/** * Login user * @return \Phalcon\Http\ResponseInterface */ public function loginAction() { if ($this->request->isPost()) { // if($this->security->checkToken() == false){ // $this->flash->error('<button type="button" class="close" data-dismiss="alert">×</button>Invalid CSRF Token'); // return $this->response->redirect('login'); // } $this->view->disable(); $email = $this->request->getPost('email'); // $_POST $password = $this->request->getPost('password'); if (empty($email) || empty($password)) { $this->flash->warning('<button type="button" class="close" data-dismiss="alert">×</button>All fields required'); return $this->response->redirect(''); } $member = Members::findFirstByEmail($email); if ($member == true && $this->security->checkHash($password, $member->password)) { $emaiConfirmed = EmailConfirmations::findFirst(array('columns' => '*', 'conditions' => 'user_id = ?1 AND email=?2 AND confirmed = ?3', 'bind' => array(1 => $member->id, 2 => $email, 3 => 'Y'))); if (!$emaiConfirmed) { $this->flash->warning('<button type="button" class="close" data-dismiss="alert">×</button>You\'re email is not yet confirmed.'); return $this->response->redirect(''); } $userSession = get_object_vars($member); //$userSession['type'] = 'Member'; $profilePic = MemberPhotos::findFirst(array('member_id="' . $userSession['id'] . '"', 'primary_pic="Yes"')); $userSession['primary_pic'] = $profilePic->file_path . $profilePic->filename; $this->session->set('userSession', $userSession); //member id $cookie_name = "mid"; $cookie_value = $userSession['id']; $date_of_expiry = time() + 60 * 60 * 24 * 90; setcookie($cookie_name, $this->encrypt($cookie_value), $date_of_expiry, "/"); //email $cookie_name = "e"; $cookie_value = $userSession['email']; setcookie($cookie_name, $this->encrypt($cookie_value), $date_of_expiry, "/"); //cookie token $cookie_name = "token"; $cookie_token = substr(md5(uniqid(rand(), true)), 0, 20); setcookie($cookie_name, $this->encrypt($cookie_token), $date_of_expiry, "/"); $member->modified = date('Y-m-d H:i:s'); $member->cookie_token = $this->security->hash($cookie_token); if ($member->update()) { $this->flash->success('<button type="button" class="close" data-dismiss="alert">×</button>You are now logged in.'); $this->response->redirect('biz/page/' . $userSession['id']); } } else { $this->flash->error('<button type="button" class="close" data-dismiss="alert">×</button>Incorrect username or password.'); $this->response->redirect(''); } } }
public function advertiser_emailConfimationAction($userId = null, $email = null, $activationToken = null) { $emaiConfirmed = EmailConfirmations::findFirst(array('columns' => '*', 'conditions' => 'user_id = ?1 AND email=?2 AND token = ?3 AND confirmed = ?4', 'bind' => array(1 => $userId, 2 => $email, 3 => $activationToken, 4 => 'N'))); if ($emaiConfirmed) { $emaiConfirmed->confirmed = 'Y'; $emaiConfirmed->update(); error_log('PASOK Confirmed'); $this->flash->success('<button type="button" class="close" data-dismiss="alert">×</button><H4>You \'re email has been confirmed.</H4>You\'re now officially part of the <strong>MyBarangay</strong> community. Mabuhay!'); //return $this->response->redirect(); } else { //return $this->response->redirect(); } }