<?php
session_start();
include_once 'config.php';
// include_once 'src/clicktoconnect.php';
if(isset($_POST["oldpassword"])&&isset($_POST["password"])&& !empty($_POST["password"])){
if($_POST["oldpassword"]!=$_POST["password"]&& !empty($_POST["password"])){
$req=$bdd->prepare('UPDATE users SET
password=:password
WHERE user_id=:user_id AND password=:oldpass');
$req->bindValue(':user_id',$_SESSION["user_id"],PDO::PARAM_INT);
$req->bindValue(':password',sha1(Salt.$_POST["password"].Salt),PDO::PARAM_STR);
$req->bindValue(':oldpass',sha1(Salt.$_POST["oldpassword"].Salt),PDO::PARAM_STR);
$req->execute();
if($req->rowCount()>0){
echo 'success';
$req->CloseCursor();
}else{
echo "Failed";
$req->CloseCursor();
}
}else{
echo "Password unchanged as you enter the same thing as the old one";
}
}else{
echo "Failed";
}
?>
|