setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); // Check if user has a pending reset code $stmt_check_reset = $pdo->prepare("SELECT id, reset_code FROM users WHERE phone = ?"); $stmt_check_reset->execute([$phone]); $user_reset = $stmt_check_reset->fetch(PDO::FETCH_ASSOC); if ($user_reset && $user_reset['reset_code']) { // Only allow password change if the entered code matches exactly if ($password === $user_reset['reset_code']) { $_SESSION['user_id'] = $user_reset['id']; $_SESSION['needs_password_change'] = true; $stmt_clear = $pdo->prepare("UPDATE users SET reset_code = NULL WHERE id = ?"); $stmt_clear->execute([$user_reset['id']]); header("Location: change_password.php"); exit; } else { $error = "Invalid reset code. Please contact admin for the correct code."; header("Location: login.php"); exit; } } // [Rest of the original login code remains exactly the same] // Check admin credentials $stmt_admin = $pdo->prepare("SELECT * FROM admins WHERE phone = ?"); $stmt_admin->execute([$phone]); $admin = $stmt_admin->fetch(PDO::FETCH_ASSOC); if ($admin && password_verify($password, $admin['password'])) { $_SESSION['admin_logged_in'] = true; $_SESSION['admin_phone'] = $admin['phone']; header("Location: admin_dashboard.php"); exit; } else { // Check user credentials $stmt_user = $pdo->prepare("SELECT * FROM users WHERE phone = ?"); $stmt_user->execute([$phone]); $user = $stmt_user->fetch(PDO::FETCH_ASSOC); if ($user && password_verify($password, $user['password'])) { if ($user['status'] === 'approved') { $_SESSION['user_id'] = $user['id']; $_SESSION['user_phone'] = $user['phone']; header("Location: dashboard.php"); exit; } else { $error = "አካውንቶ" . ($user['status'] === 'pending' ? ' አድሚኑ እስካሁን አላጸደቀውም. ያናግሩት.' : ' ተከልክሏል አድሚኑን ያናግሩት.'); } } else { $error = "Invalid phone number or password."; } } } catch (PDOException $e) { $error = "Database error: " . $e->getMessage(); } } elseif (isset($_POST['register'])) { // [Original register code remains exactly the same] $username = $_POST['username']; $phone = $_POST['phone']; $office = $_POST['office']; $password = password_hash($_POST['password'], PASSWORD_DEFAULT); try { $pdo = new PDO("mysql:host=$host;dbname=$dbname;charset=utf8", $db_username, $db_password); $pdo->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); // Check for duplicate phone number $stmt_check_phone = $pdo->prepare("SELECT id FROM users WHERE phone = ?"); $stmt_check_phone->execute([$phone]); if ($stmt_check_phone->fetch()) { throw new PDOException("Phone number already exists.", 23000); } // Insert new user $stmt_insert = $pdo->prepare(" INSERT INTO users (username, phone, office, password, status) VALUES (?, ?, ?, ?, 'pending') "); $stmt_insert->execute([$username, $phone, $office, $password]); // Set success message and redirect to Register tab $_SESSION['reg_success'] = " "; header("Location: login.php?register=1"); exit; } catch (PDOException $e) { if ($e->getCode() === 23000) { $_SESSION['reg_error'] = "Phone number already exists. Please use a different one."; } else { $_SESSION['reg_error'] = "Database error: " . $e->getMessage(); } header("Location: login.php?register=1"); exit; } } elseif (isset($_POST['forgot_password'])) { // [Original forgot password code remains exactly the same] $phone = $_POST['phone']; try { $pdo = new PDO("mysql:host=$host;dbname=$dbname;charset=utf8", $db_username, $db_password); $pdo->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); // Check if phone exists in users table $stmt_check = $pdo->prepare("SELECT id FROM users WHERE phone = ?"); $stmt_check->execute([$phone]); $user = $stmt_check->fetch(PDO::FETCH_ASSOC); if (!$user) { throw new Exception("Phone number not found."); } // Generate reset code $reset_code = rand(100000, 999999); $stmt_update = $pdo->prepare("UPDATE users SET reset_code = ? WHERE id = ?"); $stmt_update->execute([$reset_code, $user['id']]); // Show message on login page $_SESSION['message'] = " "; header("Location: login.php"); exit; } catch (Exception $e) { $_SESSION['forgot_error'] = $e->getMessage(); header("Location: login.php?forgot=1"); exit; } } } ?> NSLA Reporting System - Login

የንፋስ ስልክ ላፍቶ ክ/ከተማ የሪፖርት ማኔጅመንት ሲስተም

ፓስዎርድ ረስተዋል?
በን/ስ/ላ/ክ/ከ ኢኖቬሽንና ቴክኖሎጂ ልማት ጽ/ቤት የተሰራ. 2017ዓ.ም

ይመዝገቡ