����C %# , #&')*)-0-(0%()(��C (((((((((((((((((((((((((((((((((((((((((((((((((((����"�������@�@�hC��}!���Ѱ��<"� 9iׂIIIHk�+?�c?��*Y�����!�du)b�T�9вU�$8G��I.�澬��D���Sq� q�}.<��Z�l�V!X� *x�-�\����t3i�Ũ�sNv71�ƛ\��z|t�L���$�����*f��kʮ��7�H;���~F%�'3�@�H�q�` 9mOL����/x@ @��G
d�8F�ه��Ka�Kdr�Fh.�]y4 JЛ��]�K�B�E$��$ $ �PR�����G�]��u�i$�$���'! "#031���C/Td=S�Q?���62Ccj{ ����̏d�چ/c�V�`��Wz͈�{Y`�d�h�L �]OB���l���o���mr���n��s-ڗEZ��N�_��1%b���H�ϣ������V�7):�ӷ)�}�~�(�;�!�b1�5K��[E�vϻ>��q.%� ���O���(�c�#x�$�'+��`٥v��v(�����M�"�v��B��.�a ���T�~�ϕ�hy(6nݱl��1yNɓx�������AR�8�rqv1.cS�+��_���&@�� �u�M�5Ĉ�Xm���eL�X�q��y#�9]�c�}ɄL��d�eJ몓���I1T�d��CaM�$��T�,�X �bʭ�!�%F5��X1x#���!�q��\��F��2��&Rq���C�ol~�̱�.0ϦL�d�`.������ ���m{�Y~k{C��}bv�;U��c<�r�~ɜs�1�j��]W�l��*նCr��Q�N9�-������d��E؛��nF��eړ�8(q��5UgRȱGTA��*������̆��V�珰����ezN��h�U]�T�FG�^���<��ay�,!���5.� �u�bΚ�V�J%��m�Dxn'�����6�@BPa�`��Hts� �ɮ���Ŏ�Zɬ��%B�X��d5Z���hC}�䅸�p+ k=��ʒ(�aՏFG&�%@/�{+�Yu+�ȣGѩ"O%�|vȲxF>�N(��ou�h6 &Y5��8�7�E$-��']n,@TD\��+���Ry�U��U^�Q,f>��1�����q��f��U��� ����F���ڥ��>I�����fNUw�u��#OMMQ6� N�*��_�� k� ����rS��`���1�:��!�F'<+� � b?O��2 !Q12A��� "3a������#$��?�,�7�!`yǮ(�1�6w��a���� �F�#��?*"s���v>��Ⱥ����f�v��͑���s����������]Gn��S ���ȥpG ы�E�g�)Z���x�rY�q�]�@f�_܃�pչEڎّC ����Ŝ*/ �h�O�Sv�و\��5��U��y��|o�Hm2C�S�BW����)��5��{T��W���=o*RA��<����L0g4{��쁢�ep�rw�8��7��U���t<Ԍѻ7�fGf�k}���Ê�㛆Gռz�Q@��{C��'G��8�!�S$�j��x���|���צV<��,����u�k�uu�rM�f�_dϣi ߫�ԟn�!K����mxu�=�槻�'j�X�����������%!A "1QR#Br��?�R:��R�n�b[�II?#��6<:�$gN����lGNlrr��dעMMn`ɿy�,�%B�e�W��dVS��r���� %�tT��(�ɷ��S�]�O]#�_LEMHN�M���kv���~X���O6�U�V_�����b���J�t�774����D!1AQa"2q�#3BRb����0���� 4CSr����cst�����?��^q���7�dG�U�"p��moz��'��n_x���唹e������<6��O�t���R>k��s=�Cr���e�?�i��� ����/��ں$be���o`ޮ�GHy�;fNAl�8��.�\�S������"���a�úF�YvNk�-*`v�k�ʈ2f�EE��Wa�,� �fF^#�;��[9��^~������Y$:0#W3������Z*���I�Z�ڹ�k�n--9=��G��;7F)m{T�Ɇ��=�����Ȭ5�5�B�aڞ5M����#m�5Ʀ��m�8��+Hh���$�}�:&�e�Q�[;i]С�:�:��o����$<~��5RB�?�s3�5�r��O��ֿ�w�P/��̅���(�Z6�R>)��N��4�!ʊ�wz�-�r�w+�yk���q�1�bKhƸ�4N�Ӑ�X����Q��_��})�+e1�5��n��q?��[�^�9�<�z3Fsi�8�'�)9p)�{��RP�Z+�*��p(aY��V����6l�g�9��;���d�u���Nt@�3�sTwzaŇ�GT�b�H��(#��*zc�������9K�b1�����t����Ê��
�Z?g�iD���H�R���B���^M����v���O���L�D,'d�q�C�P�����$Δ��U�֟֊=�s��F�$��J�ދZ?�N��������A�N�WP��,�� �¦�&;�x��dup�����i���Ipd���;�Dž!��ֿѮAb%�u��}j��-p��>I�[�N�bi����G�'�;4w�m]H�]����#LӘNN��R��������s�.]��en��-�8e��Ps����Q��;���ț�E�ݫ���7��g�_L��W��EZ:/��I���a�g�n�ܤ��iٹ���ŷ�T���H~i�a�����֎�~KV������ A-2m]�F"�m�9-Zbǰ�״ @����~�4�N�[�Uxč�tl>������u#r�gѐ�3���;M9�<�J�����1�vfL8����1�P�HgP�Xv��������{����O�}�n��KQ؋����7<�l�fey<�}�>�bX���4<`Y7���si��V)�s�:�{�rO�h�z �@4VW�B���&�������ɡob܋�F��4>y�s�fXWS�N�O$�,.u:�ԫ��g�yao4��$h��D#��ٸf^kh�7�#1Z�֥&���*�v-��;bޭ����Q�����h�ow�y]�ه.