2007-07-02 05:51:26 +00:00
|
|
|
<?php
|
2007-07-11 05:54:36 +00:00
|
|
|
$ignore = array("server", "username", "password");
|
|
|
|
if (ini_get("session.use_trans_sid") && isset($_POST[session_name()])) {
|
|
|
|
$ignore[] = session_name();
|
|
|
|
}
|
2007-07-02 05:51:26 +00:00
|
|
|
if (isset($_POST["server"])) {
|
2007-07-10 15:09:07 +00:00
|
|
|
if (isset($_REQUEST[session_name()])) {
|
|
|
|
session_regenerate_id();
|
|
|
|
$_SESSION["usernames"][$_POST["server"]] = $_POST["username"];
|
|
|
|
$_SESSION["passwords"][$_POST["server"]] = $_POST["password"];
|
2007-07-11 05:54:36 +00:00
|
|
|
if (count($_POST) == count($ignore)) {
|
2007-07-10 15:09:07 +00:00
|
|
|
if ((string) $_GET["server"] === $_POST["server"]) {
|
2007-07-11 05:54:36 +00:00
|
|
|
$location = preg_replace('~(\\?)' . urlencode(session_name()) . '=[^&]*&|[&?]' . urlencode(session_name()) . '=[^&]*~', '\\1', $_SERVER["REQUEST_URI"]);
|
2007-07-10 15:09:07 +00:00
|
|
|
} else {
|
|
|
|
$location = preg_replace('~^[^?]*/([^?]*).*~', '\\1', $_SERVER["REQUEST_URI"]) . (strlen($_POST["server"]) ? '?server=' . urlencode($_POST["server"]) : '');
|
|
|
|
}
|
|
|
|
if (strlen(SID)) {
|
|
|
|
$location .= (strpos($location, "?") === false ? "?" : "&") . SID;
|
|
|
|
}
|
|
|
|
header("Location: " . (strlen($location) ? $location : "."));
|
|
|
|
exit;
|
|
|
|
}
|
2007-07-06 15:24:49 +00:00
|
|
|
}
|
|
|
|
$_GET["server"] = $_POST["server"];
|
2007-07-02 15:52:29 +00:00
|
|
|
} elseif (isset($_GET["logout"])) {
|
2007-07-05 12:58:03 +00:00
|
|
|
unset($_SESSION["usernames"][$_GET["server"]]);
|
|
|
|
unset($_SESSION["passwords"][$_GET["server"]]);
|
2007-07-13 07:03:42 +00:00
|
|
|
unset($_SESSION["databases"][$_GET["server"]]);
|
2007-07-09 06:12:22 +00:00
|
|
|
$_SESSION["tokens"][$_GET["server"]] = array();
|
2007-07-10 15:09:07 +00:00
|
|
|
redirect(substr($SELF, 0, -1), lang('Logout successful.'));
|
2007-07-02 05:51:26 +00:00
|
|
|
}
|
|
|
|
|
2007-07-10 15:09:07 +00:00
|
|
|
if (!isset($_SESSION["usernames"][$_GET["server"]]) || !$mysql->connect($_GET["server"], $_SESSION["usernames"][$_GET["server"]], $_SESSION["passwords"][$_GET["server"]])) {
|
2007-07-11 08:19:41 +00:00
|
|
|
if ($_POST["token"] && !isset($_SESSION["usernames"][$_GET["server"]])) {
|
2007-07-11 08:03:08 +00:00
|
|
|
$_POST["token"] = token();
|
|
|
|
}
|
2007-07-06 08:47:20 +00:00
|
|
|
page_header(lang('Login'));
|
2007-07-10 15:09:07 +00:00
|
|
|
if (isset($_SESSION["usernames"][$_GET["server"]])) {
|
2007-07-02 05:51:26 +00:00
|
|
|
echo "<p class='error'>" . lang('Invalid credentials.') . "</p>\n";
|
2007-07-10 15:09:07 +00:00
|
|
|
} elseif (isset($_POST["server"])) {
|
|
|
|
echo "<p class='error'>" . lang('Sessions must be enabled.') . "</p>\n";
|
2007-07-11 06:16:43 +00:00
|
|
|
} elseif ($_POST) {
|
|
|
|
echo "<p class='error'>" . lang('Session expired, please login again.') . "</p>\n";
|
2007-07-02 05:51:26 +00:00
|
|
|
}
|
|
|
|
?>
|
|
|
|
<form action="" method="post">
|
|
|
|
<table border="0" cellspacing="0" cellpadding="2">
|
|
|
|
<tr><th><?php echo lang('Server'); ?>:</th><td><input name="server" value="<?php echo htmlspecialchars($_GET["server"]); ?>" maxlength="60" /></td></tr>
|
2007-07-10 13:30:42 +00:00
|
|
|
<tr><th><?php echo lang('Username'); ?>:</th><td><input name="username" value="<?php echo htmlspecialchars($_SESSION["usernames"][$_GET["server"]]); ?>" maxlength="16" /></td></tr>
|
2007-07-02 05:51:26 +00:00
|
|
|
<tr><th><?php echo lang('Password'); ?>:</th><td><input type="password" name="password" /></td></tr>
|
|
|
|
<tr><th><?php
|
|
|
|
foreach ($_POST as $key => $val) { // expired session
|
2007-07-06 15:24:49 +00:00
|
|
|
if (is_array($val)) {
|
2007-07-02 05:51:26 +00:00
|
|
|
foreach ($val as $key2 => $val2) {
|
|
|
|
if (!is_array($val2)) {
|
2007-07-09 06:12:22 +00:00
|
|
|
echo '<input type="hidden" name="' . htmlspecialchars($key . "[$key2]") . '" value="' . htmlspecialchars($val2) . '" />';
|
2007-07-02 05:51:26 +00:00
|
|
|
} else {
|
|
|
|
foreach ($val2 as $key3 => $val3) {
|
2007-07-09 06:12:22 +00:00
|
|
|
echo '<input type="hidden" name="' . htmlspecialchars($key . "[$key2][$key3]") . '" value="' . htmlspecialchars($val3) . '" />';
|
2007-07-02 05:51:26 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
2007-07-11 05:54:36 +00:00
|
|
|
} elseif (!in_array($key, $ignore)) {
|
2007-07-06 15:24:49 +00:00
|
|
|
echo '<input type="hidden" name="' . htmlspecialchars($key) . '" value="' . htmlspecialchars($val) . '" />';
|
2007-07-02 05:51:26 +00:00
|
|
|
}
|
|
|
|
}
|
2007-07-09 06:12:22 +00:00
|
|
|
foreach ($_FILES as $key => $val) {
|
|
|
|
echo '<input type="hidden" name="files[' . htmlspecialchars($key) . ']" value="' . ($val["error"] ? $val["error"] : base64_encode(file_get_contents($val["tmp_name"]))) . '" />';
|
|
|
|
}
|
2007-07-06 15:24:49 +00:00
|
|
|
?></th><td><input type="submit" value="<?php echo lang('Login'); ?>" /></td></tr>
|
2007-07-02 05:51:26 +00:00
|
|
|
</table>
|
|
|
|
</form>
|
|
|
|
<?php
|
|
|
|
page_footer("auth");
|
|
|
|
exit;
|
|
|
|
}
|
2007-07-10 13:30:42 +00:00
|
|
|
$mysql->query("SET SQL_QUOTE_SHOW_CREATE=1");
|