e949/api/user/index.php

169 lines
3.5 KiB
PHP
Raw Normal View History

<?php
// Viewing account data
2023-08-12 01:39:17 +03:00
// Includes
2023-12-20 06:08:13 +03:00
if ($IS_FRONTEND) {
require_once("api/_auth.php");
require_once("api/_utils.php");
require_once("api/_errorslist.php");
require_once("api/_types.php");
} else {
require_once("../_auth.php");
require_once("../_utils.php");
require_once("../_errorslist.php");
require_once("../_types.php");
}
2023-08-12 01:39:17 +03:00
// Functions
/*
* FUNCTION
* Check if user with supplied login exists
*/
2023-12-20 06:08:13 +03:00
function User_LoginExist (string $login): bool {
2023-08-19 21:15:47 +03:00
global $db;
$s = $db->prepare("SELECT * FROM users WHERE login = ?");
$s->bind_param("s", $login);
$s->execute();
return (bool)$s->get_result()->fetch_assoc();
}
/*
* FUNCTION
* Check if user with supplied ID exists
*/
2023-12-20 06:08:13 +03:00
function User_IDExist (int $id): bool {
global $db;
$s = $db->prepare("SELECT * FROM users WHERE id = ?");
$s->bind_param("s", $id);
$s->execute();
return (bool)$s->get_result()->fetch_assoc();
}
/*
* FUNCTION
* Check if user has specified role
*/
2023-12-20 06:08:13 +03:00
function User_HasRole (int $id, string $role): ReturnT {
global $db;
$s = $db->prepare("SELECT * FROM users WHERE id = ?");
$s->bind_param("s", $id);
$s->execute();
$d = $s->get_result()->fetch_assoc();
if (!(bool)$d)
return new ReturnT(err_code: E_UIN_WRONGID, err_desc: "user not found in database");
2023-08-30 04:41:13 +03:00
return new ReturnT(data: $d["role"] === $role);
}
/*
* FUNCTION
* Check if user is moderator (or higher)
*/
2023-12-20 06:08:13 +03:00
function User_IsMod (int $id): ReturnT {
global $db;
$s = $db->prepare("SELECT * FROM users WHERE id = ?");
$s->bind_param("s", $id);
$s->execute();
$d = $s->get_result()->fetch_assoc();
if (!(bool)$d)
return new ReturnT(err_code: E_UIN_WRONGID, err_desc: "user not found in database");
return new ReturnT(data: in_array($d["role"], array("mod", "admin")));
}
/*
* FUNCTION
* Get user information from DB
*/
function User_GetInfoByID (int $id): ReturnT {
global $db, $THIS_USER, $LOGGED_IN;
$result = array();
$s = $db->prepare("SELECT * FROM users WHERE id = ?");
$s->bind_param("s", $id);
$s->execute();
$d = $s->get_result()->fetch_assoc();
if (!(bool)$d)
return new ReturnT(err_code: E_UIN_WRONGID, err_desc: "user not found in database");
$result["id"] = $d["id"];
$result["created_at"] = $d["created_at"];
$result["login"] = $d["login"];
$result["avatar_path"] = $d["avatar_path"];
$result["role"] = $d["role"];
$result["banned"] = $d["banned"];
// User himself and mods can see additional info
if ($id === $THIS_USER) {
$result["email"] = $d["email"];
$result["invite_id"] = $d["invite_id"];
} elseif ($LOGGED_IN) {
if (User_IsMod($THIS_USER)->GetData()) {
$result["email"] = $d["email"];
$result["invite_id"] = $d["invite_id"];
}
}
return new ReturnT(data: $result);
}
// Methods
/*
* METHOD
* Get user information from DB
*/
function User_GetInfoByID_Method (array $req): ReturnT {
2023-12-20 06:08:13 +03:00
global $THIS_USER, $LOGGED_IN;
// Input sanity checks
$UserID = null;
if (isset($req["id"])) {
if (!ctype_digit($req["id"]))
return new ReturnT(err_code: E_UIN_BADARGS, err_desc: "id must be numeric");
$UserID = intval($req["id"]);
} else {
if ($LOGGED_IN)
$UserID = $THIS_USER;
else
2023-12-20 06:08:13 +03:00
return new ReturnT(err_code: E_UIN_INSUFARGS, err_desc: "id must be specified or valid session must be provided");
}
// Actions
return User_GetInfoByID($UserID);
}
if (Utils_ThisFileIsRequested(__FILE__)) {
2023-08-19 21:15:47 +03:00
require_once("../_json.php");
$result = User_GetInfoByID_Method($_REQUEST);
if ($result->IsError())
$result->ThrowJSONError();
else
JSON_ReturnData($result->GetData());
2023-08-12 01:39:17 +03:00
}
2023-08-12 01:39:17 +03:00
?>