mirror of
				https://github.com/slawkens/myaac.git
				synced 2025-10-31 16:06:24 +01:00 
			
		
		
		
	Compare commits
	
		
			20 Commits
		
	
	
		
			develop
			...
			feature/re
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
|   | 6500c29799 | ||
|   | 456b68a88b | ||
|   | 596dde4077 | ||
|   | ac9303402d | ||
|   | 523210c5b7 | ||
|   | 29e2484ad5 | ||
|   | 9ae07acfc1 | ||
|   | dc6b60d0b6 | ||
|   | 05b5e703ed | ||
|   | 849944ff20 | ||
|   | 413ad42afa | ||
|   | 233bf001ce | ||
|   | d2f1f41576 | ||
|   | 2f9ae38c19 | ||
|   | b1b536ce68 | ||
|   | 25695a039d | ||
|   | e27d974c46 | ||
|   | 67f54eacbc | ||
|   | cde8891b9b | ||
|   | 50a8b8169f | 
| @@ -1,4 +0,0 @@ | ||||
| ## [2.0-alpha - x.x.2025] | ||||
|  | ||||
| ### Changed | ||||
| * Reworked account action logs to use single IP column as varchar(45) for both ipv4 and ipv6 (https://github.com/slawkens/myaac/pull/289) | ||||
| @@ -9,7 +9,6 @@ | ||||
|  */ | ||||
|  | ||||
| use MyAAC\Models\Account as AccountModel; | ||||
| use MyAAC\Models\AccountAction; | ||||
| use MyAAC\Models\Player; | ||||
|  | ||||
| defined('MYAAC') or die('Direct access not allowed!'); | ||||
| @@ -482,8 +481,9 @@ else if (isset($_REQUEST['search'])) { | ||||
| 									</thead> | ||||
| 									<tbody> | ||||
| 										<?php | ||||
| 											$accountActions = AccountAction::where('account_id', $account->getId())->orderByDesc('date')->get(); | ||||
| 											$accountActions = \MyAAC\Models\AccountAction::where('account_id', $account->getId())->orderByDesc('date')->get(); | ||||
| 											foreach ($accountActions as $i => $log): | ||||
| 												$log->ip = ($log->ip != 0 ? long2ip($log->ip) : inet_ntop($log->ipv6)); | ||||
| 												?> | ||||
| 											<tr> | ||||
| 												<td><?php echo $i + 1; ?></td> | ||||
|   | ||||
| @@ -26,8 +26,8 @@ | ||||
| if (version_compare(phpversion(), '8.1', '<')) die('PHP version 8.1 or higher is required.'); | ||||
|  | ||||
| const MYAAC = true; | ||||
| const MYAAC_VERSION = '2.0-dev'; | ||||
| const DATABASE_VERSION = 47; | ||||
| const MYAAC_VERSION = '1.8.5-dev'; | ||||
| const DATABASE_VERSION = 46; | ||||
| const TABLE_PREFIX = 'myaac_'; | ||||
| define('START_TIME', microtime(true)); | ||||
| define('MYAAC_OS', stripos(PHP_OS, 'WIN') === 0 ? 'WINDOWS' : (strtoupper(PHP_OS) === 'DARWIN' ? 'MAC' : 'LINUX')); | ||||
|   | ||||
| @@ -1,11 +1,11 @@ | ||||
| CREATE TABLE IF NOT EXISTS `myaac_account_actions` | ||||
| ( | ||||
| 	`id` int NOT NULL AUTO_INCREMENT, | ||||
| 	`account_id` int NOT NULL, | ||||
| 	`ip` varchar(45) NOT NULL DEFAULT '', | ||||
| 	`ip` int unsigned NOT NULL DEFAULT 0, | ||||
| 	`ipv6` binary(16) NOT NULL DEFAULT 0, | ||||
| 	`date` int NOT NULL DEFAULT 0, | ||||
| 	`action` varchar(255) NOT NULL DEFAULT '', | ||||
| 	PRIMARY KEY (`id`) | ||||
| 	KEY (`account_id`) | ||||
| ) ENGINE=InnoDB DEFAULT CHARACTER SET=utf8mb4; | ||||
|  | ||||
| CREATE TABLE IF NOT EXISTS `myaac_account_emails_verify` | ||||
|   | ||||
| @@ -12,8 +12,6 @@ | ||||
|  * @license http://www.gnu.org/licenses/lgpl-3.0.txt GNU Lesser General Public License, Version 3 | ||||
|  */ | ||||
|  | ||||
| use MyAAC\Models\AccountAction; | ||||
|  | ||||
| /** | ||||
|  * OTServ account abstraction. | ||||
|  * | ||||
| @@ -1009,16 +1007,26 @@ class OTS_Account extends OTS_Row_DAO implements IteratorAggregate, Countable | ||||
|  | ||||
| 	public function logAction($action) | ||||
| 	{ | ||||
| 		AccountAction::create([ | ||||
| 			'account_id' => $this->getId(), | ||||
| 			'ip' => get_browser_real_ip(), | ||||
| 			'date' => time(), | ||||
| 			'action' => $action, | ||||
| 		]); | ||||
| 		$ip = get_browser_real_ip(); | ||||
| 		if(!str_contains($ip, ":")) { | ||||
| 			$ipv6 = '0'; | ||||
| 		} | ||||
| 		else { | ||||
| 			$ipv6 = $ip; | ||||
| 			$ip = ''; | ||||
| 		} | ||||
|  | ||||
| 		return $this->db->exec('INSERT INTO `' . TABLE_PREFIX . 'account_actions` (`account_id`, `ip`, `ipv6`, `date`, `action`) VALUES (' . $this->db->quote($this->getId()).', ' . ($ip == '' ? '0' : $this->db->quote(ip2long($ip))) . ', (' . ($ipv6 == '0' ? $this->db->quote('') : $this->db->quote(inet_pton($ipv6))) . '), UNIX_TIMESTAMP(NOW()), ' . $this->db->quote($action).')'); | ||||
| 	} | ||||
|  | ||||
| 	public function getActionsLog($limit) { | ||||
| 		return AccountAction::where('account_id', $this->data['id'])->orderByDesc('date')->limit($limit)->get()->toArray(); | ||||
| 	public function getActionsLog($limit1, $limit2) | ||||
| 	{ | ||||
| 		$actions = array(); | ||||
|  | ||||
| 		foreach($this->db->query('SELECT `ip`, `ipv6`, `date`, `action` FROM `' . TABLE_PREFIX . 'account_actions` WHERE `account_id` = ' . $this->data['id'] . ' ORDER by `date` DESC LIMIT ' . $limit1 . ', ' . $limit2 . '')->fetchAll() as $a) | ||||
| 			$actions[] = array('ip' => $a['ip'], 'ipv6' => $a['ipv6'], 'date' => $a['date'], 'action' => $a['action']); | ||||
|  | ||||
| 		return $actions; | ||||
| 	} | ||||
| /** | ||||
|  * Returns players iterator. | ||||
|   | ||||
| @@ -277,7 +277,6 @@ class OTS_DB_MySQL extends OTS_Base_DB | ||||
| 				'field' => $result['Field'], | ||||
| 				'type' => $result['Type'], | ||||
| 				'null' => strtolower($result['Null']), | ||||
| 				'key' => strtolower($result['Key'] ?? ''), | ||||
| 				'default' => $result['Default'], | ||||
| 				'extra' => $result['Extra'], | ||||
| 			]; | ||||
|   | ||||
| @@ -1,42 +0,0 @@ | ||||
| <?php | ||||
| /** | ||||
|  * @var OTS_DB_MySQL $db | ||||
|  */ | ||||
|  | ||||
| // 2025-02-27 | ||||
| // remove ipv6, change to ip (for both ipv4 + ipv6) as VARCHAR(45) | ||||
| $up = function () use ($db) { | ||||
| 	$accountActionsInfo = $db->getColumnInfo(TABLE_PREFIX . 'account_actions', 'account_id'); | ||||
| 	if ($accountActionsInfo && is_array($accountActionsInfo) && $accountActionsInfo['key'] == 'pri') { | ||||
| 		$db->query("ALTER TABLE `myaac_account_actions` DROP KEY `account_id`;"); | ||||
| 	} | ||||
|  | ||||
| 	if (!$db->hasColumn(TABLE_PREFIX . 'account_actions', 'id')) { | ||||
| 		$db->addColumn(TABLE_PREFIX . 'account_actions', 'id', 'INT NOT NULL AUTO_INCREMENT FIRST, ADD PRIMARY KEY (`id`)'); | ||||
| 	} | ||||
|  | ||||
| 	$db->modifyColumn(TABLE_PREFIX . 'account_actions', 'ip', "VARCHAR(45) NOT NULL DEFAULT ''"); | ||||
| 	$db->query("UPDATE `" . TABLE_PREFIX . "account_actions` SET `ip` = INET_NTOA(`ip`) WHERE `ip` != '0';"); | ||||
| 	$db->query("UPDATE `" . TABLE_PREFIX . "account_actions` SET `ip` = INET6_NTOA(`ipv6`) WHERE `ip` = '0';"); | ||||
|  | ||||
| 	if ($db->hasColumn(TABLE_PREFIX . 'account_actions', 'ipv6')) { | ||||
| 		$db->dropColumn(TABLE_PREFIX . 'account_actions', 'ipv6'); | ||||
| 	} | ||||
| }; | ||||
|  | ||||
| $down = function () use ($db) { | ||||
| 	if ($db->hasColumn(TABLE_PREFIX . 'account_actions', 'id')) { | ||||
| 		$db->query("ALTER TABLE `" . TABLE_PREFIX . "account_actions` DROP `id`;"); | ||||
| 	} | ||||
|  | ||||
| 	$db->query("ALTER TABLE  `" . TABLE_PREFIX . "account_actions` ADD KEY (`account_id`);"); | ||||
|  | ||||
| 	if (!$db->hasColumn(TABLE_PREFIX . 'account_actions', 'ipv6')) { | ||||
| 		$db->addColumn(TABLE_PREFIX . 'account_actions', 'ipv6', "BINARY(16) NOT NULL DEFAULT 0x00000000000000000000000000000000 AFTER ip"); | ||||
| 	} | ||||
|  | ||||
| 	$db->query("UPDATE `" . TABLE_PREFIX . "account_actions` SET `ipv6` = INET6_ATON(ip) WHERE NOT IS_IPV4(`ip`);"); | ||||
| 	$db->query("UPDATE `" . TABLE_PREFIX . "account_actions` SET `ip` = INET_ATON(`ip`) WHERE IS_IPV4(`ip`);"); | ||||
| 	$db->query("UPDATE `" . TABLE_PREFIX . "account_actions` SET `ip` = 0 WHERE `ipv6` != 0x00000000000000000000000000000000;"); | ||||
| 	$db->modifyColumn(TABLE_PREFIX . 'account_actions', 'ip', "INT(11) UNSIGNED NOT NULL DEFAULT 0;"); | ||||
| }; | ||||
| @@ -9,540 +9,11 @@ | ||||
|  * @link      https://my-aac.org | ||||
|  */ | ||||
| defined('MYAAC') or die('Direct access not allowed!'); | ||||
| $title = 'Lost Account Interface'; | ||||
| $title = 'Lost Account'; | ||||
|  | ||||
| if(!setting('core.mail_enabled')) | ||||
| { | ||||
| 	echo '<b>Account maker is not configured to send e-mails, you can\'t use Lost Account Interface. Contact with admin to get help.</b>'; | ||||
| if(!setting('core.mail_enabled')) { | ||||
| 	echo "<b>Account maker is not configured to send e-mails, you can't use Lost Account Interface. Contact with admin to get help.</b>"; | ||||
| 	return; | ||||
| } | ||||
|  | ||||
| $action_type = isset($_REQUEST['action_type']) ? $_REQUEST['action_type'] : ''; | ||||
| if($action == '') | ||||
| { | ||||
| 	$twig->display('account.lost.form.html.twig'); | ||||
| } | ||||
| else if($action == 'step1' && $action_type == '') { | ||||
| 	$twig->display('account.lost.noaction.html.twig'); | ||||
| } | ||||
| elseif($action == 'step1' && $action_type == 'email') | ||||
| { | ||||
| 	$nick = stripslashes($_REQUEST['nick']); | ||||
| 	if(Validator::characterName($nick)) | ||||
| 	{ | ||||
| 		$player = new OTS_Player(); | ||||
| 		$account = new OTS_Account(); | ||||
| 		$player->find($nick); | ||||
| 		if($player->isLoaded()) | ||||
| 			$account = $player->getAccount(); | ||||
