Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <?php
- include ("dbconnect.php");
- include ("includes/functions.php");
- include ("includes/clientfunctions.php");
- $loginsuccess = false;
- $username = trim($username);
- $password = trim($password);
- if (validateClientLogin($username, $password)) {
- $loginsuccess = true;
- if ($rememberme) {
- setcookie("WHMCSUID", $_SESSION['uid'], time() + 60 * 60 * 24 * 365);
- setcookie("WHMCSPW", $_SESSION['upw'], time() + 60 * 60 * 24 * 365);
- }
- }
- if ($autoauthkey && $hash) {
- $autoauthkey = "";
- require ("configuration.php");
- if ($autoauthkey) {
- if ($timestamp < time() - 15 * 60 || time() < $timestamp) {
- exit("Link expired");
- }
- $hashverify = sha1($email . $timestamp . $autoauthkey);
- if ($hashverify == $hash) {
- $result = select_query("tblclients", "id,password,language", array("email" => $email, "status" => array("sqltype" => "NEQ", "value" => "Closed")));
- $data = mysql_fetch_array($result);
- $login_uid = $data['id'];
- if ($login_uid) {
- $login_pwd = $data['password'];
- $language = $data['language'];
- $fullhost = gethostbyaddr($remote_ip);
- update_query("tblclients", array("lastlogin" => "now()", "ip" => $remote_ip, "host" => $fullhost), array("id" => $login_uid));
- $_SESSION['uid'] = $login_uid;
- $haship = $CONFIG['DisableSessionIPCheck'] ? "" : $remote_ip;
- $_SESSION['upw'] = md5($login_uid . $login_pwd . $haship);
- if ($language) {
- $_SESSION['Language'] = $language;
- }
- run_hook("ClientLogin", array("userid" => $login_uid));
- $loginsuccess = true;
- }
- }
- }
- }
- $gotourl = "";
- if ($goto) {
- $goto = trim($goto);
- if (substr($goto, 0, 7) == "http://" || substr($goto, 0, 8) == "https://") {
- $goto = "";
- }
- $gotourl = html_entity_decode($goto);
- } else if (isset($_SESSION['loginurlredirect'])) {
- $gotourl = $_SESSION['loginurlredirect'];
- if (substr($gotourl, 0 - 15) == "&incorrect=true" || substr($gotourl, 0 - 15) == "?incorrect=true") {
- $gotourl = substr($gotourl, 0, strlen($gotourl) - 15);
- }
- unset($_SESSION['loginurlredirect']);
- }
- if (!$gotourl) {
- $gotourl = "clientarea.php";
- }
- if (!$loginsuccess) {
- if (strpos($gotourl, "?")) {
- $gotourl.= "&incorrect=true";
- } else {
- $gotourl.= "?incorrect=true";
- }
- }
- header("Location: {$gotourl}");
- exit();
- ?>
Advertisement
Add Comment
Please, Sign In to add comment