30) { $problems[] = 'The account name is required, up to 30 characters.'; }
if ($isOthire) {
if (!preg_match('/^[0-9]+$/', $accountName)) {
$problems[] = 'OTHire account numbers may only contain digits.';
}
} elseif (!preg_match('/^[A-Za-z0-9]+$/', $accountName)) {
$problems[] = 'The account name may only contain letters and numbers. Do not use @ or special characters.';
}
if (strlen($password) < 6) { $problems[] = 'The password must be at least 6 characters.'; }
if (strlen($password) > 29) { $problems[] = 'The password may not be longer than 29 characters.'; }
if ($password !== $password2) { $problems[] = 'The passwords do not match.'; }
if (filter_var($email, FILTER_VALIDATE_EMAIL) === false) { $problems[] = 'A valid e-mail address is required.'; }
if ($character === '' || strlen($character) > 20) { $problems[] = 'The character name is required, up to 20 characters.'; }
if (!preg_match('/^[A-Za-z ]+$/', $character)) { $problems[] = 'The character name may only contain letters and spaces.'; }
if ($problems) {
install_error(implode('
', array_map('ih', $problems)));
} else {
$link = install_connect($connectError);
if ($link === null) {
install_error('Lost the database connection: ' . ih((string)$connectError));
} else {
$esc = static fn(string $v): string => $link->real_escape_string($v);
// Refuse rather than silently attach to someone else's account.
$taken = @$link->query("SELECT `id` FROM `players` WHERE `name` = '" . $esc($character) . "' LIMIT 1");
if ($taken !== false && $taken->num_rows > 0) {
install_error('A character named ' . ih($character) . ' already exists.');
} else {
$now = time();
$hash = sha1($password);
if ($isOthire) {
// OTHire identifies accounts by number, not by name.
$accountId = (int)$accountName;
@$link->query("INSERT INTO `accounts` (`id`, `password`, `email`) VALUES ({$accountId}, '{$hash}', '" . $esc($email) . "')");
} else {
$creation = ($engine === 'TFS_10' || $engine === 'TFS_16' || $engine === 'CANARY')
? ", `creation`" : '';
$creationValue = $creation !== '' ? ", {$now}" : '';
@$link->query("INSERT INTO `accounts` (`name`, `password`, `email`{$creation})
VALUES ('" . $esc($accountName) . "', '{$hash}', '" . $esc($email) . "'{$creationValue})");
$accountId = (int)$link->insert_id;
}
if ($accountId <= 0) {
install_error('Could not create the account: ' . ih($link->error));
} else {
@$link->query("INSERT INTO `znote_accounts` (`account_id`, `ip`, `created`, `points`, `active`, `active_email`, `activekey`, `flag`)
VALUES ({$accountId}, 0, {$now}, 0, 1, 1, 0, '')");
// A level 8 knight with the stock starting stats. The point
// is to have a character whose name grants panel access;
// tune it in game or from Admin Panel > Character Skills.
$ok = @$link->query("INSERT INTO `players`
(`name`, `group_id`, `account_id`, `level`, `vocation`, `health`, `healthmax`,
`experience`, `maglevel`, `mana`, `manamax`, `town_id`, `cap`, `sex`, `looktype`)
VALUES ('" . $esc($character) . "', 1, {$accountId}, 8, 4, 185, 185, 4200, 0, 90, 90, 1, 470, 1, 128)");
if (!$ok) {
install_error('The account was created but the character was not: ' . ih($link->error)
. '
Your server\'s players table may need columns this insert does not set.');
} else {
$playerId = (int)$link->insert_id;
@$link->query("INSERT INTO `znote_players` (`player_id`, `created`, `hide_char`, `comment`)
VALUES ({$playerId}, {$now}, 0, '')");
install_state(array(
'admin_done' => true,
'admin_account' => $accountName,
'admin_character' => $character,
));
install_max_step(6);
$link->close();
header('Location: ' . install_url(6));
exit;
}
}
}
$link->close();
}
}
}
?>
Account = ih(install_get('admin_account')) ?> and character = ih(install_get('admin_character')) ?> were created. The account is given panel access at the next step.
An account to log in with, and a character on it. ZnoteX grants admin rights by account name, so the account name below is what unlocks the panel.