I tried both the quotes and HEREDOC and couldn't get either to work.
This is the error Call to undefined function form() do I need to isolate the form in some way?
Code:
// $userid must be an integer that matches a valid user's ID.
function reset_password($userid) {
query("delete from reset_password where userid = $userid");
$key = substr(base64_encode(crypt('', '')), 0, 32);
query("insert into reset_password values ($userid, '$key', " . time() . ")");
// fetch is my own wrapper function to fetch a row from the query.
$f = fetch(query("select username from organisermembers where id = $userid"));
// smtp is my own function, you will probably want to use the php mail function.
smtp(
"do-not-reply@example.com", // sender
$f['username'], // recepient
"From: The example.com Web Site <do-not-reply@example.com>\r\n" . // email headers
"To: {$f['username']} <{$f['username']}>\r\n" . // actual email address <put a nice friendly name in here if you have the the information>
'Subject: Reset Password' . "\r\n" .
"\r\n" .
"Hello\r\n" . // email body
"\r\n" .
"A request has been made to reset your example.com web site password.\r\n" .
"\r\n" .
"To complete the request, click on the following link within 48 hours of the transmision of this email and follow the on screen instructions.\r\n" .
"\r\n" .
/// URL is defined as the root of the URL used in the email, in this example it would be "http://example.com/"
URL . "resetpassword.php?page=reset-password" . urlencode($userid) . "&key=" . urlencode($key) . "\r\n" .
"\r\n" .
"Kind regards,\r\n" .
"\r\n" .
"The example.com Web Site"
);
}
// form, input_hidden, table, tr, td, label, input_password and input_submit are my own wrappers which return the appropriate HTML with escaped values where required.
echo
form('reset-password/ok',
input_hidden('userid', $_GET['userid']) .
input_hidden('key', $_GET['key']) .
table(
tr(
td(label('New Password')) .
td(input_password('new_password', ''))
) .
tr(
td(label('Confirm Password')) .
td(input_password('confirm_password', ''))
)
) .
input_submit('ok', 'OK')
);
// The reset_password_message function displays the message to the user.
if (!isset($_POST['userid'])) {
reset_password_message('You must enter a user ID. Please try again.');
} else if (!isset($_POST['key'])) {
reset_password_message('You must enter a key. Please try again.');
} else if (!isset($_POST['new_password']) || !$_POST['new_password']) {
reset_password_message('You must enter a new password. Please try again');
} else if (!isset($_POST['confirm_password']) || $_POST['new_password'] != $_POST['confirm_password']) {
reset_password_message('The new password and the confirmation do not match. Please try again.');
} else if (!$f = fetch(query("select time from reset_password where userid = " . (integer)$_POST['userid'] . " and key = '" . escape($_POST['key']) . "'"))) {
reset_password_message('The user ID and key pair are invalid. Please try again.');
} else if ($f['time'] < time() - 60 * 60 * 24 * 2) { // 60 seconds * 60 minutes * 24 hours * 2 days (48 hours as explained in the email sent to the user above).
reset_password_message('The user ID and key pair have expired. Please try again.');
} else {
query("update organisermembers set password = '" . crypt($_POST['new_password']) . "' where id = " . (integer)$_POST['userid']);
reset_password_message('Your password has been reset. Please login.');
}
?>
Bookmarks