isLoggedOn()) { $loggedon = true; $currentUser = $userservice->getCurrentUser(); $currentUserID = $userservice->getCurrentUserId(); $currentUsername = $currentUser[$userservice->getFieldName('username')]; } if ($user) { if (is_int($user)) { $userid = intval($user); } else { $user = urldecode($user); if (!($userinfo = $userservice->getUserByUsername($user))) { $tplVars['error'] = sprintf(T_('User with username %s was not found'), $user); $templateservice->loadTemplate('error.404.tpl', $tplVars); exit(); } else { $userid =& $userinfo['uId']; } } } else { $tplVars['error'] = T_('Username was not specified'); $templateservice->loadTemplate('error.404.tpl', $tplVars); exit(); } if ($user == $currentUsername) { $title = T_('My Profile'); } else { $title = T_('Profile') .': '. $user; } $tplVars['pagetitle'] = $title; $tplVars['subtitle'] = $title; $tplVars['user'] = $user; $tplVars['userid'] = $userid; if (isset($_POST['submitted']) && $currentUserID == $userid) { $error = false; $detPass = trim($_POST['pPass']); $detPassConf = trim($_POST['pPassConf']); $detName = trim($_POST['pName']); $detMail = trim($_POST['pMail']); $detPage = trim($_POST['pPage']); $detDesc = filter($_POST['pDesc']); // manage token preventing from CSRF vulnaribilities if ( !isset($_SESSION['token'], $_SESSION['token_stamp']) || time() - $_SESSION['token_stamp'] > 600 //limit token lifetime, optionnal || $_SESSION['token'] != $_POST['token']) { $error = true; $tplVars['error'] = T_('Invalid Token'); } if ($detPass != $detPassConf) { $error = true; $tplVars['error'] = T_('Password and confirmation do not match.'); } if ($detPass != "" && strlen($detPass) < 6) { $error = true; $tplVars['error'] = T_('Password must be at least 6 characters long.'); } if (!$userservice->isValidEmail($detMail)) { $error = true; $tplVars['error'] = T_('E-mail address is not valid.'); } if (!$error) { if (!$userservice->updateUser($userid, $detPass, $detName, $detMail, $detPage, $detDesc)) { $tplvars['error'] = T_('An error occurred while saving your changes.'); } else { $tplVars['msg'] = T_('Changes saved.'); } } $userinfo = $userservice->getUserByUsername($user); } if ($currentUserID != $userid) { $templatename = 'profile.tpl.php'; } else { //Token Init $_SESSION['token'] = md5(uniqid(rand(), true)); $_SESSION['token_stamp'] = time(); $templatename = 'editprofile.tpl.php'; $tplVars['formaction'] = createURL('profile', $user); $tplVars['token'] = $_SESSION['token']; } $tplVars['row'] = $userinfo; $templateservice->loadTemplate($templatename, $tplVars); ?>