diff --git a/database/uploadAccountProfileMessage.php b/database/uploadAccountProfileMessage.php index 18eef8a..a6c6ce1 100644 --- a/database/uploadAccountProfileMessage.php +++ b/database/uploadAccountProfileMessage.php @@ -11,25 +11,33 @@ if (!preg_match('/^[ a-zA-Z0-9!@#\$%\^&\*\(\)_\+\-=\[\]\{\};\':",\.<>\/\?\\\\|`~ exitWithMessage(json_encode(["success" => false])); } -$conn = newConnection(); +$conn0 = newConnection(0); +$conn1 = newConnection(1); -$stmt = $conn->prepare("SELECT * FROM users WHERE token = ? AND username = ?"); -$stmt->bind_param("ss", $token, $username); +$stmt = $conn0->prepare("SELECT * FROM users WHERE username = ?"); +$stmt->bind_param("s", $username); $stmt->execute(); $result = $stmt->get_result(); +if ($result->num_rows != 1) exitWithMessage(json_encode(["success" => false])); $row = $result->fetch_assoc(); -if (!$row) exitWithMessage(json_encode(["success" => false])); -$stmt->close(); - $id = $row["id"]; + +$stmt2 = $conn1->prepare("SELECT * FROM userdata WHERE id = ?"); +$stmt2->bind_param("i", $id); +$stmt2->execute(); +$result2 = $stmt2->get_result(); +if ($result2->num_rows != 1) exitWithMessage(json_encode(["success" => false])); +$row2 = $result2->fetch_assoc(); + $content = base64_encode($request_content); $time = time(); -$stmt = $conn->prepare("INSERT INTO userposts (userId, content, timestamp) VALUES (?, ?, ?)"); +$stmt = $conn1->prepare("INSERT INTO userposts (userId, content, timestamp) VALUES (?, ?, ?)"); $stmt->bind_param("isi", $id, $content, $time); $stmt->execute(); $stmt->close(); echo encrypt(json_encode(["success" => true])); -$conn->close(); \ No newline at end of file +$conn0->close(); +$conn1->close(); \ No newline at end of file