Файл: titwar.ru/save.php
Строк: 63
<?
include './system/common.php';
include './system/functions.php';
include './system/user.php';
if(!$user) {
header('location: /');
exit;
}
if($user['save'] == 1) {
header('location: /');
exit;
}
$title = 'Save character';
include './system/h.php';
$login = _string($_POST['login']);
$password = _string($_POST['password']);
$sex=_string($_POST['sex']);
$r=_string($_POST['r']);
if($login && $password) {
if(!preg_match('/[a-z0-9а-я]{2,20}/i', $login)) $errors = 'Error, username is invalid';
if(!preg_match('/[a-z0-9]{2,20}/i', $password)) $errors = 'Error, password is invalid';
if(strlen($login)<2 OR strlen($login)>20)$errors='Error, login must have 2-20 characters';
if(mysql_result(mysql_query('SELECT COUNT(*) FROM `users` WHERE `login` = ''.$login.'''),0) != 0) $errors = 'Error, username has been already registered';
if($errors) {
echo '<div class='content' align='center'>';
echo $errors.'<br/>';
echo '</div>
<div class='line'></div>';
}
else
{
mysql_query('UPDATE `users` SET `login` = ''.$login.'',
`password` = ''.$password.'',
`save` = '1',
`r`=''.$r.'',
`sex`=''.$sex.'',
`g` = `g` + 300 WHERE `id` = ''.$user['id'].''');
setCookie('password', $password, time() + 86400, '/');
header('location: /');
}
}
echo '
<div class='line'></div>
<div class='content' align='center'>
<form action='/save/' method='post'>
Имя героя:<br/>
<input name='login' value=''.$login.''/><br/>
Пароль:<br/>
<input name='password' value=''.$password.''/><br/>';
?>
Sex:<br/>
<select name ='sex'>
<option value='0'>Male</option>
<option value='1'>Female</option>
</select><br/>
Race:<br/>
<select name ='r'>
<option value='0'>Asura</option>
<option value='1'>Boreas</option>
</select><br/>
<?
echo '
<input type='submit' value='Save'/>
</form>
</div>
<div class='line'></div>
';
include './system/f.php';
?>