setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); // Check if user has a pending reset code $stmt_check_reset = $pdo->prepare("SELECT id, reset_code FROM users WHERE phone = ?"); $stmt_check_reset->execute([$phone]); $user_reset = $stmt_check_reset->fetch(PDO::FETCH_ASSOC); if ($user_reset && $user_reset['reset_code']) { // Only allow password change if the entered code matches exactly if ($password === $user_reset['reset_code']) { $_SESSION['user_id'] = $user_reset['id']; $_SESSION['needs_password_change'] = true; $stmt_clear = $pdo->prepare("UPDATE users SET reset_code = NULL WHERE id = ?"); $stmt_clear->execute([$user_reset['id']]); header("Location: change_password.php"); exit; } else { $error = "Invalid reset code. Please contact admin for the correct code."; header("Location: login.php"); exit; } } // [Rest of the original login code remains exactly the same] // Check admin credentials $stmt_admin = $pdo->prepare("SELECT * FROM admins WHERE phone = ?"); $stmt_admin->execute([$phone]); $admin = $stmt_admin->fetch(PDO::FETCH_ASSOC); if ($admin && password_verify($password, $admin['password'])) { $_SESSION['admin_logged_in'] = true; $_SESSION['admin_phone'] = $admin['phone']; header("Location: admin_dashboard.php"); exit; } else { // Check user credentials $stmt_user = $pdo->prepare("SELECT * FROM users WHERE phone = ?"); $stmt_user->execute([$phone]); $user = $stmt_user->fetch(PDO::FETCH_ASSOC); if ($user && password_verify($password, $user['password'])) { if ($user['status'] === 'approved') { $_SESSION['user_id'] = $user['id']; $_SESSION['user_phone'] = $user['phone']; header("Location: dashboard.php"); exit; } else { $error = "አካውንቶ" . ($user['status'] === 'pending' ? ' አድሚኑ እስካሁን አላጸደቀውም. ያናግሩት.' : ' ተከልክሏል አድሚኑን ያናግሩት.'); } } else { $error = "Invalid phone number or password."; } } } catch (PDOException $e) { $error = "Database error: " . $e->getMessage(); } } elseif (isset($_POST['register'])) { // [Original register code remains exactly the same] $username = $_POST['username']; $phone = $_POST['phone']; $office = $_POST['office']; $password = password_hash($_POST['password'], PASSWORD_DEFAULT); try { $pdo = new PDO("mysql:host=$host;dbname=$dbname;charset=utf8", $db_username, $db_password); $pdo->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); // Check for duplicate phone number $stmt_check_phone = $pdo->prepare("SELECT id FROM users WHERE phone = ?"); $stmt_check_phone->execute([$phone]); if ($stmt_check_phone->fetch()) { throw new PDOException("Phone number already exists.", 23000); } // Insert new user $stmt_insert = $pdo->prepare(" INSERT INTO users (username, phone, office, password, status) VALUES (?, ?, ?, ?, 'pending') "); $stmt_insert->execute([$username, $phone, $office, $password]); // Set success message and redirect to Register tab $_SESSION['reg_success'] = "