fetchOne(" SELECT `a`.`id`, `a`.`name`, `a`.`email`, `za`.`activekey` FROM `accounts` AS `a` INNER JOIN `znote_accounts` AS `za` ON `a`.`id` = `za`.`account_id` WHERE `a`.`email` = ? ORDER BY `a`.`id` ASC LIMIT 1; ", [$email]); } elseif ($character) { $account = db()->fetchOne(" SELECT `a`.`id`, `a`.`name`, `a`.`email`, `za`.`activekey` FROM `players` AS `p` INNER JOIN `accounts` AS `a` ON `p`.`account_id` = `a`.`id` INNER JOIN `znote_accounts` AS `za` ON `a`.`id` = `za`.`account_id` WHERE `p`.`name` = ? LIMIT 1; ", [$character]); } if (is_array($account) && !empty($account['email'])) { $recoverylink = $config['site_url'] . '/recovery.php?action=lostaccount_reset&a=' . (int)$account['id'] . '&k=' . (int)$account['activekey']; $mailer = new Mail($config['mailserver']); $title = t('recovery.mail_subject_lostaccount', ['host' => $_SERVER['HTTP_HOST']]); $body = '
' . t('recovery.mail_lostaccount_intro') . '
'; $body .= '' . htmlspecialchars($recoverylink, ENT_QUOTES, 'UTF-8') . '
'; $body .= '' . t('recovery.mail_ignore') . '
'; $body .= '' . t('recovery.mail_noreply') . '
'; $mailer->sendMail((string)$account['email'], $title, $body, (string)$account['name']); } ?>= t('recovery.sent_generic') ?>
= t('recovery.not_automated') ?>
normalizedEngine() === 'TFS_03' && config('salt') === true) { $saltdata = db()->fetchOne( "SELECT `salt` FROM `accounts` WHERE `email` = ? LIMIT 1;", [$email] ); if ($saltdata !== false) $salt .= $saltdata['salt']; } if (znote_server_adapter()->accountIdentityColumn() !== 'id') $candidate = db()->fetchOne( "SELECT `p`.`id` AS `player_id`, `a`.`id` AS `account_id`, `a`.`name`, `a`.`password` FROM `players` `p` INNER JOIN `accounts` `a` ON `p`.`account_id` = `a`.`id` WHERE `p`.`name` = ? AND `a`.`email` = ? LIMIT 1;", [$character, $email] ); else $candidate = db()->fetchOne( "SELECT `p`.`id` AS `player_id`, `a`.`id` AS `account_id`, `a`.`id` AS `name`, `a`.`password` FROM `players` `p` INNER JOIN `accounts` `a` ON `p`.`account_id` = `a`.`id` WHERE `p`.`name` = ? AND `a`.`email` = ? LIMIT 1;", [$character, $email] ); $user = false; if ($candidate !== false && user_verify_login_password((int)$candidate['account_id'], (string)$password, (string)$candidate['password'], $salt)) { $user = $candidate; } if ($user !== false) { // Found user $mailer = new Mail($config['mailserver']); $title = t('recovery.mail_subject_username', ['host' => $_SERVER['HTTP_HOST']]); $body = '' . t('recovery.your_username2') . ' ' . htmlspecialchars((string)$user['name'], ENT_QUOTES, 'UTF-8') . '
';
$body .= t('recovery.mail_enjoy_stay', ['site' => $config['mailserver']['fromName']]) . '
';
$body .= '
= t('recovery.sent_username2') ?> .
= t('recovery.check_junk') ?>
= t('recovery.wrong_data') ?>
normalizedEngine() !== 'TFS_03') { // TFS 0.2 and 1.0 $password = sha1($newpass); } else { // TFS 0.3/4 if (config('salt') === true) { $saltdata = db()->fetchOne( "SELECT `salt` FROM `accounts` WHERE `email` = ? LIMIT 1;", [$email] ); if ($saltdata !== false) $salt .= $saltdata['salt']; } $password = sha1($salt.$newpass); } if (znote_server_adapter()->accountIdentityColumn() !== 'id') $user = db()->fetchOne( "SELECT `p`.`id` AS `player_id`, `a`.`name`, `a`.`id` AS `account_id` FROM `players` `p` INNER JOIN `accounts` `a` ON `p`.`account_id` = `a`.`id` WHERE `p`.`name` = ? AND `a`.`email` = ? AND `a`.`name` = ? LIMIT 1;", [$character, $email, $username] ); else $user = db()->fetchOne( "SELECT `p`.`id` AS `player_id`, `a`.`id` AS `account_id`, `a`.`id` AS `name` FROM `players` `p` INNER JOIN `accounts` `a` ON `p`.`account_id` = `a`.`id` WHERE `p`.`name` = ? AND `a`.`email` = ? AND `a`.`id` = ? LIMIT 1;", [$character, $email, $username] ); if ($user !== false) { // Found user // Give him the new password db()->execute( "UPDATE `accounts` SET `password` = ? WHERE `id` = ? LIMIT 1;", [$password, (int)$user['account_id']] ); user_set_website_password_hash((int)$user['account_id'], (string)$newpass); // Send him a mail with the new password $mailer = new Mail($config['mailserver']); $title = t('recovery.mail_subject_password', ['host' => $_SERVER['HTTP_HOST']]); $body = '' . t('recovery.new_password') . ' ' . htmlspecialchars((string)$newpass, ENT_QUOTES, 'UTF-8') . '
';
$body .= t('recovery.recommend_change_password') . '
';
$body .= t('recovery.mail_enjoy_stay', ['site' => $config['mailserver']['fromName']]) . '
';
$body .= '
= t('recovery.sent_password') ?> .