|  | ||||
| 		if($account->isLoaded()) | ||||
| 		{ | ||||
| 			if($account->getCustomField('email_next') < time()) | ||||
| 				echo 'Please enter e-mail to account with this character.<BR> | ||||
| 				<form action="' . getLink('account/lost') . '?action=sendcode" method=post> | ||||
| 				<input type=hidden name="character"> | ||||
| 				<table cellspacing=1 cellpadding=4 border=0 width=100%> | ||||
| 				<TR><TD BGCOLOR="'.$config['vdarkborder'].'" class="white"><B>Please enter e-mail to account</B></TD></TR> | ||||
| 				<TR><TD BGCOLOR="'.$config['darkborder'].'"> | ||||
| 				Character: <INPUT TYPE=text NAME="nick" VALUE="'.$nick.'" SIZE="40" readonly="readonly"><BR> | ||||
| 				E-mail to account:<INPUT TYPE=text NAME="email" VALUE="" SIZE="40"><BR> | ||||
| 				</TD></TR> | ||||
| 				</TABLE> | ||||
| 				<BR> | ||||
| 				<TABLE CELLSPACING=0 CELLPADDING=0 BORDER=0 WIDTH=100%><TR><TD><div style="text-align:center"> | ||||
| 				' . $twig->render('buttons.submit.html.twig') . '</div> | ||||
| 				</TD></TR></FORM></TABLE></TABLE>'; | ||||
| 			else | ||||
| 			{ | ||||
| 				$insec = (int)$account->getCustomField('email_next') - time(); | ||||
| 				$minutesleft = floor($insec / 60); | ||||
| 				$secondsleft = $insec - ($minutesleft * 60); | ||||
| 				$timeleft = $minutesleft.' minutes '.$secondsleft.' seconds'; | ||||
| 				echo 'Account of selected character (<b>'.$nick.'</b>) received e-mail in last '.ceil(setting('core.mail_lost_account_interval') / 60).' minutes. You must wait '.$timeleft.' before you can use Lost Account Interface again.'; | ||||
| 			} | ||||
| 		} | ||||
| 		else | ||||
| 			echo 'Player or account of player <b>' . $nick . '</b> doesn\'t exist.'; | ||||
| 	} | ||||
| 	else | ||||
| 		echo 'Invalid player name format. If you have other characters on account try with other name.'; | ||||
| 	echo '<BR /><TABLE CELLSPACING=0 CELLPADDING=0 BORDER=0 WIDTH=100%><TR><TD><div style="text-align:center"> | ||||
| 				<a href="' . getLink('account/lost') . '" border="0"><IMG SRC="'.$template_path.'/images/global/buttons/sbutton_back.gif" NAME="Back" ALT="Back" BORDER=0 WIDTH=120 HEIGHT=18></a></div> | ||||
| 				</TD></TR></FORM></TABLE></TABLE>'; | ||||
| } | ||||
| elseif($action == 'sendcode') | ||||
| { | ||||
| 	$email = $_REQUEST['email']; | ||||
| 	$nick = stripslashes($_REQUEST['nick']); | ||||
| 	if(Validator::characterName($nick)) | ||||
| 	{ | ||||
| 		$player = new OTS_Player(); | ||||
| 		$account = new OTS_Account(); | ||||
| 		$player->find($nick); | ||||
| 		if($player->isLoaded()) | ||||
| 			$account = $player->getAccount(); | ||||
|  | ||||
| 		if($account->isLoaded()) | ||||
| 		{ | ||||
| 			if($account->getCustomField('email_next') < time()) | ||||
| 			{ | ||||
| 				if($account->getEMail() == $email) | ||||
| 				{ | ||||
| 					$newcode = generateRandomString(30, true, false, true); | ||||
| 					$mailBody = ' | ||||
| 					You asked to reset your ' . $config['lua']['serverName'] . ' password.<br/> | ||||
| 					<p>Account name: '.$account->getName().'</p> | ||||
| 					<br /> | ||||
| 					To do so, please click this link: | ||||
| 					<p><a href="' . getLink('account/lost') . '?action=checkcode&code='.$newcode.'&character='.urlencode($nick).'">' . getLink('account/lost') . '?action=checkcode&code='.$newcode.'&character='.urlencode($nick).'</a></p> | ||||
| 					<p>or open page: <i>' . getLink('account/lost') . '?action=checkcode</i> and in field "code" write <b>'.$newcode.'</b></p> | ||||
| 					<br/> | ||||
| 						<p>If you did not request a password change, you may ignore this message and your password will remain unchanged.'; | ||||
|  | ||||
| 					$account_mail = $account->getCustomField('email'); | ||||
| 					if(_mail($account_mail, $config['lua']['serverName'].' - Recover your account', $mailBody)) | ||||
| 					{ | ||||
| 						$account->setCustomField('email_code', $newcode); | ||||
| 						$account->setCustomField('email_next', (time() + setting('core.mail_lost_account_interval'))); | ||||
| 						echo '<br />Details about steps required to recover your account has been sent to <b>' . $account_mail . '</b>. You should receive this email within 15 minutes. Please check your inbox/spam directory.'; | ||||
| 					} | ||||
| 					else | ||||
| 					{ | ||||
| 						$account->setCustomField('email_next', (time() + 60)); | ||||
| 						echo '<br /><p class="error">An error occurred while sending email! Try again later or contact with admin. For Admin: More info can be found in system/logs/mailer-error.log</p>'; | ||||
| 					} | ||||
| 				} | ||||
| 				else | ||||
| 					echo 'Invalid e-mail to account of character <b>'.$nick.'</b>. Try again.'; | ||||
| 			} | ||||
| 			else | ||||
| 			{ | ||||
| 				$insec = (int)$account->getCustomField('email_next') - time(); | ||||
| 				$minutesleft = floor($insec / 60); | ||||
| 				$secondsleft = $insec - ($minutesleft * 60); | ||||
| 				$timeleft = $minutesleft.' minutes '.$secondsleft.' seconds'; | ||||
| 				echo 'Account of selected character (<b>'.$nick.'</b>) received e-mail in last '.ceil(setting('core.mail_lost_account_interval') / 60).' minutes. You must wait '.$timeleft.' before you can use Lost Account Interface again.'; | ||||
| 			} | ||||
| 		} | ||||
| 		else | ||||
| 			echo 'Player or account of player <b>'.$nick.'</b> doesn\'t exist.'; | ||||
| 	} | ||||
| 	else | ||||
| 		echo 'Invalid player name format. If you have other characters on account try with other name.'; | ||||
| 	echo '<BR /><TABLE CELLSPACING=0 CELLPADDING=0 BORDER=0 WIDTH=100%><TR><TD><div style="text-align:center"> | ||||
| 				<a href="' . getLink('account/lost') . '?action=step1&action_type=email&nick='.urlencode($nick).'" border="0"><IMG SRC="'.$template_path.'/images/global/buttons/sbutton_back.gif" NAME="Back" ALT="Back" BORDER=0 WIDTH=120 HEIGHT=18></a></div> | ||||
| 				</TD></TR></FORM></TABLE></TABLE>'; | ||||
| } | ||||
| elseif($action == 'step1' && $action_type == 'reckey') | ||||
| { | ||||
| 	$nick = stripslashes($_REQUEST['nick']); | ||||
| 	if(Validator::characterName($nick)) | ||||
| 	{ | ||||
| 		$player = new OTS_Player(); | ||||
| 		$account = new OTS_Account(); | ||||
| 		$player->find($nick); | ||||
| 		if($player->isLoaded()) | ||||
| 			$account = $player->getAccount(); | ||||
| 		if($account->isLoaded()) | ||||
| 		{ | ||||
| 			$account_key = $account->getCustomField('key'); | ||||
| 			if(!empty($account_key)) | ||||
| 			{ | ||||
| 						echo 'If you enter right recovery key you will see form to set new e-mail and password to account. To this e-mail will be send your new password and account name.<BR> | ||||
| 						<FORM ACTION="' . getLink('account/lost') . '?action=step2" METHOD=post> | ||||
| 						<TABLE CELLSPACING=1 CELLPADDING=4 BORDER=0 WIDTH=100%> | ||||
| 						<TR><TD BGCOLOR="'.$config['vdarkborder'].'" class="white"><B>Please enter your recovery key</B></TD></TR> | ||||
| 						<TR><TD BGCOLOR="'.$config['darkborder'].'"> | ||||
| 						Character name: <INPUT TYPE=text NAME="nick" VALUE="'.$nick.'" SIZE="40" readonly="readonly"><BR /> | ||||
| 						Recovery key:    <INPUT TYPE=text NAME="key" VALUE="" SIZE="40"><BR> | ||||
| 						</TD></TR> | ||||
| 						</TABLE> | ||||
| 						<BR> | ||||
| 						<TABLE CELLSPACING=0 CELLPADDING=0 BORDER=0 WIDTH=100%><TR><TD><div style="text-align:center"> | ||||
| 						' . $twig->render('buttons.submit.html.twig') . '</div> | ||||
| 						</TD></TR></FORM></TABLE></TABLE>'; | ||||
| 			} | ||||
| 			else | ||||
| 				echo 'Account of this character has no recovery key!'; | ||||
| 		} | ||||
| 		else | ||||
| 			echo 'Player or account of player <b>'.$nick.'</b> doesn\'t exist.'; | ||||
| 	} | ||||
| 	else | ||||
| 		echo 'Invalid player name format. If you have other characters on account try with other name.'; | ||||
| 	echo '<BR /><TABLE CELLSPACING=0 CELLPADDING=0 BORDER=0 WIDTH=100%><TR><TD><div style="text-align:center"> | ||||
| 				<a href="' . getLink('account/lost') . '" border="0"><IMG SRC="'.$template_path.'/images/global/buttons/sbutton_back.gif" NAME="Back" ALT="Back" BORDER=0 WIDTH=120 HEIGHT=18></a></div> | ||||
| 				</TD></TR></FORM></TABLE></TABLE>'; | ||||
| } | ||||
| elseif($action == 'step2') | ||||
| { | ||||
| 	$rec_key = trim($_REQUEST['key']); | ||||
| 	$nick = stripslashes($_REQUEST['nick']); | ||||
| 	if(Validator::characterName($nick)) | ||||
| 	{ | ||||
| 		$player = new OTS_Player(); | ||||
| 		$account = new OTS_Account(); | ||||
| 		$player->find($nick); | ||||
| 		if($player->isLoaded()) | ||||
| 			$account = $player->getAccount(); | ||||
| 		if($account->isLoaded()) | ||||
| 		{ | ||||
| 			$account_key = $account->getCustomField('key'); | ||||
| 			if(!empty($account_key)) | ||||
| 			{ | ||||
| 				if($account_key == $rec_key) | ||||
| 				{ | ||||
| 					echo '<script type="text/javascript"> | ||||
| 					function validate_required(field,alerttxt) | ||||
| 					{ | ||||
| 					with (field) | ||||
| 					{ | ||||
| 					if (value==null||value==""||value==" ") | ||||
| 					  {alert(alerttxt);return false;} | ||||
| 					else {return true} | ||||
| 					} | ||||