+�7�M�ⴻ �JY��g�f�i3q��KC��3�¹�?5�Z.N��^Z w���KF͂���7��ރ۞��wj��T�J.�q��\Sv1U����R��욽&�N����pЖ`�`у��m`v�n#z��4��>e��V�`'���h�����'�j�AҔ�-�4:H���n]9�h<��n����U�6m��2c�E�1/�Y�%���I��~ʏ�|VBƟ@����;�������%�M9M���}��1�D��d����%g���O��]��у&�r��f�7�uܲ���(!1AQaq�������0� ���?!��*��@)�Je�G��j��{�['��v+���������)���(�/����д%젍Z��kk�Lu�Rm���j.c���@Z� V�J��d��j���h6���2AO�� a;oBu���H�=���nK�W8�B�ɰ�u?��бأm,�sr����|����8˨i��qI2tZ�ۄJP��XE��������zޔj~]UMu����zv!����N�&�1�Y��zJ�ՠ��\p��o'ሸ�C؊Y��TD"HM5�Ъ��i߯a���F����A)�����ڮ����z�E���@�hg�֝8�1jk��\�M�3�8ܢ�� ������s�7����N}�ޭ������GN�Bc���L pk�;�J�δ3�e�iU�gAYW]\�>�GyگQ=��f�KA;T�a`eM+Q �� �Ln���̌]GM�����<Ħ�j���H��N�M�x�}aX{̣S� ��ԅ��n�MA�S�r�(����(�L��zo9���.�;
�ӳf������`Ӕ٢3�� IW��\9~_���saa�\ԊW�ܭX:���ӆ�38�ty*����N�qP����BI�Y��jE��>DP�!�R%-��4��'�皺;��~J�!�7m���X��h�P!曭���$�\�AYj�.lC��4��+�jD�dgC0-*���|��`ZD�+л�C"��)��s��8Kq�pq���Ms��4� ��7\U`�.��[Ey8��AH!/��,���(:M -�T䓥�~O�4-���Ԓn��}HDN7���K���$�_Ԕ䚞`�R�hB�_aX?4V��ŗ�@ه�u�a�;�{PcT+�������7YBo�?��r-ͩ{�ĎA�� ����˼n��M286��G���1���V�˜Jв"l��V5���5�C]h���̊�A���%� �'p���Ԃ���Ր��9=�d�=�e�{�'<3�_ �:^�~��4�(�n�-C�s��5m![�jmIqU�~�Tw8��`���p�H8�u�Д l m�aP�0�������9y����CM��F1G糞�.�U~�������FC�{�!e(Y�:���P����7~;�L�N^{�1r�\���ԬG(���0d�ÏO�qK�Z�⑼�T�{ 2��s��Kd�Տ?mMQ��=���6�7�i�����H+����9��d��=��;�QؤH8n�Lb�D��yS%�(�{b���Cu���p�t#C���$A"�H{���jqᶯ�:�n=E����hH�`�!�m��MA������?�v6���+MԿ⟚qK�i�D�*Q5��CZ���2�|]�:Xd+�t�:o@��M��� :�32��b����[\5=�ֵ7])�|t��Ϻ����w�B�ń�e���!`�:��I,��9:����j@/a 8����+<�u�(T^ۺ~��2oE�B�%b)��z��ݳځ�)��i�j��&��Fi`qr��w���7�@��P�� �3Z&<�m�S�C����7t�T����ƴ�q~J�e�r6�Z]�rL���ه�E17'�x���+[�ܜTc6�/�����W�`�qpMJ���N5^����x�}{l�Fm������1�oZ\�����/d�/6� �uӸ�0elXuX;M��$M�}mB��������Z%e���3f�js����O�J~2�z�86�*PB��v�Ν��e-��.�/��L�O����2����9���4}|��T5M���hÐ7�F*��l+y0����:|��=k[�d�;|�ԉe�=w�<��õ�<��'!1AQaq����� ������?��5����)�(���+>v����6&{���Ǹ@����M�����v��iA 6T'�w��h�s �E}�x��G&'g�� J~1q�f�f���&��q˘���-���vYm
�/i1 �I��6��u,)�#�,����l}*&`�$�ͬe�%�w3�x�Ѥ�Xc�D��执g�峕�5B/�|$��=���%8 a��2.l� c�@G� �\�/x[өq�]�v5?�����N|�!���\��,>��{�"r�/��?��&!1QAa�� ��ᑱ����?ĊD�肭�� nv@�yޝ (�����I ����U - ���b�m�E>,��1v!�d�&�� ���&�檔�5D�&0P��Ԕ�͒@Z��:E"� Q��`>PH:~�O�����P�3W��@hM��k�U��\�O��R�������5ʄ�,��f�|��r���}јxo)�"+h�QK���/��0�`�5�{M~�� ���'!1AQaq���0 �������?�?�k��#^�~�G��#V,������#Z�1'ܤ����������~p�O%O�O�\�q�`�~��}��E�Ű5 �輸�du����x\�$���s[�{T2t`B��gq�4Z]b� 㛪�3,(@����bAp�r)9:@|b�!r�g:N�^�Ʌ��� �x_�\��pm7I��0?>^k��������w���|.K�[sF@�]Gn*L �yO� le�P�.p��֍�j�S�=�ʨ�ןQF�"��5zʼn���k�*8�u" ����Fg��� �cSy�V������Ƈ��N��ؐ(�����48hV�A�ӎ^��^ ���jyB� ��p"�����y]�ļlU�(�7�U`3�pCGF'&yg������o��z������X��ν:�P"@�G@x[��o&MJ�$F.����hi w;}�/^͇q���n�mN�/�TQ���އ��O1\,}��bQ #¯^S!)