= t('recovery.check_junk') ?>
= t('recovery.wrong_data') ?>
fetchOne( "SELECT `a`.`id`, `a`.`name`, `a`.`password`, `za`.`activekey` FROM `accounts` AS `a` INNER JOIN `znote_accounts` AS `za` ON `a`.`id` = `za`.`account_id` WHERE `a`.`name` = ? AND `a`.`email` = ? LIMIT 1;", [$username, $email] ); $user = false; if ($candidate !== false && user_verify_login_password((int)$candidate['id'], (string)$password, (string)$candidate['password'])) { $user = $candidate; } if ($user !== false) { // Found user $recoverylink = $config['site_url'] . '/recovery.php?a='.$user['id'].'&k='.$user['activekey']; $mailer = new Mail($config['mailserver']); $title = $config['site_title'] . ': ' . t('recovery.remove_2fa') . ' link'; $body = '' . t('recovery.remove_2fa_confirm_link') . '
';
$body .= '' . htmlspecialchars($recoverylink, ENT_QUOTES, 'UTF-8') . '
';
$body .= t('recovery.mail_enjoy_stay', ['site' => $config['mailserver']['fromName']]) . '
';
$body .= '
= t('recovery.sent_link') ?> .
= t('recovery.click_link') ?> = t('common.2fa') ?>.
= t('recovery.check_junk') ?>
= t('recovery.wrong_data') ?>
fetchOne( "SELECT `a`.`id`, `a`.`name`, `a`.`email` FROM `accounts` AS `a` INNER JOIN `znote_accounts` AS `za` ON `a`.`id` = `za`.`account_id` WHERE `a`.`id` = ? AND `za`.`activekey` = ? LIMIT 1;", [$a, $k] ); if ($account !== false && !empty($account['email'])) { $newpass = substr(sha1(random_bytes(32)), 0, 12); if (znote_server_adapter()->normalizedEngine() === 'TFS_03' && config('salt') === true) { user_change_password03((int)$account['id'], $newpass); } else { user_change_password((int)$account['id'], $newpass); } db()->execute("UPDATE `znote_accounts` SET `activekey` = ? WHERE `account_id` = ? LIMIT 1;", [rand(100000000, 999999999), (int)$account['id']]); $mailer = new Mail($config['mailserver']); $title = t('recovery.mail_subject_recovered', ['host' => $_SERVER['HTTP_HOST']]); $body = '' . t('recovery.your_username2') . ' ' . htmlspecialchars((string)$account['name'], ENT_QUOTES, 'UTF-8') . '
';
$body .= t('recovery.new_password') . ' ' . htmlspecialchars($newpass, ENT_QUOTES, 'UTF-8') . '
' . t('recovery.recommend_change_password_now') . '
'; $body .= '' . t('recovery.mail_noreply') . '
'; $mailer->sendMail((string)$account['email'], $title, $body, (string)$account['name']); ?>= t('recovery.sent_generic') ?>
= t('recovery.cannot_auth') ?>
fetchOne( "SELECT `a`.`id`, `a`.`secret`, `za`.`secret` FROM `accounts` AS `a` INNER JOIN `znote_accounts` AS `za` ON `a`.`id` = `za`.`account_id` WHERE `a`.`id` = ? AND `za`.`activekey` = ? LIMIT 1;", [$a, $k] ); if ($account !== false) { db()->execute("UPDATE `accounts` SET `secret` = NULL WHERE `id` = ? LIMIT 1;", [$a]); db()->execute("UPDATE `znote_accounts` SET `secret` = NULL WHERE `account_id` = ? LIMIT 1;", [$a]); ?>= t('recovery.2fa_disabled_text') ?>
= t('recovery.cannot_auth') ?>
= t('recovery.intro_text') ?>
= t('recovery.can_intro') ?>
= t('recovery.first_step') ?>
= t('recovery.disabled_text2') ?>