| 					} | ||||
| 					function validate_email(field,alerttxt) | ||||
| 					{ | ||||
| 					with (field) | ||||
| 					{ | ||||
| 					apos=value.indexOf("@"); | ||||
| 					dotpos=value.lastIndexOf("."); | ||||
| 					if (apos<1||dotpos-apos<2) | ||||
| 					  {alert(alerttxt);return false;} | ||||
| 					else {return true;} | ||||
| 					} | ||||
| 					} | ||||
| 					function validate_form(thisform) | ||||
| 					{ | ||||
| 					with (thisform) | ||||
| 					{ | ||||
| 					if (validate_required(email,"Please enter your e-mail!")==false) | ||||
| 					  {email.focus();return false;} | ||||
| 					if (validate_email(email,"Invalid e-mail format!")==false) | ||||
| 					  {email.focus();return false;} | ||||
| 					if (validate_required(passor,"Please enter password!")==false) | ||||
| 					  {passor.focus();return false;} | ||||
| 					if (validate_required(passor2,"Please repeat password!")==false) | ||||
| 					  {passor2.focus();return false;} | ||||
| 					if (passor2.value!=passor.value) | ||||
| 					  {alert(\'Repeated password is not equal to password!\');return false;} | ||||
| 					} | ||||
| 					} | ||||
| 					</script>'; | ||||
| 					echo 'Set new password and e-mail to your account.<BR> | ||||
| 					<FORM ACTION="' . getLink('account/lost') . '?action=step3" onsubmit="return validate_form(this)" METHOD=post> | ||||
| 					<INPUT TYPE=hidden NAME="character" VALUE=""> | ||||
| 					<TABLE CELLSPACING=1 CELLPADDING=4 BORDER=0 WIDTH=100%> | ||||
| 					<TR><TD BGCOLOR="'.$config['vdarkborder'].'" class="white"><B>Please enter new password and e-mail</B></TD></TR> | ||||
| 					<TR><TD BGCOLOR="'.$config['darkborder'].'"> | ||||
| 					Account of character:  <INPUT TYPE=text NAME="nick" VALUE="'.$nick.'" SIZE="40" readonly="readonly"><BR /> | ||||
| 					New password:            <INPUT id="passor" TYPE=password NAME="passor" VALUE="" SIZE="40"><BR> | ||||
| 					Repeat new password:  <INPUT id="passor2" TYPE=password NAME="passor" VALUE="" SIZE="40"><BR> | ||||
| 					New e-mail address:     <INPUT id="email" TYPE=text NAME="email" VALUE="" SIZE="40"><BR> | ||||
| 					<INPUT TYPE=hidden NAME="key" VALUE="'.$rec_key.'"> | ||||
| 					</TD></TR> | ||||
| 					</TABLE> | ||||
| 					<BR> | ||||
| 					<TABLE CELLSPACING=0 CELLPADDING=0 BORDER=0 WIDTH=100%><TR><TD><div style="text-align:center"> | ||||
| 					' . $twig->render('buttons.submit.html.twig') . '</div> | ||||
| 					</TD></TR></FORM></TABLE></TABLE>'; | ||||
| 				} | ||||
| 				else | ||||
| 					echo 'Wrong recovery key!'; | ||||
| 			} | ||||
| 			else | ||||
| 				echo 'Account of this character has no recovery key!'; | ||||
| 		} | ||||
| 		else | ||||
| 			echo 'Player or account of player <b>'.$nick.'</b> doesn\'t exist.'; | ||||
| 	} | ||||
| 	else | ||||
| 		echo 'Invalid player name format. If you have other characters on account try with other name.'; | ||||
| 	echo '<BR /><TABLE CELLSPACING=0 CELLPADDING=0 BORDER=0 WIDTH=100%><TR><TD><div style="text-align:center"> | ||||
| 				<a href="' . getLink('account/lost') . '?action=step1&action_type=reckey&nick='.urlencode($nick).'" border="0"><IMG SRC="'.$template_path.'/images/global/buttons/sbutton_back.gif" NAME="Back" ALT="Back" BORDER=0 WIDTH=120 HEIGHT=18></a></div> | ||||
| 				</TD></TR></FORM></TABLE></TABLE>'; | ||||
| } | ||||
| elseif($action == 'step3') | ||||
| { | ||||
| 	$rec_key = trim($_REQUEST['key']); | ||||
| 	$nick = stripslashes($_REQUEST['nick']); | ||||
| 	$new_pass = trim($_REQUEST['passor']); | ||||
| 	$new_email = trim($_REQUEST['email']); | ||||
| 	if(Validator::characterName($nick)) | ||||
| 	{ | ||||
| 		$player = new OTS_Player(); | ||||
| 		$account = new OTS_Account(); | ||||
| 		$player->find($nick); | ||||
| 		if($player->isLoaded()) | ||||
| 			$account = $player->getAccount(); | ||||
| 		if($account->isLoaded()) | ||||
| 		{ | ||||
| 			$account_key = $account->getCustomField('key'); | ||||
| 			if(!empty($account_key)) | ||||
| 			{ | ||||
| 				if($account_key == $rec_key) | ||||
| 				{ | ||||
| 					if(Validator::password($new_pass)) | ||||
| 					{ | ||||
| 						if(Validator::email($new_email)) | ||||
| 						{ | ||||
| 							$account->setEMail($new_email); | ||||
|  | ||||
| 							$tmp_new_pass = $new_pass; | ||||
| 							if(USE_ACCOUNT_SALT) | ||||
| 							{ | ||||
| 								$salt = generateRandomString(10, false, true, true); | ||||
| 								$tmp_new_pass = $salt . $new_pass; | ||||
| 							} | ||||
|  | ||||
| 							$account->setPassword(encrypt($tmp_new_pass)); | ||||
| 							$account->save(); | ||||
|  | ||||
| 							if(USE_ACCOUNT_SALT) | ||||
| 								$account->setCustomField('salt', $salt); | ||||
|  | ||||
| 							echo 'Your account name, new password and new e-mail.<BR> | ||||
| 							<FORM ACTION="' . getLink('account/manage') . '" onsubmit="return validate_form(this)" METHOD=post> | ||||
| 							<INPUT TYPE=hidden NAME="character" VALUE=""> | ||||
| 							<TABLE CELLSPACING=1 CELLPADDING=4 BORDER=0 WIDTH=100%> | ||||
| 							<TR><TD BGCOLOR="'.$config['vdarkborder'].'" class="white"><B>Your account name, new password and new e-mail</B></TD></TR> | ||||
| 							<TR><TD BGCOLOR="'.$config['darkborder'].'"> | ||||
| 							Account name:     <b>'.$account->getName().'</b><BR> | ||||
| 							New password:        <b>'.$new_pass.'</b><BR> | ||||
| 							New e-mail address: <b>'.$new_email.'</b><BR>'; | ||||
| 							if($account->getCustomField('email_next') < time()) | ||||
| 							{ | ||||
| 								$mailBody = ' | ||||
| 								<h3>Your account name and new password!</h3> | ||||
| 								<p>Changed password and e-mail to your account in Lost Account Interface on server <a href="'.BASE_URL.'"><b>'.$config['lua']['serverName'].'</b></a></p> | ||||
| 								<p>Account name: <b>'.$account->getName().'</b></p> | ||||
| 								<p>New password: <b>'.$new_pass.'</b></p> | ||||
| 								<p>E-mail: <b>'.$new_email.'</b> (this e-mail)</p> | ||||
| 								<br /> | ||||
| 								<p><u>It\'s automatic e-mail from OTS Lost Account System. Do not reply!</u></p>'; | ||||
|  | ||||
| 								if(_mail($account->getCustomField('email'), $config['lua']['serverName']." - New password to your account", $mailBody)) | ||||
| 								{ | ||||
| 									echo '<br /><small>Sent e-mail with your account name and password to new e-mail. You should receive this e-mail in 15 minutes. You can login now with new password!</small>'; | ||||
| 								} | ||||
| 								else | ||||
| 								{ | ||||
| 									echo '<br /><p class="error">An error occurred while sending email! You will not receive e-mail with this informations. For Admin: More info can be found in system/logs/mailer-error.log</p>'; | ||||
| 								} | ||||
| 							} | ||||
| 							else | ||||
| 							{ | ||||
| 								echo '<br /><small>You will not receive e-mail with this informations.</small>'; | ||||
| 							} | ||||
| 							echo '<INPUT TYPE=hidden NAME="account_login" VALUE="'.$account->getId().'"> | ||||
| 							<INPUT TYPE=hidden NAME="password_login" VALUE="'.$new_pass.'"> | ||||
| 							</TD></TR></TABLE><BR> | ||||
| 							<TABLE CELLSPACING=0 CELLPADDING=0 BORDER=0 WIDTH=100%><TR><TD><div style="text-align:center"> | ||||
| 							<INPUT TYPE=image NAME="Login" ALT="Login" SRC="'.$template_path.'/images/global/buttons/sbutton_login.gif" BORDER=0 WIDTH=120 HEIGHT=18></div> | ||||
| 							</TD></TR></FORM></TABLE></TABLE>'; | ||||
| 						} | ||||
| 						else | ||||
| 							echo Validator::getLastError(); | ||||
| 					} | ||||
| 					else | ||||
| 						echo Validator::getLastError(); | ||||
| 				} | ||||
| 				else | ||||
| 					echo 'Wrong recovery key!'; | ||||
| 			} | ||||
| 			else | ||||
| 				echo 'Account of this character has no recovery key!'; | ||||
| 		} | ||||
| 		else | ||||
| 			echo 'Player or account of player <b>'.$nick.'</b> doesn\'t exist.'; | ||||
| 	} | ||||
| 	else | ||||
| 		echo 'Invalid player name format. If you have other characters on account try with other name.'; | ||||
| 	echo '<BR /><TABLE CELLSPACING=0 CELLPADDING=0 BORDER=0 WIDTH=100%><TR><TD><div style="text-align:center"> | ||||
| 				<a href="' . getLink('account/lost') . '?action=step1&action_type=reckey&nick='.urlencode($nick).'" border="0"><IMG SRC="'.$template_path.'/images/global/buttons/sbutton_back.gif" NAME="Back" ALT="Back" BORDER=0 WIDTH=120 HEIGHT=18></a></div> | ||||
| 				</TD></TR></FORM></TABLE></TABLE>'; | ||||
| } | ||||
| elseif($action == 'checkcode') | ||||
| { | ||||
| 	$code = trim($_REQUEST['code']); | ||||
| 	$character = stripslashes(trim($_REQUEST['character'])); | ||||
| 	if(empty($code) || empty($character)) | ||||
| 		echo 'Please enter code from e-mail and name of one character from account. Then press Submit.<BR> | ||||
| 				<FORM ACTION="' . getLink('account/lost') . '?action=checkcode" METHOD=post> | ||||
| 				<TABLE CELLSPACING=1 CELLPADDING=4 BORDER=0 WIDTH=100%> | ||||
| 				<TR><TD BGCOLOR="'.$config['vdarkborder'].'" class="white"><B>Code & character name</B></TD></TR> | ||||
| 				<TR><TD BGCOLOR="'.$config['darkborder'].'"> | ||||