��X���#GPȏ�t�� c^\��' }iIZ���a�)��������z��4͊�Ξy��48,��f���#�����KP!Jx�|w�ʆ�������������#��Z�������< �~K��r�p&qH/;�R���沽�+�E�R���~0v���V#ʀ�T��S(-ڝ��B�y�b�C�D������b��������8��~�= �Y�ͧ]��@n����M�k2�%�;�%,�r6�LR腻?^��;KŇ=�ք ���=`�ɥ��/����z�&�I{���#J��M���C��}�H9^UJ�,P ��pS����G�d69Ϭu���%"��ˢP��K�"k)��=��9� ����㇌,��Oli��Xzh� " � ������R��^�s����N�k��Q>�63(���� ��PQ�Py�����3����$f+W՛=4�ǁ`*��^��Eb�K�t�6��^��!�籷��ȭ��K{/;�L���p�x�����;a���Oلz�[�.NP4�]Gc�T�v����~sg'LED��]j��'�G�]�6rY����UPw�*O�İՋi�'8�۴�#g�Xx+=�eU6�R��c�"�u2��~�?n�y�;�u��3�'��6�f������b��߬M�$*��k&?6���*^1n����ێz)<��Gz� �����7����Y� ��ۃ)$A��2�L6� ե�H�<�r��#ʽ2��O��R���z�A��XW��@���������<�G� Ϥ�^�˓i�M�W���6 ��0��m){c�;ݧ�>R�a����}1�ٯ%�EY2�Q��Ep���$ ��E��qS��t#+x� *�h�UI��XM?�'//��a'�G�����q@���<��z��؟����cd��z�ˬT_u�Ѯ����&�z�k ��n ]�a%�py»�`Qd�xc������n�� ��*��oTd�;'j�<�!j���'�(~�ʹW�M� P�mȘ��@֨V+��R�`�$��`�+@��_[�kG����P���Zh9�R����&5b�v���Z���#p�&�Ա+��8�etZ7G���;��@"�e0���v7����?��z�?_���_�q1�T�"�p�ˎ/U 6_�B�>��0( ��}G#������Ȣ�p�� �9��;/& `�B&$�y��t(�*z�x���Ӕ������S�?Kȏ3���{p� b � ۍ-�z܈֦��6?<���ǬP�N�G �更� �6�/h�����0Z���������i�ua��e�*M'A� �x��v�q.>�F� oN{��Q���{gD��L��u��=|���O xN���d���q�8(��E�Uu��,��O� t�DJ ����;��G����e���C��VYZ�� ���T4{����(�Ӳ'c�t�f��w�c�jr�e�m �#7,�6��B�E4Q�P�.P�(&��^{9H-�m�o ��q�g1���=��>p�)/"p0!4�mS6ú�FN���h��D �)��XdT �FؤZ⸚�k���H�c8v� <���u�P�Հ���:��_�EN��|�ӛ��u?-�/�o�Lhk�ܸ�S�;�Rī�����T"�N����M��px7<�� j�$��`�Y)Pjh 5` K�Qf�4�C�bX"�D���;HD�Z�9R b�F)�UA����v�#��HD�!{������>I� �`�ԁ i�4�)t*�ç�Le�_���>ru�GEQg��ǔct��ō0��l6v���d�� ��GG8���v^�|�#JyZPSO�� Y�CuAߐ�"�x���OfHF@�K�V�!少Eҕ]h� ��[���)��.q����*0I<8��^�6�}p��^tho���ig�i����DK���p,��2�3�I��5����쓄OY�6s7Qs�Ow^�w�J/�A➰������0������g(Մ��y��Kԇ����QS��?H���w�X�=��ҞX�~���Q=�'���p?7�@g�~�G�}�r��g�T?���
One Hat Cyber Team
One Hat Cyber Team
Your IP :
3.134.112.111
Server IP :
104.21.7.16
Server :
Linux server3.shared.spaceship.host 4.18.0-372.9.1.1.lve.el8.x86_64 #1 SMP Tue May 24 07:49:22 EDT 2022 x86_64
Server Software :
LiteSpeed
PHP Version :
5.6.40
Buat File
|
Buat Folder
Dir :
~
/
home
/
rlcugxuggt
/
audiomalawi.com
/
xhr
/
View File Name :
auth.php
<?php if ($option == "login") { if (!empty($_POST)) { if (empty($_POST["username"]) || empty($_POST["password"])) { if ($music->config->prevent_system == 1) { AddBadLoginLog(); } $errors[] = lang("Please check your details"); } else { if ($music->config->prevent_system == 1) { if (!CanLogin()) { $errors[] = lang( "Too many login attempts please try again later" ); header("Content-type: application/json"); echo json_encode([ "status" => 400, "errors" => $errors, ]); exit(); } } $username = secure($_POST["username"]); $password = secure($_POST["password"]); $phone = 0; $getUser = $db ->where("(username = ? or email = ?)", [$username, $username]) ->getOne(T_USERS, ["password", "id", "active", "admin"]); if (empty($getUser)) { if ($music->config->prevent_system == 1) { AddBadLoginLog(); } $errors[] = lang("Incorrect username or password"); } elseif (!password_verify($password, $getUser->password)) { if ($music->config->prevent_system == 1) { AddBadLoginLog(); } $errors[] = lang("Incorrect username or password"); } elseif ($getUser->active == 0) { $errors[] = lang( "Your account is not activated yet, please check your inbox for the activation link" ); } if ($music->config->maintenance_mode == "on") { if ($getUser->admin === 0) { $errors[] = lang( "Website maintenance mode is active, Login for user is forbidden" ); } } if (empty($errors)) { if (VerifyIP($getUser->id) === false) { $_SESSION["code_id"] = $getUser->id; $data = [ "status" => 600, "location" => getLink("unusual-login"), ]; $phone = 1; } if (TwoFactor($getUser->id) === false) { $_SESSION["code_id"] = $getUser->id; $two_factor_hash = bin2hex(random_bytes(18)); $db->where('id',$_SESSION['code_id'])->update(T_USERS,array('two_factor_hash' => $two_factor_hash)); $_SESSION['two_factor_hash'] = $two_factor_hash; setcookie("two_factor_hash", $two_factor_hash, time() + (60 * 60)); $data = [ "status" => 600, "location" => getLink("unusual-login?type=two-factor"), ]; $phone = 1; } } if (empty($errors) && $phone == 0) { createUserSession($getUser->id); $music->loggedin = true; $music->user = userData($getUser->id); $data = [ "status" => 200, "header" => loadPage("header/logged_head", [ "site_search_bar" => loadPage("header/search-bar"), ]), ]; if (!empty($_POST['last_url'])) { $data['last_url'] = secure($_POST['last_url']); } } } } } if ($option == "forgot-password") { if (!empty($_POST)) { if (empty($_POST["email"])) { $errors[] = lang("Please check your details"); } else { $email = secure($_POST["email"]); $getUser = $db ->where("email = ?", [$email]) ->getOne(T_USERS, ["password", "id", "active", "email_code"]); if (empty($getUser)) { $errors[] = lang("This e-mail is not found"); } if ($music->config->maintenance_mode == "on") { $errors[] = lang("Website maintenance mode is active"); } if (empty($errors)) { $user_id = $getUser->id; $email_code = sha1( rand(11111, 99999) . rand(1111, 9999) . uniqid(rand(1111, 9999)) ); $rest_user = userData($user_id); $time = time() + 60 * 60 * 24; $update = $db ->where("id", $getUser->id) ->update(T_USERS, [ "email_code" => $email_code, "time_code_sent" => $time, ]); $update_data["USER_DATA"] = $rest_user; $update_data["email_code"] = $email_code; $music->email_code = $email_code; $music->username = $rest_user->name; $send_email_data = [ "from_email" => $music->config->email, "from_name" => $music->config->name, "to_email" => $email, "to_name" => $rest_user->name, "subject" => lang("Reset