register.php

main 159 lines · 4.8 KB Raw
Alex Alex Commit Initial commit 01/10/2026 09:20
1<?php
2require_once 'engine/init.php';
3logged_in_redirect();
4theme_open();
5require_once('config.countries.php');
6
7if (empty($_POST) === false) {
8 // $_POST['']
9 $required_fields = array('username', 'password', 'password_again', 'email', 'selected');
10 foreach($_POST as $key=>$value) {
11 if (empty($value) && in_array($key, $required_fields) === true) {
12 $errors[] = t('reg.fill_all');
13 break 1;
14 }
15 }
16
17 // check errors (= user exist, pass long enough
18 if (empty($errors) === true) {
19 /* Token used for cross site scripting security */
20 if (!Token::isValid($_POST['token'] ?? null)) {
21 $errors[] = t('login.token_invalid');
22 }
23
24 if ($config['use_captcha']) {
25 if(!verifyGoogleReCaptcha($_POST['g-recaptcha-response'])) {
26 $errors[] = t('reg.captcha');
27 }
28 }
29
30 if (user_exist($_POST['username']) === true) {
31 $errors[] = t('reg.name_taken');
32 }
33
34 // Don't allow "default admin names in config.php" access to register.
35 $isNoob = in_array(strtolower($_POST['username']), $config['page_admin_access']) ? true : false;
36 if ($isNoob) {
37 $errors[] = t('reg.name_blocked');
38 }
39 if ($config['client'] >= 830) {
40 if (preg_match("/^[a-zA-Z0-9]+$/", $_POST['username']) == false) {
41 $errors[] = t('reg.name_chars');
42 }
43 } else {
44 if (preg_match("/^[0-9]+$/", $_POST['username']) == false) {
45 $errors[] = t('reg.name_digits');
46 }
47 if ((int)$_POST['username'] < 100000 || (int)$_POST['username'] > 999999999) {
48 $errors[] = t('reg.name_length_num');
49 }
50 }
51 // name restriction
52 $resname = explode(" ", $_POST['username']);
53 foreach($resname as $res) {
54 if(in_array(strtolower($res), $config['invalidNameTags'])) {
55 $errors[] = t('reg.restricted_word');
56 }
57 else if(strlen($res) == 1) {
58 $errors[] = t('reg.words_too_short');
59 }
60 }
61 if (strlen($_POST['username']) > 32) {
62 $errors[] = t('reg.name_too_long');
63 }
64 // end name restriction
65 if (strlen($_POST['password']) < 6) {
66 $errors[] = t('reg.pw_too_short');
67 }
68 if (strlen($_POST['password']) > 29) {
69 $errors[] = t('reg.pw_too_long');
70 }
71 if ($_POST['password'] !== $_POST['password_again']) {
72 $errors[] = t('reg.pw_mismatch');
73 }
74 if (filter_var($_POST['email'], FILTER_VALIDATE_EMAIL) === false) {
75 $errors[] = t('reg.email_invalid');
76 }
77 if (user_email_exist($_POST['email']) === true) {
78 $errors[] = t('reg.email_taken');
79 }
80 if ($_POST['selected'] != 1) {
81 $errors[] = t('reg.accept_rules');
82 }
83 if ($config['validate_IP'] === true) {
84 if (validate_ip(getIP()) === false) {
85 $errors[] = t('reg.bad_ip');
86 }
87 }
88 if (strlen($_POST['flag']) < 1) {
89 $errors[] = t('reg.choose_country');
90 }
91 }
92}
93
94?>
95<?php view('register_header'); ?>
96<?php
97if (isset($_GET['success']) && empty($_GET['success'])) {
98 view('register_success', ['emailRequired' => (bool)$config['mailserver']['register']]);
99} elseif (isset($_GET['authenticate']) && empty($_GET['authenticate'])) {
100 // Authenticate user, fetch user id and activation key
101 $auid = (isset($_GET['u']) && (int)$_GET['u'] > 0) ? (int)$_GET['u'] : false;
102 $akey = (isset($_GET['k']) && (int)$_GET['k'] > 0) ? (int)$_GET['k'] : false;
103 // Find a match
104 $user = db()->fetchOne("SELECT `id`, `active`, `active_email` FROM `znote_accounts` WHERE `account_id` = ? AND `activekey` = ? LIMIT 1;", [$auid, $akey]);
105 if ($user !== false) {
106 $userId = (int) $user['id'];
107 $active = (int) $user['active'];
108 $active_email = (int) $user['active_email'];
109 // Enable the account to login
110 if ($active == 0 || $active_email == 0) {
111 db()->execute("UPDATE `znote_accounts` SET `active` = '1', `active_email` = '1' WHERE `id` = ? LIMIT 1;", [$userId]);
112 }
113 view('register_authenticate_result', ['ok' => true]);
114 } else {
115 view('register_authenticate_result', ['ok' => false]);
116 }
117} else {
118 if (empty($_POST) === false && empty($errors) === true) {
119 if ($config['log_ip']) {
120 znote_visitor_insert_detailed_data(1);
121 }
122
123 //Register
124 $register_data = array(
125 'name' => $_POST['username'],
126 'password' => $_POST['password'],
127 'email' => $_POST['email'],
128 'created' => time(),
129 'ip' => getIPLong(),
130 'flag' => $_POST['flag']
131 );
132
133 $accountId = user_create_account($register_data, $config['mailserver']);
134
135 $createPremiumDays = max(0, min(999, (int)($config['account_create_premdays'] ?? 0)));
136 if ($accountId > 0 && $createPremiumDays > 0) {
137 user_account_add_premdays($accountId, $createPremiumDays);
138 }
139
140 // Plugins can react to a new account: a welcome bonus, a webhook, an
141 // entry in a referral ledger.
142 znote_hook('account.registered', array(
143 'name' => $register_data['name'] ?? '',
144 'email' => $register_data['email'] ?? '',
145 ));
146 if (!$config['mailserver']['debug']) header('Location: register.php?success');
147 exit();
148 //End register
149
150 } else if (empty($errors) === false){
151 echo '<font color="red"><b>';
152 echo output_errors($errors);
153 echo '</b></font>';
154 }
155 view('register_form');
156}
157theme_close();
158?>
159
Top