| 				Your code: <INPUT TYPE=text NAME="code" VALUE="" SIZE="40")><BR /> | ||||
| 				Character: <INPUT TYPE=text NAME="character" VALUE="" SIZE="40")><BR /> | ||||
| 				</TD></TR> | ||||
| 				</TABLE> | ||||
| 				<BR> | ||||
| 				<TABLE CELLSPACING=0 CELLPADDING=0 BORDER=0 WIDTH=100%><TR><TD><div style="text-align:center"> | ||||
| 				' . $twig->render('buttons.submit.html.twig') . '</div> | ||||
| 				</TD></TR></FORM></TABLE></TABLE>'; | ||||
| 	else | ||||
| 	{ | ||||
| 		$player = new OTS_Player(); | ||||
| 		$account = new OTS_Account(); | ||||
| 		$player->find($character); | ||||
| 		if($player->isLoaded()) | ||||
| 			$account = $player->getAccount(); | ||||
| 		if($account->isLoaded()) | ||||
| 		{ | ||||
| 			if($account->getCustomField('email_code') == $code) | ||||
| 			{ | ||||
| 				echo '<script type="text/javascript"> | ||||
| 				function validate_required(field,alerttxt) | ||||
| 				{ | ||||
| 				with (field) | ||||
| 				{ | ||||
| 				if (value==null||value==""||value==" ") | ||||
| 				  {alert(alerttxt);return false;} | ||||
| 				else {return true} | ||||
| 				} | ||||
| 				} | ||||
|  | ||||
| 				function validate_form(thisform) | ||||
| 				{ | ||||
| 				with (thisform) | ||||
| 				{ | ||||
| 				if (validate_required(passor,"Please enter password!")==false) | ||||
| 				  {passor.focus();return false;} | ||||
| 				if (validate_required(passor2,"Please repeat password!")==false) | ||||
| 				  {passor2.focus();return false;} | ||||
| 				if (passor2.value!=passor.value) | ||||
| 				  {alert(\'Repeated password is not equal to password!\');return false;} | ||||
| 				} | ||||
| 				} | ||||
| 				</script> | ||||
| 				Please enter new password to your account and repeat to make sure you remember password.<BR> | ||||
| 				<FORM ACTION="' . getLink('account/lost') . '?action=setnewpassword" onsubmit="return validate_form(this)" METHOD=post> | ||||
| 				<INPUT TYPE=hidden NAME="character" VALUE="'.$character.'"> | ||||
| 				<INPUT TYPE=hidden NAME="code" VALUE="'.$code.'"> | ||||
| 				<TABLE CELLSPACING=1 CELLPADDING=4 BORDER=0 WIDTH=100%> | ||||
| 				<TR><TD BGCOLOR="'.$config['vdarkborder'].'" class="white"><B>Code & account name</B></TD></TR> | ||||
| 				<TR><TD BGCOLOR="'.$config['darkborder'].'"> | ||||
| 				New password:      <INPUT TYPE=password ID="passor" NAME="passor" VALUE="" SIZE="40")><BR /> | ||||
| 				Repeat new password: <INPUT TYPE=password ID="passor2" NAME="passor2" VALUE="" SIZE="40")><BR /> | ||||
| 				</TD></TR> | ||||
| 				</TABLE> | ||||
| 				<BR> | ||||
| 				<TABLE CELLSPACING=0 CELLPADDING=0 BORDER=0 WIDTH=100%><TR><TD><div style="text-align:center"> | ||||
| 				' . $twig->render('buttons.submit.html.twig') . '</div> | ||||
| 				</TD></TR></FORM></TABLE></TABLE>'; | ||||
| 			} | ||||
| 			else | ||||
| 				$error= 'Wrong code to change password.'; | ||||
| 		} | ||||
| 		else | ||||
| 			$error = 'Account of this character or this character doesn\'t exist.'; | ||||
| 	} | ||||
| 	if(!empty($error)) | ||||
| 				echo '<span style="color: red"><b>'.$error.'</b></span><br />Please enter code from e-mail and name of one character from account. Then press Submit.<BR> | ||||
| 				<FORM ACTION="' . getLink('account/lost') . '?action=checkcode" METHOD=post> | ||||
| 				<TABLE CELLSPACING=1 CELLPADDING=4 BORDER=0 WIDTH=100%> | ||||
| 				<TR><TD BGCOLOR="'.$config['vdarkborder'].'" class="white"><B>Code & character name</B></TD></TR> | ||||
| 				<TR><TD BGCOLOR="'.$config['darkborder'].'"> | ||||
| 				Your code: <INPUT TYPE=text NAME="code" VALUE="" SIZE="40")><BR /> | ||||
| 				Character: <INPUT TYPE=text NAME="character" VALUE="" SIZE="40")><BR /> | ||||
| 				</TD></TR> | ||||
| 				</TABLE> | ||||
| 				<BR> | ||||
| 				<TABLE CELLSPACING=0 CELLPADDING=0 BORDER=0 WIDTH=100%><TR><TD><div style="text-align:center"> | ||||
| 				' . $twig->render('buttons.submit.html.twig') . '</div> | ||||
| 				</TD></TR></FORM></TABLE></TABLE>'; | ||||
| } | ||||
| elseif($action == 'setnewpassword') | ||||
| { | ||||
| 	$newpassword = $_REQUEST['passor']; | ||||
| 	$code = $_REQUEST['code']; | ||||
| 	$character = stripslashes($_REQUEST['character']); | ||||
| 	echo ''; | ||||
| 	if(empty($code) || empty($character) || empty($newpassword)) | ||||
| 		echo '<span style="color: red"><b>Error. Try again.</b></span><br />Please enter code from e-mail and name of one character from account. Then press Submit.<BR> | ||||
| 				<BR><FORM ACTION="' . getLink('account/lost') . '?action=checkcode" METHOD=post> | ||||
| 				<TABLE CELLSPACING=0 CELLPADDING=0 BORDER=0 WIDTH=100%><TR><TD><div style="text-align:center"> | ||||
| 				<INPUT TYPE=image NAME="Back" ALT="Back" SRC="'.$template_path.'/images/global/buttons/sbutton_back.gif" BORDER=0 WIDTH=120 HEIGHT=18></div> | ||||
| 				</TD></TR></FORM></TABLE></TABLE>'; | ||||
| 	else | ||||
| 	{ | ||||
| 		$player = new OTS_Player(); | ||||
| 		$account = new OTS_Account(); | ||||
| 		$player->find($character); | ||||
| 		if($player->isLoaded()) | ||||
| 			$account = $player->getAccount(); | ||||
| 		if($account->isLoaded()) | ||||
| 		{ | ||||
| 			if($account->getCustomField('email_code') == $code) | ||||
| 			{ | ||||
| 				if(Validator::password($newpassword)) | ||||
| 				{ | ||||
| 					$tmp_new_pass = $newpassword; | ||||
| 					if(USE_ACCOUNT_SALT) | ||||
| 					{ | ||||
| 						$salt = generateRandomString(10, false, true, true); | ||||
| 						$tmp_new_pass  = $salt . $newpassword; | ||||
| 						$account->setCustomField('salt', $salt); | ||||
| 					} | ||||
|  | ||||
| 					$account->setPassword(encrypt($tmp_new_pass )); | ||||
| 					$account->save(); | ||||
| 					$account->setCustomField('email_code', ''); | ||||
| 					echo 'New password to your account is below. Now you can login.<BR> | ||||
| 					<INPUT TYPE=hidden NAME="character" VALUE="'.$character.'"> | ||||
| 					<TABLE CELLSPACING=1 CELLPADDING=4 BORDER=0 WIDTH=100%> | ||||
| 					<TR><TD BGCOLOR="'.$config['vdarkborder'].'" class="white"><B>Changed password</B></TD></TR> | ||||
| 					<TR><TD BGCOLOR="'.$config['darkborder'].'"> | ||||
| 					New password: <b>'.$newpassword.'</b><BR /> | ||||
| 					Account name:   <i>(Already on your e-mail)</i><BR />'; | ||||
|  | ||||
| 					$mailBody = ' | ||||
| 					<h3>Your account name and password!</h3> | ||||
| 					<p>Changed password to your account in Lost Account Interface on server <a href="'.BASE_URL.'"><b>'.$config['lua']['serverName'].'</b></a></p> | ||||
| 					<p>Account name: <b>'.$account->getName().'</b></p> | ||||
| 					<p>New password: <b>'.$newpassword.'</b></p> | ||||
| 					<br /> | ||||
| 					<p><u>It\'s automatic e-mail from OTS Lost Account System. Do not reply!</u></p>'; | ||||
|  | ||||
| 					if(_mail($account->getCustomField('email'), $config['lua']['serverName']." - Your new password", $mailBody)) | ||||
| 					{ | ||||
| 						echo '<br /><small>New password work! Sent e-mail with your password and account name. You should receive this e-mail in 15 minutes. You can login now with new password!'; | ||||
| 					} | ||||
| 					else | ||||
| 					{ | ||||
| 						echo '<br /><p class="error">New password work! An error occurred while sending email! You will not receive e-mail with new password. For Admin: More info can be found in system/logs/mailer-error.log'; | ||||
| 					} | ||||
| 				echo '</TD></TR> | ||||
| 				</TABLE> | ||||
| 				<BR> | ||||
| 				<TABLE CELLSPACING=0 CELLPADDING=0 BORDER=0 WIDTH=100%><TR><TD><div style="text-align:center"> | ||||
| 				<FORM ACTION="' . getLink('account/manage') . '" METHOD=post> | ||||
| 				<INPUT TYPE=image NAME="Login" ALT="Login" SRC="'.$template_path.'/images/global/buttons/sbutton_login.gif" BORDER=0 WIDTH=120 HEIGHT=18></div> | ||||
| 				</TD></TR></FORM></TABLE></TABLE>'; | ||||
| 				} | ||||
| 				else | ||||
| 					$error= Validator::getLastError(); | ||||
| 			} | ||||
| 			else | ||||
| 				$error= 'Wrong code to change password.'; | ||||
| 		} | ||||
| 		else | ||||
| 			$error = 'Account of this character or this character doesn\'t exist.'; | ||||
| 	} | ||||
| 	if(!empty($error)) | ||||
| 				echo '<span style="color: red"><b>'.$error.'</b></span><br />Please enter code from e-mail and name of one character from account. Then press Submit.<BR> | ||||
| 				<FORM ACTION="' . getLink('account/lost') . '?action=checkcode" METHOD=post> | ||||
| 				<TABLE CELLSPACING=1 CELLPADDING=4 BORDER=0 WIDTH=100%> | ||||
| 				<TR><TD BGCOLOR="'.$config['vdarkborder'].'" class="white"><B>Code & character name</B></TD></TR> | ||||
| 				<TR><TD BGCOLOR="'.$config['darkborder'].'"> | ||||
| 				Your code: <INPUT TYPE=text NAME="code" VALUE="" SIZE="40")><BR /> | ||||
| 				Character: <INPUT TYPE=text NAME="character" VALUE="" SIZE="40")><BR /> | ||||
| 				</TD></TR> | ||||
| 				</TABLE> | ||||
| 				<BR> | ||||
| 				<TABLE CELLSPACING=0 CELLPADDING=0 BORDER=0 WIDTH=100%><TR><TD><div style="text-align:center"> | ||||
| 				' . $twig->render('buttons.submit.html.twig') . '</div> | ||||
| 				</TD></TR></FORM></TABLE></TABLE>'; | ||||
| } | ||||
| $twig->display('account/lost/form.html.twig'); | ||||
|   | ||||
							
