<?php
//Session  START
session_start();
session_regenerate_id();
?>
<?php
//Includes
require_once 'connect.php';
require_once 'validate.php';
?>
<?php
if (isset($_POST['btn'])) {
if($_SERVER["REQUEST_METHOD"]=="POST") {
	//connect
	$dbcon = new mysqli($DB_HOST,$DB_USER,$DB_PSWD,$DB_NAME);
	if ($dbcon->connect_error){die('err connecting');}
	//good continue, clean form
	$temp_group = cleandata($_POST["groupusr"]);
	$temp_grkey = cleandata($_POST["groupkey"]);
	$temp_usern = cleandata($_POST["username"]);
	//query
	$query = "select * from user where eventname ='$temp_group'";
	$result = $dbcon->query($query);
	$good=false;
	if ($result->num_rows ==1) {
		$result->data_seek(0);
		$row = $result->fetch_array(MYSQLI_ASSOC);
		if ($row['eventmstr']==$temp_usern)	{
			$token = hash('sha256',$temp_grkey.$row['eventsalt']);
			$base64 = base64_encode(pack('H*',$token));  //this converts hext to base 64
			if ($base64==$row['eventkey']){$good=true;$temp_useri=$row['userid'];}
		}
		else {
			$token = hash('sha256',$temp_grkey.$row['publicsalt']);
			$base64 = base64_encode(pack('H*',$token));  //this converts hext to base 64
			if ($base64==$row['publickey'])	{$good=true;$temp_useri=$row['userid'];}
		}
	}	
	if (strlen($temp_usern)<3)
	{
		$good=false;
	}
	if ($good) {
		session_start();
		$_SESSION["type"] = "not_master";
		if ($row['eventmstr']==$temp_usern)	{$_SESSION["type"] = "master";}
		$_SESSION["timestamp"] = time();
		$_SESSION["group"] = cleandata($_POST["group"]);
		$_SESSION["username"] = cleandata($_POST["username"]);
		$_SESSION["userid"] = cleandata($temp_useri);
		if ( $_SESSION["type"] == "master"){
			header("Location:  /event/masterevent"); //redirect to index.php
		}
		else {
			header("Location:  /event/myevent"); //redirect to index.php
		}
	}
	else {
		$_SESSION['logged_in'] = "Invalid entry";
		//echo "Invalid entry";
	}
}
}
?>
<?php
//Re-Direct to HTTPS if needed
if(isset($_SERVER['HTTPS'])) {
	if ($_SERVER['HTTPS'] == "on") {}
   // else { header("Location:  https://blazeritcom.fatcow.com/event"); } //redirect to index.php 
}
//else { header("Location:  https://blazeritcom.fatcow.com/event"); }//redirect to index.php
?>

<!DOCTYPE html>
<html>
<head><link rel="stylesheet" type="text/css" href="event.css" /></head>
<body class="mainclass">
<BR>Please Type in Your Event Group Name<BR><BR>
<form name="test1" method="POST" action="<?php echo htmlspecialchars($_SERVER["PHP_SELF"]);?>">
<table class="mainclass">
<table class="mainclass">
<tr><td>GROUP: </td><td><input class="txtbox" name="groupusr" type="text"    ></input></td></tr>
<tr><td> KEY : </td><td><input class="txtbox" name="groupkey" type="password"></input></td></tr>
<tr><td>INITS: </td><td><input class="txtbox" name="username" type="text"    ></input></td></tr>
</table>
<br>
<input name="btn" class="buttons" type="submit" value="ENTER"></input>
</table>
</form>

<?php
//Display Logoff Message
if (isset($_SESSION['logged_in'])){echo $_SESSION['logged_in'];}
$_SESSION['logged_in'] = "";
?>

</body>
</html>