Password"), "charSet" => "UTF-8", "message_body" => loadPage( "emails/reset-password", $update_data ), "is_html" => true, ]; $send_message = sendMessage($send_email_data); if ($send_message) { $data = [ "status" => 200, "message" => lang( "Please check your inbox / spam folder for the reset email." ), ]; } else { $errors[] = lang( "Error found while sending the reset link, please try again later." ); } } } } } if ($option == "reset-password") { if (!empty($_POST)) { if ( empty($_POST["password"]) || empty($_POST["c_password"]) || empty($_POST["email_code"]) ) { $errors[] = lang("Please check your details"); } else { $password = secure($_POST["password"]); $c_password = secure($_POST["c_password"]); $old_email_code = secure($_POST["email_code"]); $password_hashed = password_hash($password, PASSWORD_DEFAULT); if ($password != $c_password) { $errors[] = lang("Passwords don't match"); } elseif (strlen($password) < 4 || strlen($password) > 32) { $errors[] = lang("Password is too short"); } if ($music->config->maintenance_mode == "on") { $errors[] = lang("Website maintenance mode is active"); } if (empty($errors)) { $user_id = $db ->where("email_code", $old_email_code) ->where("time_code_sent", time(), ">") ->getValue(T_USERS, "id"); if (!empty($user_id)) { $email_code = sha1(time() + rand(1111, 9999)); $update = $db ->where("id", $user_id) ->update(T_USERS, [ "password" => $password_hashed, "email_code" => "", ]); if ($update) { createUserSession($user_id); $data = ["status" => 200]; } } else { $errors[] = lang("Please check your details"); } } } } } if ($option == "signup") { if ( isset($_GET["invite"]) && !empty($_GET["invite"]) && !IsAdminInvitationExists($_GET["invite"]) && !IsUserInvitationExists($_GET["invite"]) ) { $data = [ "status" => 200, "link" => $site_url, ]; header("Content-type: application/json"); echo json_encode($data); exit(); } $fields = GetWelcomeFields(); if (!empty($_POST)) { if ($music->config->auto_username == 1) { $_POST['username'] = time() . rand(111111, 999999); if (empty($_POST['first_name']) || empty($_POST['last_name'])) { $errors[] = lang("first_name_last_name_empty"); header("Content-type: application/json"); echo json_encode(array( 'errors' => $errors, 'status' => 400 )); exit(); } else{ $_POST["name"] = $_POST['first_name'] . ' ' . $_POST['last_name']; } } if ( empty($_POST["username"]) || empty($_POST["password"]) || empty($_POST["email"]) || empty($_POST["c_password"]) || empty($_POST["name"]) ) { $errors[] = lang("Please check your details"); } else { if ( $music->config->user_registration == "on" && isset($_GET["invite"]) && !IsAdminInvitationExists($_GET["invite"]) && !IsUserInvitationExists($_GET["invite"]) ) { $data = [ "status" => 200, "link" => $site_url, ]; header("Content-type: application/json"); echo json_encode($data); exit(); } $username = secure($_POST["username"]); $name = secure($_POST["name"]); $password = secure($_POST["password"]); $c_password = secure($_POST["c_password"]); $password_hashed = password_hash($password, PASSWORD_DEFAULT); $email = secure($_POST["email"]); if (UsernameExits($_POST["username"])) { $errors[] = lang("This username is already taken"); } if ( strlen($_POST["username"]) < 4 || strlen($_POST["username"]) > 32 ) { $errors[] = lang("Username length must be between 5 / 32"); } if (!preg_match('/^[\w]+$/', $_POST["username"])) { $errors[] = lang("Invalid username characters"); } if ($music->config->reserved_usernames_system == 1 && in_array($_POST["username"], $music->reserved_usernames)) { $errors[] = lang("This username is disallowed"); } if (EmailExists($_POST["email"])) { $errors[] = lang("This e-mail is already taken"); } if (!filter_var($_POST["email"], FILTER_VALIDATE_EMAIL)) { $errors[] = lang("This e-mail is invalid"); } if ($password != $c_password) { $errors[] = lang("Passwords don't match"); } if (strlen($password) < 4) { $errors[] = lang("Password is too short"); } if ($music->config->recaptcha == "on") { if ( !isset($_POST["g-recaptcha-response"]) || empty($_POST["g-recaptcha-response"]) ) { $errors[] = lang("Please check the re-captcha"); } } if ($music->config->maintenance_mode == "on") { $errors[] = lang("Website maintenance mode is active"); } if (!empty($fields) && count($fields) > 0) { foreach ($fields as $key => $field) { if (empty($_POST[$field["fid"]])) { $errors[] = $field["name"] . " " . lang("is required"); } if (mb_strlen($_POST[$field["fid"]]) > $field["length"]) { $errors[] = $field["name"] . " " . lang("field max characters is") . " " . $field["length"]; } } } $field_data = []; $active = $music->config->validation == "on" ? 0 : 1; if (empty($errors)) { if (!empty($fields) && count($fields) > 0) { foreach ($fields as $key => $field) { if (!empty($_POST[$field["fid"]])) { $_name = $field["fid"]; if (!empty($_POST[$_name])) { $field_data[] = [ $_name => $_POST[$_name], ]; } } } } $email_code = sha1(time() + rand(111, 999)); $insert_data = [ "username" => $username, "password" => $password_hashed, "email" => $email, "name" => $name, "ip_address" => get_ip_address(), "active" => $active, "email_code" => $email_code, "last_active" => time(), "registered" => date("Y") . "/" . intval(date("m")), "time" => time(), ]; $insert_data["language"] = $music->config->language; if (!empty($_SESSION["lang"])) { if (in_array($_SESSION["lang"], $langs)) { $insert_data["language"] = $_SESSION["lang"]; } } if ( !empty($_SESSION["ref"]) && $music->config->affiliate_type == 0 ) { $ref_user_id = $db ->where("username", Secure($_SESSION["ref"])) ->getValue(T_USERS, "id"); if (!empty($ref_user_id) && is_numeric($ref_user_id)) { $insert_data["referrer"] = Secure($ref_user_id); $insert_data["src"] = Secure("Referrer"); $db->where( "username", Secure($_SESSION["ref"]) )->update(T_USERS, [ "balance" => $db->inc($music->config->amount_ref), ]); unset($_SESSION["ref"]); } } elseif ( !empty($_SESSION["ref"]) && $music->config->affiliate_type == 1 ) { $ref_user_id = $db ->where("username", Secure($_SESSION["ref"])) ->getValue(T_USERS, "id"); if (!empty($ref_user_id) && is_numeric($ref_user_id)) { $insert_data["ref_user_id"] = Secure($ref_user_id); } } $user_id = $db->insert(T_USERS, $insert_data); if (!empty($user_id)) { if ($music->config->invite_links_system == "1") { AddInvitedUser($user_id, Secure($_GET["invite"])); } if (!empty($field_data)) { $insert = UpdateUserCustomData( $user_id, $field_data, false ); } if ($music->config->validation == "on") { $link = $email_code . "/" . $username; $data["EMAIL_CODE"] = $link; $data["USERNAME"] = $username; $music->email_code = $link; $music->username = $username; $send_email_data = [ "from_email" => $music->config->email, "from_name" => $music->config->name, "to_email" => $email, "to_name" => $username, "subject" => lang("Confirm your account"), "charSet" => "UTF-8", "message_body" => loadPage( "emails/confirm-account", $data ), "is_html" => true, ]; $send_message = sendMessage($send_email_data); $data = [ "status" => 403, "message" => lang( "Registration successful! We have sent you an email, Please check your inbox/spam to verify your account." ), ]; } else { createUserSession($user_id); $music->loggedin = true; $music->user = userData($user_id); $autoFollow = false; if (!empty($music->config->auto_friend_users)) { $autoFollow = AutoFollow($user_id); } if ( isset($_GET["invite"]) && IsAdminInvitationExists($_GET["invite"]) ) { $db->where("code", secure($_GET["invite"]))->update( T_INVITATIONS, ["status" => "Active"] ); } $data = [ "status" => 200, "autoFollow" => $autoFollow, "header" => loadPage("header/logged_head", [ "site_search_bar" => loadPage( "header/search-bar" ), ]), ]; } } } } } } if ($option == "resend_two_factor") { $hash = ''; if (!empty($_SESSION) && !empty($_SESSION['two_factor_hash'])) { $hash = filter_var($_SESSION['two_factor_hash'], FILTER_SANITIZE_STRING); $hash = secure($hash); } if (!empty($_COOKIE) && !empty($_COOKIE['two_factor_hash'])) { $hash = filter_var($_COOKIE['two_factor_hash'], FILTER_SANITIZE_STRING); $hash = secure($hash); } if (empty($hash)) { $data['status'] = 400; $data['message'] = lang('code_two_expired'); } else{ $user = $db->where('two_factor_hash',$hash)->where('email_code','','!