								
								
									
										18
									
								
								system/pages/account/lost/base.php
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										18
									
								
								system/pages/account/lost/base.php
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,18 @@ | ||||
| <?php | ||||
| defined('MYAAC') or die('Direct access not allowed!'); | ||||
|  | ||||
| function lostAccountWriteCooldown(string $nick, int $time): void | ||||
| { | ||||
| 	global $twig; | ||||
|  | ||||
| 	$inSec = $time - time(); | ||||
| 	$minutesLeft = floor($inSec / 60); | ||||
| 	$secondsLeft = $inSec - ($minutesLeft * 60); | ||||
| 	$timeLeft = "$minutesLeft minutes $secondsLeft seconds"; | ||||
|  | ||||
| 	$timeRounded = ceil(setting('core.mail_lost_account_interval') / 60); | ||||
|  | ||||
| 	$twig->display('error_box.html.twig', [ | ||||
| 		'errors' => ["Account of selected character (<b>" . escapeHtml($nick) . "</b>) received e-mail in last $timeRounded minutes. You must wait $timeLeft before you can use Lost Account Interface again."] | ||||
| 	]); | ||||
| } | ||||
							
								
								
									
										51
									
								
								system/pages/account/lost/check-code.php
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										51
									
								
								system/pages/account/lost/check-code.php
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,51 @@ | ||||
| <?php | ||||
| defined('MYAAC') or die('Direct access not allowed!'); | ||||
|  | ||||
| csrfProtect(); | ||||
|  | ||||
| $title = 'Lost Account'; | ||||
|  | ||||
| $code = $_POST['code'] ?? ''; | ||||
| $character = $_POST['character'] ?? ''; | ||||
|  | ||||
| if(empty($code) || empty($character)) { | ||||
| 	$twig->display('account/lost/check-code.html.twig', [ | ||||
| 		'code' => $code, | ||||
| 		'characters' => $character, | ||||
| 	]); | ||||
| } | ||||
| else { | ||||
| 	$player = new OTS_Player(); | ||||
| 	$account = new OTS_Account(); | ||||
| 	$player->find($character); | ||||
| 	if($player->isLoaded()) { | ||||
| 		$account = $player->getAccount(); | ||||
| 	} | ||||
|  | ||||
| 	if($account->isLoaded()) { | ||||
| 		if($account->getCustomField('email_code') == $code) { | ||||
| 			$twig->display('account/lost/check-code.finish.html.twig', [ | ||||
| 				'character' => $character, | ||||
| 				'code' => $code, | ||||
| 			]); | ||||
| 		} | ||||
| 		else { | ||||
| 			$error = 'Wrong code to change password.'; | ||||
| 		} | ||||
| 	} | ||||
| 	else { | ||||
| 		$error = "Account of this character or this character doesn't exist."; | ||||
| 	} | ||||
| } | ||||
|  | ||||
| if(!empty($error)) { | ||||
| 	$twig->display('error_box.html.twig', [ | ||||
| 		'errors' => [$error], | ||||
| 	]); | ||||
|  | ||||
| 	echo '<br/>'; | ||||
|  | ||||
| 	$twig->display('account/lost/check-code.html.twig', [ | ||||
|  | ||||
| 	]); | ||||
| } | ||||
							
								
								
									
										68
									
								
								system/pages/account/lost/email/send-code.php
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										68
									
								
								system/pages/account/lost/email/send-code.php
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,68 @@ | ||||
| <?php | ||||
| defined('MYAAC') or die('Direct access not allowed!'); | ||||
|  | ||||
| csrfProtect(); | ||||
|  | ||||
| require __DIR__ . '/../base.php'; | ||||
|  | ||||
| $title = 'Lost Account'; | ||||
|  | ||||
| $email = $_POST['email'] ?? ''; | ||||
| $nick = $_POST['nick'] ?? ''; | ||||
|  | ||||
| $player = new OTS_Player(); | ||||
| $account = new OTS_Account(); | ||||
| $player->find($nick); | ||||
| if($player->isLoaded()) { | ||||
| 	$account = $player->getAccount(); | ||||
| } | ||||
|  | ||||
| if($account->isLoaded()) { | ||||
| 	if($account->getCustomField('email_next') < time()) { | ||||
| 		if($account->getEMail() == $email) { | ||||
| 			$newCode = generateRandomString(30, true, false, true); | ||||
| 			$mailBody = $twig->render('mail.account.lost.code.html.twig', [ | ||||
| 				'newCode' => $newCode, | ||||
| 				'account' => $account, | ||||
| 				'nick' => $nick, | ||||
| 			]); | ||||
|  | ||||
| 			$accountEMail = $account->getCustomField('email'); | ||||
| 			if(_mail($accountEMail, configLua('serverName') . ' - Recover your account', $mailBody)) { | ||||
| 				$account->setCustomField('email_code', $newCode); | ||||
| 				$account->setCustomField('email_next', (time() + setting('core.mail_lost_account_interval'))); | ||||
|  | ||||
| 				$twig->display('success.html.twig', [ | ||||
| 					'title' => 'Email has been sent', | ||||
| 					'description' => 'Details about steps required to recover your account has been sent to <b>' . $accountEMail . '</b>. You should receive this email within 15 minutes. Please check your inbox/spam directory.', | ||||
| 					'custom_buttons' => '', | ||||
| 				]); | ||||
| 			} | ||||
| 			else { | ||||
| 				$account->setCustomField('email_next', (time() + 60)); | ||||
| 				error('An error occurred while sending email! Try again later or contact with admin. For Admin: More info can be found in system/logs/mailer-error.log</p>'); | ||||
| 			} | ||||
| 		} | ||||
| 		else { | ||||
| 			$errors[] = 'Invalid e-mail to account of character <b>' . escapeHtml($nick) . '</b>. Try again.'; | ||||
| 		} | ||||
| 	} | ||||
| 	else { | ||||
| 		lostAccountWriteCooldown($nick, (int)$account->getCustomField('email_next')); | ||||
| 	} | ||||
| } | ||||
| else { | ||||
| 	$errors[] =  "Player or account of player <b>" . escapeHtml($nick) . "</b> doesn't exist."; | ||||
| } | ||||
|  | ||||
| if (!empty($errors)) { | ||||
| 	$twig->display('error_box.html.twig', [ | ||||
| 		'errors' => $errors, | ||||
| 	]); | ||||
| } | ||||
|  | ||||
| $twig->display('account.back_button.html.twig', [ | ||||
| 	'new_line' => true, | ||||
| 	'center' => true, | ||||
| 	'action' => getLink('account/lost/step-1') . '?action=email&nick=' . urlencode($nick), | ||||
| ]); | ||||
							
								
								
									
										94
									
								
								system/pages/account/lost/email/set-new-password.php
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										94
									
								
								system/pages/account/lost/email/set-new-password.php
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,94 @@ | ||||
| <?php | ||||
| defined('MYAAC') or die('Direct access not allowed!'); | ||||
|  | ||||
| csrfProtect(); | ||||
|  | ||||
| $title = 'Lost Account'; | ||||
|  | ||||
| $newPassword = $_POST['password'] ?? ''; | ||||
| $passwordRepeat = $_POST['password_repeat'] ?? ''; | ||||
| $code = $_POST['code'] ?? ''; | ||||
| $character = $_POST['character'] ?? ''; | ||||
|  | ||||
| if(empty($code) || empty($character) || empty($newPassword) || empty($passwordRepeat)) { | ||||
| 	$errors[] = 'Please enter code from e-mail and name of one character from account. Then press Submit.'; | ||||
|  | ||||
| 	$twig->display('error_box.html.twig', [ | ||||
| 		'errors' => $errors, | ||||
| 	]); | ||||
|  | ||||
| 	$twig->display('account.back_button.html.twig', [ | ||||
| 		'new_line' => true, | ||||
| 		'center' => true, | ||||
| 		'action' => getLink('account/lost/check-code') | ||||
| 	]); | ||||
|  | ||||
| 	return; | ||||
| } | ||||
|  | ||||
| $player = new OTS_Player(); | ||||
| $account = new OTS_Account(); | ||||
| $player->find($character); | ||||
| if($player->isLoaded()) { | ||||
| 	$account = $player->getAccount(); | ||||
| } | ||||
|  | ||||
| if($account->isLoaded()) { | ||||
| 	if($account->getCustomField('email_code') == $code) { | ||||
| 		if ($newPassword == $passwordRepeat) { | ||||
| 			if (Validator::password($newPassword)) { | ||||
| 				$tmp_new_pass = $newPassword; | ||||
| 				if (USE_ACCOUNT_SALT) { | ||||
| 					$salt = generateRandomString(10, false, true, true); | ||||
| 					$tmp_new_pass = $salt . $newPassword; | ||||
| 					$account->setCustomField('salt', $salt); | ||||
| 				} | ||||
|  | ||||
| 				$account->setPassword(encrypt($tmp_new_pass)); | ||||
| 				$account->save(); | ||||
| 				$account->setCustomField('email_code', ''); | ||||
|  | ||||
| 				$mailBody = $twig->render('mail.account.lost.new-password.html.twig', [ | ||||
| 					'account' => $account, | ||||
| 					'newPassword' => $newPassword, | ||||
| 				]); | ||||
|  | ||||
| 				$statusMsg = ''; | ||||
| 				if (_mail($account->getCustomField('email'), configLua('serverName') . ' - Your new password', $mailBody)) { | ||||
| 					$statusMsg = '<br /><small>New password work! Sent e-mail with your password and account name. You should receive this e-mail in 15 minutes. You can login now with new password!'; | ||||
| 				} else { | ||||
| 					$statusMsg = '<br /><p class="error">New password work! An error occurred while sending email! You will not receive e-mail with new password. For Admin: More info can be found in system/logs/mailer-error.log'; | ||||
| 				} | ||||
|  | ||||
| 				$twig->display('account/lost/finish.new-password.html.twig', [ | ||||
| 					'statusMsg' => $statusMsg, | ||||
| 					'newPassword' => $newPassword, | ||||
| 				]); | ||||
| 			} else { | ||||
| 				$error = Validator::getLastError(); | ||||
| 			} | ||||
| 		} | ||||
| 		else { | ||||
| 			$error = 'Passwords are not the same!'; | ||||
| 		} | ||||
| 	} | ||||
| 	else { | ||||
| 		$error = 'Wrong code to change password.'; | ||||
| 	} | ||||
| } | ||||
| else { | ||||
| 	$error = "Account of this character or this character doesn't exist."; | ||||
| } | ||||
|  | ||||
| if(!empty($error)) { | ||||
| 	$twig->display('error_box.html.twig', [ | ||||
| 		'errors' => [$error], | ||||
| 	]); | ||||
|  | ||||
| 	echo '<br/>'; | ||||
|  | ||||
| 	$twig->display('account/lost/check-code.html.twig', [ | ||||
| 		'code' => $code, | ||||
| 		'character' => $character, | ||||
| 	]); | ||||
| } | ||||
							
								
								
									
										36
									
								
								system/pages/account/lost/email/step-1.php
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										36
									
								
								system/pages/account/lost/email/step-1.php
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,36 @@ | ||||
| <?php | ||||
| defined('MYAAC') or die('Direct access not allowed!'); | ||||
|  | ||||
| require __DIR__ . '/../base.php'; | ||||
|  | ||||
| csrfProtect(); | ||||
|  | ||||
| $title = 'Lost Account'; | ||||
|  | ||||
| $nick = $_POST['nick'] ?? ''; | ||||
|  | ||||
| if($account->isLoaded()) { | ||||
| 	if($account->getCustomField('email_next') < time()) { | ||||
| 		$twig->display('account/lost/email.html.twig', [ | ||||
| 			'nick' => $nick, | ||||
| 		]); | ||||
| 	} | ||||
| 	else { | ||||
| 		lostAccountWriteCooldown($nick, (int)$account->getCustomField('email_next')); | ||||
| 	} | ||||
| } | ||||
| else { | ||||
| 	$errors[] = "Player or account of player <b>" . escapeHtml($nick) . "</b> doesn't exist."; | ||||
| } | ||||
|  | ||||
| if (!empty($errors)) { | ||||
| 	$twig->display('error_box.html.twig', [ | ||||
| 		'errors' => $errors, | ||||
| 	]); | ||||
| } | ||||
|  | ||||
| $twig->display('account.back_button.html.twig', [ | ||||
| 	'new_line' => true, | ||||
| 	'center' => true, | ||||
| 	'action' => getLink('account/lost'), | ||||
| ]); | ||||
							
