<?php
ini_set('display_errors', 1);
ini_set('display_startup_errors', 1);
error_reporting(E_ALL);
include(dirname(__FILE__).'/db.php');
$user_id_cookie = isset($_COOKIE['user_id']) ? $_COOKIE['user_id'] : '';
$user_pass_cookie = isset($_COOKIE['user_pass']) ? $_COOKIE['user_pass'] : '';
// Защита от SQL-INJ
$user_id_cookie = mysqli_real_escape_string($conn, $user_id_cookie);
$user_pass_cookie = mysqli_real_escape_string($conn, $user_pass_cookie);
$result = mysqli_query($conn, "SELECT id, password FROM users WHERE id = '$user_id_cookie'");
if ($result) {
$row = mysqli_fetch_assoc($result);
if ($row['password'] === $user_pass_cookie) {
$user_result = mysqli_query($conn, "SELECT * FROM users WHERE id = '".$row['id']."'");
if ($user_result) {
$user = mysqli_fetch_assoc($user_result);
}
}
}
include(dirname(__FILE__).'/func.php');