age)) {
if (empty($username) || empty($email) || empty($confirm_email) || empty($password) || empty($dob)) {
$errors[] = "All fields are required.";
}
@@ -29,8 +29,27 @@ if ($_SERVER['REQUEST_METHOD'] === 'POST') {
$errors[] = "Password must be at least 6 characters.";
}
if ($age < 16) {
$errors[] = "You must be at least 16 years old to register.";
// Date of Birth validation
if ($dob) {
try {
$birthDate = new DateTime($dob);
$today = new DateTime();
if ($birthDate > $today) {
$errors[] = "Date of birth cannot be in the future.";
}
if ($birthDate < new DateTime('1900-01-01')) {
$errors[] = "Please enter a valid birth year (1900 or later).";
}
$age = $today->diff($birthDate)->y;
if ($age < 16) {
$errors[] = "You must be at least 16 years old to register.";
}
} catch (Exception $e) {
$errors[] = "Invalid date of birth.";
}
}
// CAPTCHA validation
@@ -55,11 +74,13 @@ if ($_SERVER['REQUEST_METHOD'] === 'POST') {
$hash = password_hash($password, PASSWORD_BCRYPT, ['cost' => 12]);
$uniqueId = bin2hex(random_bytes(16));
$insert = $conn->prepare("INSERT INTO users (username, email, password, uniqueid) VALUES (:username, :email, :password, :uniqueid)");
$insert = $conn->prepare("INSERT INTO users (username, email, password, dob, uniqueid)
VALUES (:username, :email, :password, :dob, :uniqueid)");
$insert->execute([
'username' => $username,
'email' => $email,
'password' => $hash,
'dob' => $dob,
'uniqueid' => $uniqueId,
]);

39
inc/php/save_email.php Normal file
View File

@@ -0,0 +1,39 @@
<?php
// /inc/php/save_email.php
session_start();
require_once($_SERVER['DOCUMENT_ROOT'] . '/inc/php/auth.php');
requireLogin(); // block guests
require_once($_SERVER['DOCUMENT_ROOT'] . '/db.php');
$conn = getConnection();
$user_id = $_SESSION['user_id'] ?? null;
if (!$user_id) {
die("Unauthorized. Please log in.");
}
// Get and sanitize inputs
$subject = trim($_POST['subject'] ?? '');
$email_body = trim($_POST['email_body'] ?? '');
if (empty($email_body)) {
die("No email content provided.");
}
$stmt = $conn->prepare("
INSERT INTO saved_emails (user_id, subject, body, created_at)
VALUES (:user_id, :subject, :body, NOW())
");
if ($stmt->execute([
':user_id' => $user_id,
':subject' => $subject,
':body' => $email_body
])) {
header("Location: /home.php?success=1");
exit;
} else {
$error = $stmt->errorInfo();
echo "Error saving email: " . $error[2];
}

33
inc/php/view_email.php Normal file
View File

@@ -0,0 +1,33 @@
<?php
// /inc/php/view_email.php
session_start();
require_once($_SERVER['DOCUMENT_ROOT'] . '/inc/php/auth.php');
requireLogin();
require_once($_SERVER['DOCUMENT_ROOT'] . '/db.php');
$conn = getConnection();
$user_id = $_SESSION['user_id'] ?? null;
$id = intval($_GET['id'] ?? 0);
$stmt = $conn->prepare("SELECT subject, body, created_at FROM saved_emails WHERE id = ? AND user_id = ?");
$stmt->bind_param("ii", $id, $user_id);
$stmt->execute();
$result = $stmt->get_result();
$email = $result->fetch_assoc();
include($_SERVER['DOCUMENT_ROOT'] . '/inc/php/header.php');
?>
<body>
<div class="container">
<?php if ($email): ?>
<h1><?= htmlspecialchars($email['subject'] ?: '(No Subject)') ?></h1>
<p><em>Saved on <?= $email['created_at'] ?></em></p>
<pre><?= htmlspecialchars($email['body']) ?></pre>
<a href="/inc/php/saved.php"><button>⬅ Back</button></a>
<?php else: ?>
<p>Email not found ❌</p>
<?php endif; ?>
</div>
<?php include($_SERVER['DOCUMENT_ROOT'] . '/inc/php/footer.php'); ?>