								
								
									
										36
									
								
								system/pages/account/lost/recovery-key/step-1.php
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										36
									
								
								system/pages/account/lost/recovery-key/step-1.php
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,36 @@ | ||||
| <?php | ||||
| defined('MYAAC') or die('Direct access not allowed!'); | ||||
|  | ||||
| csrfProtect(); | ||||
|  | ||||
| $title = 'Lost Account'; | ||||
|  | ||||
| $nick = $_POST['nick'] ?? ''; | ||||
|  | ||||
| if($account->isLoaded()) { | ||||
| 	$account_key = $account->getCustomField('key'); | ||||
|  | ||||
| 	if(!empty($account_key)) { | ||||
| 		$twig->display('account/lost/recovery-key.step-1.html.twig', [ | ||||
| 			'nick' => $nick, | ||||
| 		]); | ||||
| 	} | ||||
| 	else { | ||||
| 		$errors[] = 'Account of this character has no recovery key!'; | ||||
| 	} | ||||
| } | ||||
| else { | ||||
| 	$errors[] = "Player or account of player <b>" . escapeHtml($nick) . "</b> doesn't exist."; | ||||
| } | ||||
|  | ||||
| if (!empty($errors)) { | ||||
| 	$twig->display('error_box.html.twig', [ | ||||
| 		'errors' => $errors, | ||||
| 	]); | ||||
| } | ||||
|  | ||||
| $twig->display('account.back_button.html.twig', [ | ||||
| 	'new_line' => true, | ||||
| 	'center' => true, | ||||
| 	'action' => getLink('account/lost'), | ||||
| ]); | ||||
							
								
								
									
										49
									
								
								system/pages/account/lost/recovery-key/step-2.php
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										49
									
								
								system/pages/account/lost/recovery-key/step-2.php
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,49 @@ | ||||
| <?php | ||||
| defined('MYAAC') or die('Direct access not allowed!'); | ||||
|  | ||||
| csrfProtect(); | ||||
|  | ||||
| $title = 'Lost Account'; | ||||
|  | ||||
| $key = $_REQUEST['key'] ?? ''; | ||||
| $nick = $_POST['nick'] ?? ''; | ||||
|  | ||||
| $player = new OTS_Player(); | ||||
| $account = new OTS_Account(); | ||||
| $player->find($nick); | ||||
| if($player->isLoaded()) { | ||||
| 	$account = $player->getAccount(); | ||||
| } | ||||
|  | ||||
| if($account->isLoaded()) { | ||||
| 	$accountKey = $account->getCustomField('key'); | ||||
| 	if(!empty($accountKey)) { | ||||
| 		if($accountKey == $key) { | ||||
| 			$twig->display('account/lost/recovery-key.step-2.html.twig', [ | ||||
| 				'nick' => $nick, | ||||
| 				'key' => $key, | ||||
| 			]); | ||||
| 		} | ||||
| 		else { | ||||
| 			$errors[] = 'Wrong recovery key!'; | ||||
| 		} | ||||
| 	} | ||||
| 	else { | ||||
| 		$errors[] = 'Account of this character has no recovery key!'; | ||||
| 	} | ||||
| } | ||||
| else { | ||||
| 	$errors[] = "Player or account of player <b>" . escapeHtml($nick) . "</b> doesn't exist."; | ||||
| } | ||||
|  | ||||
| if (!empty($errors)) { | ||||
| 	$twig->display('error_box.html.twig', [ | ||||
| 		'errors' => $errors, | ||||
| 	]); | ||||
| } | ||||
|  | ||||
| $twig->display('account.back_button.html.twig', [ | ||||
| 	'new_line' => true, | ||||
| 	'center' => true, | ||||
| 	'action' => getLink('account/lost/step-1') . '?action=recovery-key&nick=' . urlencode($nick), | ||||
| ]); | ||||
							
								
								
									
										101
									
								
								system/pages/account/lost/recovery-key/step-3.php
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										101
									
								
								system/pages/account/lost/recovery-key/step-3.php
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,101 @@ | ||||
| <?php | ||||
| defined('MYAAC') or die('Direct access not allowed!'); | ||||
|  | ||||
| csrfProtect(); | ||||
|  | ||||
| $title = 'Lost Account'; | ||||
|  | ||||
| $key = $_POST['key']; | ||||
| $nick = $_POST['nick'] ?? ''; | ||||
| $newPassword = $_POST['password'] ?? ''; | ||||
| $passwordRepeat = $_POST['password_repeat'] ?? ''; | ||||
| $newEmail = $_POST['email'] ?? ''; | ||||
|  | ||||
| $player = new OTS_Player(); | ||||
| $account = new OTS_Account(); | ||||
| $player->find($nick); | ||||
| if($player->isLoaded()) { | ||||
| 	$account = $player->getAccount(); | ||||
| } | ||||
|  | ||||
| if($account->isLoaded()) { | ||||
| 	$accountKey = $account->getCustomField('key'); | ||||
|  | ||||
| 	if(!empty($accountKey)) { | ||||
| 		if($accountKey == $key) { | ||||
| 			if(Validator::password($newPassword)) { | ||||
| 				if ($newPassword == $passwordRepeat) { | ||||
| 					if (Validator::email($newEmail)) { | ||||
| 						$account->setEMail($newEmail); | ||||
|  | ||||
| 						$tmp_new_pass = $newPassword; | ||||
| 						if (USE_ACCOUNT_SALT) { | ||||
| 							$salt = generateRandomString(10, false, true, true); | ||||
| 							$tmp_new_pass = $salt . $newPassword; | ||||
| 						} | ||||
|  | ||||
| 						$account->setPassword(encrypt($tmp_new_pass)); | ||||
| 						$account->save(); | ||||
|  | ||||
| 						if (USE_ACCOUNT_SALT) { | ||||
| 							$account->setCustomField('salt', $salt); | ||||
| 						} | ||||
|  | ||||
| 						$statusMsg = ''; | ||||
| 						if ($account->getCustomField('email_next') < time()) { | ||||
| 							$mailBody = $twig->render('mail.account.lost.new-email.html.twig', [ | ||||
| 								'account' => $account, | ||||
| 								'newPassword' => $newPassword, | ||||
| 								'newEmail' => $newEmail, | ||||
| 							]); | ||||
|  | ||||
| 							if (_mail($account->getCustomField('email'), configLua('serverName') . ' - New password to your account', $mailBody)) { | ||||
| 								$statusMsg = '<br /><small>Sent e-mail with your account name and password to new e-mail. You should receive this e-mail in 15 minutes. You can login now with new password!</small>'; | ||||
| 							} else { | ||||
| 								$statusMsg = '<br /><p class="error">An error occurred while sending email! You will not receive e-mail with this informations. For Admin: More info can be found in system/logs/mailer-error.log</p>'; | ||||
| 							} | ||||
| 						} else { | ||||
| 							$statusMsg = '<br /><small>You will not receive e-mail with this informations.</small>'; | ||||
| 						} | ||||
|  | ||||
| 						$twig->display('account/lost/finish.new-email.html.twig', [ | ||||
| 							'statusMsg' => $statusMsg, | ||||
| 							'account' => $account, | ||||
| 							'newPassword' => $newPassword, | ||||
| 							'newEmail' => $newEmail, | ||||
| 						]); | ||||
| 					} else { | ||||
| 						$errors[] = Validator::getLastError(); | ||||
| 					} | ||||
| 				} | ||||
| 				else { | ||||
| 					$errors[] = 'Passwords are not the same!'; | ||||
| 				} | ||||
| 			} | ||||
| 			else { | ||||
| 				$errors[] = Validator::getLastError(); | ||||
| 			} | ||||
| 		} | ||||
| 		else { | ||||
| 			$errors[] = 'Wrong recovery key!'; | ||||
| 		} | ||||
| 	} | ||||
| 	else { | ||||
| 		$errors[] = 'Account of this character has no recovery key!'; | ||||
| 	} | ||||
| } | ||||
| else { | ||||
| 	$errors[] = "Player or account of player <b>" . escapeHtml($nick) . "</b> doesn't exist."; | ||||
| } | ||||
|  | ||||
| if (!empty($errors)) { | ||||
| 	$twig->display('error_box.html.twig', [ | ||||
| 		'errors' => $errors, | ||||
| 	]); | ||||
| } | ||||
|  | ||||
| $twig->display('account.back_button.html.twig', [ | ||||
| 	'new_line' => true, | ||||
| 	'center' => true, | ||||
| 	'action' => getLink('account/lost/step-1') . '?action=recovery-key&nick=' . urlencode($nick), | ||||
| ]); | ||||
							
								
								
									
										26
									
								
								system/pages/account/lost/step-1.php
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										26
									
