aboutsummaryrefslogtreecommitdiff
path: root/backend/forget.php
blob: 9f6f543ba64cf95e8ac7603cad8072bcdf9d24f2 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
<?php
/* hitler-clicker
 * api for account deletion
 * © 2025 hitler.rip <git@hitler.rip>
 * licensed under AGPLv3-or-later; see LICENSE.md for more information
 */

header('Content-Type: application/json; charset=UTF-8');

try {
	$pdo = new PDO("mysql:host=127.0.0.1;dbname=hitlerclicker", "root", "aA1234Aa");
} catch(PDOException $e) {
	die('{ "status": "database offline" }');
};

$wrkarr = [];
$ifarr = [ "name", "password" ];
$postjson = json_decode(file_get_contents('php://input'), true);
foreach ($ifarr as $i):
	if (isset($postjson[$i])):
		$newarr = [
			"$i" => "$postjson[$i]",
		];
		$wrkarr = array_merge($wrkarr, $newarr);
	endif;
endforeach;

if (!isset($wrkarr["name"]) || trim($wrkarr["name"]) == ""):
	die('{ "status": "login (name) was not provided.\ncould not attempt to forget." }');
elseif (!isset($wrkarr["password"]) || trim($wrkarr["password"]) == ""):
	die('{ "status": "password was not provided.\ncould not attempt to forget." }');
else:

	$query = $pdo->prepare("SELECT name, password, team, clicks FROM users WHERE name LIKE ?");
	$query -> execute([$wrkarr["name"]]);
	$found = $query->fetch(PDO::FETCH_ASSOC);
	if ($found):

		if (!password_verify($wrkarr["password"], $found["password"])):
			die('{ "status": "wrong password." }');
		else:

			$forgottenclicks = $found["clicks"];

			$query = $pdo->prepare("SELECT team, clicks, fromanon FROM stats WHERE team LIKE ?");
			$query -> execute([$found["team"]]);
			$found = $query->fetch(PDO::FETCH_ASSOC);

			$oldanonclicks = $found["fromanon"];
			$newanonclicks = $oldanonclicks + $forgottenclicks;

			$query = $pdo->prepare("UPDATE stats SET fromanon = :fromanon WHERE stats.team = :team");
			$query -> execute([
				"fromanon" => "$newanonclicks",
				"team" => "$found[team]"
			]);

			$query = $pdo->prepare("DELETE FROM users WHERE name LIKE ?");
			$query -> execute([$wrkarr["name"]]);

			die("{ \"status\": \"success\", \"fc\": \"$forgottenclicks\", \"nac\": \"$newanonclicks\" }");

		endif;

	else:
		die('{ "status": "name does not exist in the database." }');
	endif;

endif;

?>