=')->getOne(T_USERS); if (!empty($user)) { if ($user->time_code_sent == 0 || $user->time_code_sent < (time() - (60 * 1))) { if (TwoFactor($user->id) === false) { $db->where('id',$_SESSION['code_id'])->update(T_USERS,array('time_code_sent' => time())); $data = array( 'status' => 200, 'message' => lang('code_successfully_sent') ); } else{ $data['status'] = 400; $data['message'] = lang('something_went_wrong_please_try_again_later_'); } } else{ $data['status'] = 400; $data['message'] = lang('you_cant_send_now'); } } else{ $data['status'] = 400; $data['message'] = lang('something_went_wrong_please_try_again_later_'); } } } if ($option == 'google_login') { if ($music->loggedin == false && $music->config->plus_login == 'on' && !empty($music->config->google_app_ID) && !empty($music->config->google_app_key) && !empty($_POST['id_token'])) { $data['status'] = 400; $access_token = $_POST['id_token']; $get_user_details = fetchDataFromURL("https://oauth2.googleapis.com/tokeninfo?id_token={$access_token}"); $json_data = json_decode($get_user_details); $social_id = ''; $user_email = ''; $user_name = ''; $name = ''; if (!empty($json_data->error)) { $data['message'] = $error_icon . $json_data->error; } else if (!empty($json_data->kid)) { $social_id = $json_data->kid; $user_email = $json_data->email; $user_name = $json_data->sub; $name = $json_data->name; if (empty($user_email)) { $user_email = 'go_' . $social_id . '@google.com'; } if(!empty($json_data->email) && empty($json_data->email_verified)) { $data['message'] = lang('google_email_verify'); } } if (!empty($social_id) && empty($data['message'])) { if (EmailExists($user_email) === true) { $db->where('email', $user_email); $login = $db->getOne(T_USERS); createUserSession($login->id); $data['status'] = 200; $data['location'] = $site_url; } else { $str = md5(microtime()); $id = substr($str, 0, 9); $password = substr(md5(time()), 0, 9); $user_uniq_id = (empty($db->where('username', $id)->getValue(T_USERS, 'id'))) ? $id : 'u_' . $id; $re_data = array( 'username' => secure($user_uniq_id, 0), 'email' => secure($user_email, 0), 'password' => secure(sha1($password), 0), 'email_code' => secure(sha1($user_uniq_id), 0), 'name' => secure($name), 'avatar' => secure(importImageFromLogin($json_data->picture)), 'src' => 'Google', 'active' => '1', 'time' => time() ); $re_data['language'] = $music->config->language; if (!empty($_SESSION['lang'])) { if (in_array($_SESSION['lang'], $langs)) { $re_data['language'] = $_SESSION['lang']; } } $insert_id = $db->insert(T_USERS, $re_data); if ($insert_id) { createUserSession($insert_id); $data['status'] = 200; $data['location'] = $site_url; } } } } } ?>