								
								system/pages/account/lost/step-1.php
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,26 @@ | ||||
| <?php | ||||
| defined('MYAAC') or die('Direct access not allowed!'); | ||||
|  | ||||
| csrfProtect(); | ||||
|  | ||||
| $title = 'Lost Account'; | ||||
|  | ||||
| $nick = $_REQUEST['nick'] ?? ''; | ||||
|  | ||||
| $player = new OTS_Player(); | ||||
| $account = new OTS_Account(); | ||||
| $player->find($nick); | ||||
| if($player->isLoaded()) { | ||||
| 	$account = $player->getAccount(); | ||||
| } | ||||
|  | ||||
| if (ACTION == 'email') { | ||||
| 	require __DIR__ . '/email/step-1.php'; | ||||
| } | ||||
| else if (ACTION == 'recovery-key') { | ||||
| 	require __DIR__ . '/recovery-key/step-1.php'; | ||||
| } | ||||
| else { | ||||
| 	$twig->display('account/lost/no-action.html.twig'); | ||||
| } | ||||
|  | ||||
| @@ -96,8 +96,12 @@ if($email_new_time > 1) | ||||
| 	} | ||||
| } | ||||
|  | ||||
| $actions = $account_logged->getActionsLog(1000); | ||||
| $actions = array(); | ||||
| foreach($account_logged->getActionsLog(0, 1000) as $action) { | ||||
| 	$actions[] = array('action' => $action['action'], 'date' => $action['date'], 'ip' => $action['ip'] != 0 ? long2ip($action['ip']) : inet_ntop($action['ipv6'])); | ||||
| } | ||||
|  | ||||
| $players = array(); | ||||
| /** @var OTS_Players_List $account_players */ | ||||
| $account_players = $account_logged->getPlayersList(); | ||||
| $account_players->orderBy('id'); | ||||
|   | ||||
| @@ -9,6 +9,6 @@ class AccountAction extends Model { | ||||
|  | ||||
| 	public $timestamps = false; | ||||
|  | ||||
| 	protected $fillable = ['account_id', 'ip', 'date', 'action']; | ||||
| 	protected $fillable = ['account_id', 'ip', 'ipv6', 'date', 'action']; | ||||
|  | ||||
| } | ||||
|   | ||||
| @@ -1,7 +1,26 @@ | ||||
| {% if new_line is defined and new_line %} | ||||
| 	<br/> | ||||
| {% endif %} | ||||
| <form action="{% if action is not defined %}{{ getLink('account/manage') }}{% else %}{{ action }}{% endif %}" method="post"> | ||||
| 	{{ csrf() }} | ||||
| 	{{ include('buttons.back.html.twig') }} | ||||
| </form> | ||||
|  | ||||
| {% set _center = false %} | ||||
|  | ||||
| {% if center is defined and center %} | ||||
| {% set _center = true %} | ||||
| {% endif %} | ||||
|  | ||||
| {% if _center %} | ||||
| <table border="0" cellspacing="1" cellpadding="4" width="100%"> | ||||
| 	<tbody> | ||||
| 	<tr> | ||||
| 		<td align="center"> | ||||
| {% endif %} | ||||
| 			<form action="{% if action is not defined %}{{ getLink('account/manage') }}{% else %}{{ action }}{% endif %}" method="post"> | ||||
| 				{{ csrf() }} | ||||
| 				{{ include('buttons.back.html.twig') }} | ||||
| 			</form> | ||||
| {% if _center %} | ||||
| 		</td> | ||||
| 	</tr> | ||||
| 	</tbody> | ||||
| </table> | ||||
| {% endif %} | ||||
|   | ||||
| @@ -1,36 +0,0 @@ | ||||
| The Lost Account Interface can help you to get back your account name and password. Please enter your character name and select what you want to do.<br/> | ||||
| <form action="{{ getLink('account/lost') }}?action=step1" method="post"> | ||||
| 	{{ csrf() }} | ||||
| 	<input type="hidden" name="character" value=""> | ||||
| 	<table cellspacing="1" cellpadding="4" border="0" width="100%"> | ||||
| 		<tr> | ||||
| 			<td bgcolor="{{ config.vdarkborder }}" class="white"><b>Please enter your character name</b></td> | ||||
| 		</tr> | ||||
| 		<tr> | ||||
| 			<td bgcolor="{{ config.darkborder }}"> | ||||
| 				<input type="text" name="nick" size="40" autofocus/><br> | ||||
| 			</td> | ||||
| 		</tr> | ||||
| 	</table> | ||||
| 	<table cellspacing="1" cellpadding="4" border="0" width="100%"> | ||||
| 		<tr> | ||||
| 			<td bgcolor="{{ config.vdarkborder }}" class="white"><b>What do you want?</b></td> | ||||
| 		</tr> | ||||
| 		<tr> | ||||
| 			<td bgcolor="{{ config.darkborder }}"> | ||||
| 				<input type="radio" name="action_type" id="action_type_email" value="email"> | ||||
| 				<label for="action_type_email"> Send me new password and my account name to account e-mail adress.</label><br/> | ||||
| 				<input type=radio name="action_type" id="action_type_key" value="reckey"> | ||||
| 				<label for="action_type_key"> I got <b>recovery key</b> and want set new password and e-mail adress to my account.</label><br/> | ||||
| 			</td> | ||||
| 		</tr> | ||||
| 	</table> | ||||
| 	<br/> | ||||
| 	<table cellspacing="0" cellpadding="0" border="0" width="100%"> | ||||
| 		<tr> | ||||
| 			<td align="center"> | ||||
| 				{{ include('buttons.submit.html.twig') }} | ||||
| 			</td> | ||||
| 		</tr> | ||||
| 	</table> | ||||
| </form> | ||||
| @@ -1,10 +0,0 @@ | ||||
| Please select action.<br/> | ||||
| <table cellspacing="0" cellpadding="0" border="0" width="100%"> | ||||
| 	<tr> | ||||
| 		<td align="center"> | ||||
| 			<a href="{{ getLink('account/lost') }}" border="0"> | ||||
| 				{{ include('buttons.back.html.twig') }} | ||||
| 			</a> | ||||
| 		</td> | ||||
| 	</tr> | ||||
| </table> | ||||
							
								
								
									
										54
									
								
								system/templates/account/lost/check-code.finish.html.twig
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										54
									
								
								system/templates/account/lost/check-code.finish.html.twig
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,54 @@ | ||||
| Please enter new password to your account and repeat to make sure you remember password.<BR> | ||||
| <form action="{{ getLink('account/lost/email/set-new-password') }}" method="post"> | ||||
|  | ||||
| 	{{ csrf() }} | ||||
|  | ||||
| 	<input type="hidden" name="character" value="{{ character }}"> | ||||
| 	<input type="hidden" name="code" value="{{ code }}"> | ||||
|  | ||||
| 	<table class="myaac-table" style="width: 100%;"> | ||||
|  | ||||
| 		<thead> | ||||
| 		<tr> | ||||
| 			<th class="white"><b>Passwords</b></th> | ||||
| 		</tr> | ||||
| 		</thead> | ||||
|  | ||||
| 		<tbody> | ||||
| 		<tr> | ||||
| 			<td> | ||||
| 				<table> | ||||
| 					<tr> | ||||
| 						<td> | ||||
| 							<label for="password">New password:</label> | ||||
| 						</td> | ||||
| 						<td> | ||||
| 							<input type="password" id="password" name="password" value="" size="40"> | ||||
| 						</td> | ||||
| 					</tr> | ||||
| 					<tr> | ||||
| 						<td> | ||||
| 							<label for="password_repeat">Repeat new password:</label> | ||||
| 						</td> | ||||
| 						<td> | ||||
| 							<input type="password" id="password_repeat" name="password_repeat" value="" size="40"> | ||||
| 						</td> | ||||
| 					</tr> | ||||
| 				</table> | ||||
| 			</td> | ||||
| 		</tr> | ||||
| 		</tbody> | ||||
|  | ||||
| 	</table> | ||||
| 	<br/> | ||||
| 	<table style="width: 100%"> | ||||
| 		<tr> | ||||
| 			<td> | ||||
| 				<div style="text-align: center"> | ||||
| 					{% set button_name = 'Submit' %} | ||||
| 					{% include('buttons.base.html.twig') %} | ||||
| 				</div> | ||||
| 			</td> | ||||
| 		</tr> | ||||
| 	</table> | ||||
| </form> | ||||
							
								
								
									
										33
									
								
								system/templates/account/lost/check-code.html.twig
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										33
									
								
								system/templates/account/lost/check-code.html.twig
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,33 @@ | ||||
| Please enter code from e-mail and name of one character from account. Then press Submit.<br/> | ||||
| <form action="{{ getLink('account/lost/check-code') }}" method="post"> | ||||
|  | ||||
| 	{{ csrf() }} | ||||
|  | ||||
| 	<table class="myaac-table" style="width: 100%;"> | ||||
| 		<thead> | ||||
| 		<tr> | ||||
| 			<th class="white"> | ||||
| 				<b>Code & character name</b> | ||||
| 			</th> | ||||
| 		</tr> | ||||
| 		</thead> | ||||
|  | ||||
| 		<tbody> | ||||
| 		<tr> | ||||
| 			<td> | ||||
| 				Your code: <input type="text" name="code" value="{{ code }}" size="40"><br/> | ||||
| 				Character: <input type="text" name="character" value="{{ character }}" size="40"><br/> | ||||
| 			</td> | ||||
| 		</tr> | ||||
| 		</tbody> | ||||
| 	</table> | ||||
| 	<br> | ||||
| 	<table style="width: 100%"> | ||||
| 		<tr> | ||||
| 			<td align="center"> | ||||
| 				{% set button_name = 'Submit' %} | ||||
| 				{% include('buttons.base.html.twig') %} | ||||
| 			</td> | ||||
| 		</tr> | ||||
| 	</table> | ||||
| </form> | ||||
							
								
								
									
										54
									
								
								system/templates/account/lost/email.html.twig
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										54
									
								
								system/templates/account/lost/email.html.twig
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,54 @@ | ||||
| Please enter e-mail to account with this character.<br/> | ||||
| <form action="{{ getLink('account/lost/email/send-code') }}" method="post"> | ||||
|  | ||||
| 	{{ csrf() }} | ||||
|  | ||||
| 	<input type=hidden name="character"> | ||||
| 	<table class="myaac-table" style="width: 100%;"> | ||||
|  | ||||
| 		<thead> | ||||
| 		<tr> | ||||
| 			<th class="white"><b>Please enter e-mail to account</b></th> | ||||
| 		</tr> | ||||
| 		</thead> | ||||
|  | ||||
| 		<tbody> | ||||
| 		<tr> | ||||
| 			<td> | ||||
|  | ||||
| 				<table> | ||||
| 					<tr> | ||||
| 						<td> | ||||
| 							<label for="nick">Character:</label> | ||||
| 						</td> | ||||
| 						<td> | ||||
| 							<input type=text id="nick" name="nick" value="{{ nick }}" size="40" readonly="readonly"> | ||||
| 						</td> | ||||
| 					</tr> | ||||
| 					<tr> | ||||
| 						<td> | ||||
| 							<label for="name">E-mail to account:</label> | ||||
| 						</td> | ||||
| 						<td> | ||||
| 							<input type=text id="name" name="email" value="" size="40"> | ||||
| 						</td> | ||||
| 					</tr> | ||||
| 				</table> | ||||
|  | ||||
| 			</td> | ||||
| 		</tr> | ||||
| 		</tbody> | ||||
|  | ||||
| 	</table> | ||||
| 	<br> | ||||
| 	<table style="width: 100%"> | ||||
| 		<tr> | ||||
| 			<td> | ||||
| 				<div style="text-align:center"> | ||||
| 					{% set button_name = 'Submit' %} | ||||
| 					{% include('buttons.base.html.twig') %} | ||||
| 				</div> | ||||
| 			</td> | ||||
| 		</tr> | ||||
| 	</table> | ||||
| </form> | ||||
							
								
								
									
										58
									
								
								system/templates/account/lost/finish.new-email.html.twig
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										58
									
								
								system/templates/account/lost/finish.new-email.html.twig
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,58 @@ | ||||
| Your account name, new password and new e-mail.<br/> | ||||
| <table class="myaac-table" style="width: 100%;"> | ||||
|  | ||||
| 	<thead> | ||||
| 	<tr> | ||||
| 		<th class="white"> | ||||
| 			<b>Your account name, new password and new e-mail</b> | ||||
| 		</th> | ||||
| 	</tr> | ||||
| 	</thead> | ||||
|  | ||||
| 	<tbody> | ||||
| 	<tr> | ||||
| 		<td> | ||||
|  | ||||
| 			<table> | ||||
| 				<tr> | ||||
| 					<td> | ||||
| 						Account name: | ||||
| 					</td> | ||||
| 					<td> | ||||
| 						<b>{{ account.getName() }}</b> | ||||
| 					</td> | ||||
| 				</tr> | ||||
| 				<tr> | ||||
| 					<td> | ||||
| 						New password: | ||||
| 					</td> | ||||
| 					<td> | ||||
| 						<b>{{ newPassword }}</b> | ||||
| 					</td> | ||||
| 				</tr> | ||||
| 				<tr> | ||||
| 					<td> | ||||
| 						New e-mail address: | ||||
| 					</td> | ||||
| 					<td> | ||||
| 						<b>{{ newEmail }}</b> | ||||
| 					</td> | ||||
| 				</tr> | ||||
| 			</table> | ||||
|  | ||||
| 			{{ statusMsg|raw }} | ||||
| 		</td> | ||||
| 	</tr> | ||||
| 	</tbody> | ||||
|  | ||||
| </table> | ||||
| <br> | ||||
| <table style="width: 100%"> | ||||
| 	<tr> | ||||
| 		<td align="center"> | ||||
| 			<form action="{{ getLink('account/manage') }}" method="post"> | ||||
| 				{{ include('buttons.login.html.twig') }} | ||||
| 			</form> | ||||
| 		</td> | ||||
| 	</tr> | ||||
| </table> | ||||
							
