johnburn

dologin.php

Dec 14th, 2011
431
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 2.56 KB | None | 0 0
  1. <?php
  2. include ("dbconnect.php");
  3. include ("includes/functions.php");
  4. include ("includes/clientfunctions.php");
  5. $loginsuccess = false;
  6. $username = trim($username);
  7. $password = trim($password);
  8. if (validateClientLogin($username, $password)) {
  9.     $loginsuccess = true;
  10.     if ($rememberme) {
  11.         setcookie("WHMCSUID", $_SESSION['uid'], time() + 60 * 60 * 24 * 365);
  12.         setcookie("WHMCSPW", $_SESSION['upw'], time() + 60 * 60 * 24 * 365);
  13.     }
  14. }
  15. if ($autoauthkey && $hash) {
  16.     $autoauthkey = "";
  17.     require ("configuration.php");
  18.     if ($autoauthkey) {
  19.         if ($timestamp < time() - 15 * 60 || time() < $timestamp) {
  20.             exit("Link expired");
  21.         }
  22.         $hashverify = sha1($email . $timestamp . $autoauthkey);
  23.         if ($hashverify == $hash) {
  24.             $result = select_query("tblclients", "id,password,language", array("email" => $email, "status" => array("sqltype" => "NEQ", "value" => "Closed")));
  25.             $data = mysql_fetch_array($result);
  26.             $login_uid = $data['id'];
  27.             if ($login_uid) {
  28.                 $login_pwd = $data['password'];
  29.                 $language = $data['language'];
  30.                 $fullhost = gethostbyaddr($remote_ip);
  31.                 update_query("tblclients", array("lastlogin" => "now()", "ip" => $remote_ip, "host" => $fullhost), array("id" => $login_uid));
  32.                 $_SESSION['uid'] = $login_uid;
  33.                 $haship = $CONFIG['DisableSessionIPCheck'] ? "" : $remote_ip;
  34.                 $_SESSION['upw'] = md5($login_uid . $login_pwd . $haship);
  35.                 if ($language) {
  36.                     $_SESSION['Language'] = $language;
  37.                 }
  38.                 run_hook("ClientLogin", array("userid" => $login_uid));
  39.                 $loginsuccess = true;
  40.             }
  41.         }
  42.     }
  43. }
  44. $gotourl = "";
  45. if ($goto) {
  46.     $goto = trim($goto);
  47.     if (substr($goto, 0, 7) == "http://" || substr($goto, 0, 8) == "https://") {
  48.         $goto = "";
  49.     }
  50.     $gotourl = html_entity_decode($goto);
  51. } else if (isset($_SESSION['loginurlredirect'])) {
  52.     $gotourl = $_SESSION['loginurlredirect'];
  53.     if (substr($gotourl, 0 - 15) == "&incorrect=true" || substr($gotourl, 0 - 15) == "?incorrect=true") {
  54.         $gotourl = substr($gotourl, 0, strlen($gotourl) - 15);
  55.     }
  56.     unset($_SESSION['loginurlredirect']);
  57. }
  58. if (!$gotourl) {
  59.     $gotourl = "clientarea.php";
  60. }
  61. if (!$loginsuccess) {
  62.     if (strpos($gotourl, "?")) {
  63.         $gotourl.= "&incorrect=true";
  64.     } else {
  65.         $gotourl.= "?incorrect=true";
  66.     }
  67. }
  68. header("Location: {$gotourl}");
  69. exit();
  70. ?>
  71.  
Advertisement
Add Comment
Please, Sign In to add comment