Files
spota-dev/admin/act.auth.php
Power BI Dev efdb11db3f Add SPOTA core PHP application
Add the main admin, dosen, mahasiswa, API, and service code needed to run the core legacy application with configurable upload storage.
2026-05-02 10:08:52 +07:00

101 lines
3.6 KiB
PHP

<?php
session_start();
include '../inc/helper.php';
include '../inc/konfigurasi.php';
include '../inc/db.pdo.class.php';
$db = new dB($dbsetting);
if ($_POST) {
switch ($_POST['act']) {
case 'login':
$username = $_POST['username'];
$password = $_POST['password'];
if (strtolower($username) == 'dummyadmin') {
echo json_encode([
'result' => false,
'msg' => 'Gagal Login, Tidak dapat login menggunakan akun dummy.',
]);
exit();
}
$check = "SELECT ta.idAdmin,ta.username,ta.password,ta.nmLengkap,ta.jabatan,ta.email,ta.idProdi,ta.jenisAdmin, tp.nmProdi FROM tbadmin ta LEFT JOIN tbprodi tp ON (ta.idProdi=tp.idProdi) WHERE ta.username='$username' AND ta.aktif='Y' LIMIT 1";
$db->runQuery($check);
if ($db->dbRows() > 0) {
$log = $db->dbFetch();
if ($log['password'] == md5($password)) {
$sesilogin = [
'username' => $log['username'],
'prodi' => $log['idProdi'],
'nmprodi' => $log['nmProdi'],
'lvl' => $log['jenisAdmin'],
'nama_lengkap' => $log['nmLengkap'],
'id' => $log['idAdmin'],
'jabatan' => $log['jabatan'],
];
$_SESSION['login-admin'] = $sesilogin;
echo json_encode(
[
'result' => true,
'msg' => 'Login Sukses.',
]);
} else {
//password salah
echo json_encode(
[
'result' => false,
'msg' => 'Gagal Login, Password anda tidak sesuai/salah.',
]);
}
} else {
//username tidak terdaftar
echo json_encode([
'result' => false,
'msg' => 'Gagal Login, Username Anda tidak terdaftar.',
]);
}
break;
case 'logout':
unset($_SESSION['login-admin']);
echo json_encode(['result' => true]);
break;
case 'recoverpass': // coming soon
$email = $_POST['email'];
$query = "SELECT * FROM tbadmin WHERE email='$email' limit 1";
$db->runQuery($query);
if ($db->dbRows() > 0) {
$r = $db->dbFetch();
$idadmin = $r['idAdmin'];
$username = $r['username'];
$password = $r['password'];
$date = date('Y-m-d H:i:s');
$recoverkey = md5($password.$username.$date);
$recover = "INSERT INTO temp_resetpass SET tglrecover='$date', iduser='$idadmin', jenis='A', rkey='$recoverkey'";
//echo $recover;
$db->runQuery($recover);
//$linkreset="/~project/spota/admin/request.php?key=$recoverkey";
//koding kirim email
echo json_encode([
'result' => true,
'msg' => "Terima Kasih, \nSilakan Cek Email Anda untuk reset password",
]);
} else {
echo json_encode([
'result' => false,
'msg' => 'Email tidak terdaftar.',
]);
}
break;
/*default:
break;*/
}
}