								
								
									
										30
									
								
								system/templates/account/lost/finish.new-password.html.twig
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										30
									
								
								system/templates/account/lost/finish.new-password.html.twig
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,30 @@ | ||||
| New password to your account is below. Now you can log in.<BR> | ||||
| <table class="myaac-table" style="width: 100%;"> | ||||
|  | ||||
| 	<thead> | ||||
| 	<tr> | ||||
| 		<th class="white"><b>Changed password</b></th> | ||||
| 	</tr> | ||||
| 	</thead> | ||||
|  | ||||
| 	<tbody> | ||||
| 	<tr> | ||||
| 		<td> | ||||
| 			New password: <b>{{ newPassword }}</b><br/> | ||||
| 			Account name:   <i>(Already on your e-mail)</i><br/> | ||||
| 			{{ statusMsg|raw }} | ||||
| 		</td> | ||||
| 	</tr> | ||||
| 	</tbody> | ||||
| </table> | ||||
| <br/> | ||||
| <table style="width: 100%"> | ||||
| 	<tr> | ||||
| 		<td align="center"> | ||||
| 			<form action="{{ getLink('account/manage') }}"> | ||||
| 				{% set button_name = 'Login' %} | ||||
| 				{% include('buttons.base.html.twig') %} | ||||
| 			</form> | ||||
| 		</td> | ||||
| 	</tr> | ||||
| </table> | ||||
							
								
								
									
										43
									
								
								system/templates/account/lost/form.html.twig
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										43
									
								
								system/templates/account/lost/form.html.twig
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,43 @@ | ||||
| The Lost Account Interface can help you to get back your account name and password. Please enter your character name and select what you want to do.<br/> | ||||
| <form action="{{ getLink('account/lost/step-1') }}" method="post"> | ||||
|  | ||||
| 	{{ csrf() }} | ||||
|  | ||||
| 	<input type="hidden" name="character" value=""> | ||||
| 	<table class="myaac-table" style="width: 100%"> | ||||
| 		<thead> | ||||
| 		<tr> | ||||
| 			<th class="white"><b>Please enter your character name</b></th> | ||||
| 		</tr> | ||||
| 		</thead> | ||||
| 		<tbody> | ||||
| 			<tr> | ||||
| 				<td> | ||||
| 					<input type="text" name="nick" size="40" autofocus/><br> | ||||
| 				</td> | ||||
| 			</tr> | ||||
| 		</tbody> | ||||
| 	</table> | ||||
| 	<table style="width: 100%; border-spacing: 1px"> | ||||
| 		<tr> | ||||
| 			<td style="padding: 4px; background: {{ config('vdarkborder') }}" class="white"><b>What do you want?</b></td> | ||||
| 		</tr> | ||||
| 		<tr> | ||||
| 			<td style="padding: 4px; background: {{ config('darkborder') }}"> | ||||
| 				<input type="radio" name="action" id="action_type_email" value="email"> | ||||
| 				<label for="action_type_email"> Send me new password and my account name to account e-mail address.</label><br/> | ||||
| 				<input type=radio name="action" id="action_type_key" value="recovery-key"> | ||||
| 				<label for="action_type_key"> I got <b>recovery key</b> and want set new password and e-mail address to my account.</label><br/> | ||||
| 			</td> | ||||
| 		</tr> | ||||
| 	</table> | ||||
| 	<br/> | ||||
| 	<table style="width: 100%"> | ||||
| 		<tr> | ||||
| 			<td align="center"> | ||||
| 				{% set button_name = 'Submit' %} | ||||
| 				{% include('buttons.base.html.twig') %} | ||||
| 			</td> | ||||
| 		</tr> | ||||
| 	</table> | ||||
| </form> | ||||
							
								
								
									
										10
									
								
								system/templates/account/lost/no-action.html.twig
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										10
									
								
								system/templates/account/lost/no-action.html.twig
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,10 @@ | ||||
| Please select action.<br/> | ||||
| <table style="width: 100%"> | ||||
| 	<tr> | ||||
| 		<td align="center"> | ||||
| 			<a href="{{ getLink('account/lost') }}"> | ||||
| 				{{ include('buttons.back.html.twig') }} | ||||
| 			</a> | ||||
| 		</td> | ||||
| 	</tr> | ||||
| </table> | ||||
							
								
								
									
										53
									
								
								system/templates/account/lost/recovery-key.step-1.html.twig
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										53
									
								
								system/templates/account/lost/recovery-key.step-1.html.twig
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,53 @@ | ||||
| If you enter right recovery key you will see form to set new e-mail and password to account. To this e-mail will be send your new password and account name.<BR> | ||||
| <form action="{{ getLink('account/lost/recovery-key/step-2') }}" method="post"> | ||||
|  | ||||
| 	{{ csrf() }} | ||||
|  | ||||
| 	<table class="myaac-table" style="width: 100%;"> | ||||
|  | ||||
| 		<thead> | ||||
| 		<tr> | ||||
| 			<th class="white"> | ||||
| 				<b>Please enter your recovery key</b> | ||||
| 			</th> | ||||
| 		</tr> | ||||
| 		</thead> | ||||
|  | ||||
| 		<tbody> | ||||
| 		<tr> | ||||
| 			<td> | ||||
| 				<table> | ||||
| 					<tr> | ||||
| 						<td> | ||||
| 							<label for="nick">Character name:</label> | ||||
| 						</td> | ||||
| 						<td> | ||||
| 							<input type=text id="nick" name="nick" value="{{ nick }}" size="40" readonly="readonly"> | ||||
| 						</td> | ||||
| 					</tr> | ||||
| 					<tr> | ||||
| 						<td> | ||||
| 							<label for="key">Recovery key:</label> | ||||
| 						</td> | ||||
| 						<td> | ||||
| 							<input type="text" id="key" name="key" value="" size="40"> | ||||
| 						</td> | ||||
| 					</tr> | ||||
| 				</table> | ||||
| 			</td> | ||||
| 		</tr> | ||||
| 		</tbody> | ||||
|  | ||||
| 	</table> | ||||
| 	<br> | ||||
| 	<table style="width: 100%"> | ||||
| 		<tr> | ||||
| 			<td> | ||||
| 				<div style="text-align:center"> | ||||
| 					{% set button_name = 'Submit' %} | ||||
| 					{% include('buttons.base.html.twig') %} | ||||
| 				</div> | ||||
| 			</td> | ||||
| 		</tr> | ||||
| 	</table> | ||||
| </form> | ||||
							
								
								
									
										71
									
								
								system/templates/account/lost/recovery-key.step-2.html.twig
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										71
									
								
								system/templates/account/lost/recovery-key.step-2.html.twig
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,71 @@ | ||||
| Set new password and e-mail to your account.<br> | ||||
| <form action="{{ getLink('account/lost/recovery-key/step-3') }}" method="post"> | ||||
|  | ||||
| 	{{ csrf() }} | ||||
|  | ||||
| 	<input type="hidden" name="key" VALUE="{{ key }}"> | ||||
|  | ||||
| 	<input type="hidden" name="character" value=""> | ||||
| 	<table class="myaac-table" style="width: 100%"> | ||||
|  | ||||
| 		<thead> | ||||
| 		<tr> | ||||
| 			<th class="white"> | ||||
| 				<b>Please enter new password and e-mail</b> | ||||
| 			</th> | ||||
| 		</tr> | ||||
| 		</thead> | ||||
|  | ||||
| 		<tbody> | ||||
| 		<tr> | ||||
| 			<td> | ||||
|  | ||||
| 				<table> | ||||
| 					<tr> | ||||
| 						<td> | ||||
| 							<label for="nick">Account of character:</label> | ||||
| 						</td> | ||||
| 						<td> | ||||
| 							<input type="text" id="nick" name="nick" value="{{ nick }}" size="40" readonly="readonly"> | ||||
| 						</td> | ||||
| 					</tr> | ||||
| 					<tr> | ||||
| 						<td> | ||||
| 							<label for="password">New password:</label> | ||||
| 						</td> | ||||
| 						<td> | ||||
| 							<input type="password" id="password" name="password" value="" size="40"> | ||||
| 						</td> | ||||
| 					</tr> | ||||
| 					<tr> | ||||
| 						<td> | ||||
| 							<label for="password_repeat">Repeat new password:</label> | ||||
| 						</td> | ||||
| 						<td> | ||||
| 							<input type="password" id="password_repeat" name="password_repeat" value="" size="40"> | ||||
| 						</td> | ||||
| 					</tr> | ||||
| 					<tr> | ||||
| 						<td> | ||||
| 							<label for="email">New e-mail address:</label> | ||||
| 						</td> | ||||
| 						<td> | ||||
| 							<input type="text" id="email" name="email" value="" size="40"> | ||||
| 						</td> | ||||
| 					</tr> | ||||
| 				</table> | ||||
|  | ||||
| 			</td> | ||||
| 		</tr> | ||||
| 		</tbody> | ||||
| 	</table> | ||||
| 	<br> | ||||
| 	<table style="width: 100%"> | ||||
| 		<tr> | ||||
| 			<td align="center"> | ||||
| 				{% set button_name = 'Submit' %} | ||||
| 				{% include('buttons.base.html.twig') %} | ||||
| 			</td> | ||||
| 		</tr> | ||||
| </table> | ||||
| </form> | ||||
							
								
								
									
										10
									
								
								system/templates/mail.account.lost.code.html.twig
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										10
									
								
								system/templates/mail.account.lost.code.html.twig
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,10 @@ | ||||
| You asked to reset your {{ config('lua')['serverName'] }} password.<br/> | ||||
| <p>Account name: {{ account.getName() }}</p> | ||||
| <br/> | ||||
| To do so, please click this link: | ||||
| <p> | ||||
| 	<a href="{{ getLink('account/lost/check-code') }}?code={{ newCode }}&character={{ nick|urlencode }}">{{ getLink('account/lost/check-code') }}?code={{ newCode }}&character={{ nick|urlencode }}</a> | ||||
| </p> | ||||
| <p>or open page: <i>{{ getLink('account/lost/check-code') }}</i> and in field "code" write <b>{{ newCode }}</b></p> | ||||
| <br/> | ||||
| <p>If you did not request a password change, you may ignore this message and your password will remain unchanged. | ||||
							
								
								
									
										7
									
								
								system/templates/mail.account.lost.new-email.html.twig
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										7
									
								
								system/templates/mail.account.lost.new-email.html.twig
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,7 @@ | ||||
| <h3>Your account name and new password!</h3> | ||||
| <p>Changed password and e-mail to your account in Lost Account Interface on server <a href="{{ constant('BASE_URL') }}"><b>{{ config('lua')['serverName'] }}</b></a></p> | ||||
| <p>Account name: <b>{{ account.getName() }}</b></p> | ||||
| <p>New password: <b>{{ newPassword }}</b></p> | ||||
| <p>E-mail: <b>{{ newEmail }}</b> (this e-mail)</p> | ||||
| <br/> | ||||
| <p><u>It's automatic e-mail from OTS Lost Account System. Do not reply!</u></p> | ||||
| @@ -0,0 +1,6 @@ | ||||
| <h3>Your account name and password!</h3> | ||||
| <p>Changed password to your account in Lost Account Interface on server <a href="{{ constant('BASE_URL') }}"><b>{{ config('lua')['serverName'] }}</b></a></p> | ||||
| <p>Account name: <b>{{ account.getName() }}</b></p> | ||||
| <p>New password: <b>{{ newPassword }}</b></p> | ||||
| <br/> | ||||
| <p><u>It's automatic e-mail from OTS Lost Account System. Do not reply!</u></p> | ||||
		Reference in New Issue
	
	Block a user