//config domain
//$domainname=strtolower(str_replace("www.depotnew.raspund.ro","",$_SERVER['HTTP_HOST']));
$domainname='cninew.ngp.ro';
$config_site_url='https://'.$domainname.'/'; //mandatory to end with /
$config_site_short_url=''.$domainname.'';
$config_domain_name=''.$domainname;
//end config domain
//admin
$config_admin_url='https://'.$domainname.'/admin';
//database
$dbhost = 'localhost';
$dbname = 'ngp_cni';
$dbuser = 'ngp_cni';
$dbpass = 'CbzdGrZveaNx';
$cniKey='cnikCFSA%#Q#bzdCbzdGrZve@$%!%@#!%@#aNxGrZveaNx';
//config denumire cat
$config_denumire_pagini='pag';
global $config_denumire_categorii;
$config_denumire_categorii='produse';
$config_denumire_produs='produs';
$config_tva_produs=20;
$dir=$config_site_url;
$GLOBALS['dir']=$dir;
$config_site_name='Compania Nationala de Investitii S.A.';
//pages config
$catname='cat';
$subcatname='subcat';
$subsubname='produse';
$pagname='pag';
$prodname='produs';
//modalitate plata
//OP
$config_numerar_op_active=0; //1-activ 0-dezactivat;
//company details
$config_furnizor_bank=' ';
$config_furnizor_company_details='';
//other
$dir=$config_site_url;
//analytics
$config_analytics="";
?>
class users
{
function profileUpdate($tip=0) //0 parola si marketing, 1-personal, 2 - profesional
{
$db=new bazaDate();
$smarty=$GLOBALS['smarty'];
if ($_POST['step']=='updateDatePersonale')
{
$smarty->assign('mesajSucces',"Datele au fost actualizate
");
if ($_POST['adresaCorespondenta']!='')
$db->simpleQuery("UPDATE users set adresaCorespondenta='".$db->cleanVar($_POST['adresaCorespondenta'])."' where id='".$_SESSION['userId']."' LIMIT 1");
else $errors['adresaCorespondenta']='Nu ati completat adresa';
if ($_POST['judet']>0)
$db->simpleQuery("UPDATE users set judet='".$db->cleanVar($_POST['judet'])."' where id='".$_SESSION['userId']."' LIMIT 1");
if ($_POST['localitate']>0)
$db->simpleQuery("UPDATE users set localitate='".$db->cleanVar($_POST['localitate'])."' where id='".$_SESSION['userId']."' LIMIT 1");
}
if ($_POST['step']=='updateDatePersonale' and $tip==1)
{
$telefonInvalid=0;
if (strlen($_POST['phone'])!=10) { $errors['telefon']='Telefon invalid'; $error=1;$telefonInvalid=1; }
else
{
$telefon=$_POST['phone'];
for ($i=0; $i<=9; $i++)
{
if (!is_numeric($telefon[$i])) { $errors['telefon']='Telefon invalid'; $error=1;$telefonInvalid=1; break;}
}
}
if ($telefonInvalid!=1)
$db->simpleQuery("UPDATE users set phone='".$db->cleanVar($_POST['phone'])."' where id='".$_SESSION['userId']."' LIMIT 1");
if (strlen($_POST['lastName'])<3) { $errors['nume']='Numele este obligatoriu'; $error=1; }
else $db->simpleQuery("UPDATE users set lastName='".$db->cleanVar($_POST['lastName'])."' where id='".$_SESSION['userId']."' LIMIT 1");
if (strlen($_POST['prenume'])<3) { $errors['prenume']='Prenumele este obligatoriu'; $error=1; }
else $db->simpleQuery("UPDATE users set firstName='".$db->cleanVar($_POST['prenume'])."' where id='".$_SESSION['userId']."' LIMIT 1");
}
if ($_POST['step']=='updateDateProfesionale' and $tip==2)
{
$smarty->assign('mesajSucces',"Datele au fost actualizate
");
if ($_POST['ocupatia']>0)
{
$db->simpleQuery("UPDATE users set ocupatia='".$db->cleanVar($_POST['ocupatia'])."' where id='".$_SESSION['userId']."' LIMIT 1");
if ($_POST['specializare']>0)
$db->simpleQuery("UPDATE users set specializarea='".$db->cleanVar($_POST['specializare'])."' where id='".$_SESSION['userId']."' LIMIT 1");
}
$db->simpleQuery("UPDATE users set specializarea2='".$db->cleanVar($_POST['specializare2'])."' where id='".$_SESSION['userId']."' LIMIT 1");
$db->simpleQuery("UPDATE users set nrMinori='".$db->cleanVar($_POST['nrMinori'])."' where id='".$_SESSION['userId']."' LIMIT 1");
if ($_POST['titluUniversitar']>0)
$db->simpleQuery("UPDATE users set titluUniversitar='".$db->cleanVar($_POST['titluUniversitar'])."' where id='".$_SESSION['userId']."' LIMIT 1");
$db->simpleQuery("UPDATE users set codParafa='".$db->cleanVar($_POST['codParafa'])."' where id='".$_SESSION['userId']."' LIMIT 1");
$cuimInvalid=0;
if ($_POST['ocupatia']==1 or $_POST['ocupatia']==6)
if (strlen($_POST['cuim'])!=10) { $errors['cuim']='CUIM invalid'; $error=1; $cuimInvalid=1;}
else
{
$telefon=$_POST['cuim'];
for ($i=0; $i<=9; $i++)
{
if (!is_numeric($telefon[$i])) { $errors['cuim']='CUIM invalid'; $error=1; $cuimInvalid=1; break;}
}
}
if ($cuimInvalid!=1)
$db->simpleQuery("UPDATE users set cuim='".$db->cleanVar($_POST['cuim'])."' where id='".$_SESSION['userId']."' LIMIT 1");
if (strlen($_POST['denumireaInstitutiei'])>5)
$db->simpleQuery("UPDATE users set denumireaInstitutiei='".$db->cleanVar($_POST['denumireaInstitutiei'])."' where id='".$_SESSION['userId']."' LIMIT 1");
else { $errors['denumireaInstitutiei']='Denumire Invalida'; $error=1;}
if (strlen($_POST['adresaInstitutiei'])>5)
$db->simpleQuery("UPDATE users set adresaInstitutiei='".$db->cleanVar($_POST['adresaInstitutiei'])."' where id='".$_SESSION['userId']."' LIMIT 1");
else { $errors['adresaInstitutiei']='Adresa Invalida'; $error=1;}
if ($_POST['judetInstitutie']>0)
{
$db->simpleQuery("UPDATE users set judetInstitutie='".$db->cleanVar($_POST['judetInstitutie'])."' where id='".$_SESSION['userId']."' LIMIT 1");
if ($_POST['localitateInstitutie']>0)
$db->simpleQuery("UPDATE users set localitateInstitutie='".$db->cleanVar($_POST['localitateInstitutie'])."' where id='".$_SESSION['userId']."' LIMIT 1");
}
}
$smarty->assign('errors',$errors);
if ($tip==0)
{
if ($_POST['step']=='updatePassAndMarketing')
{
$error=0;
$db->simpleQuery("UPDATE users set acordSms='".$db->cleanVar($_POST['acordSms'])."', acordPosta='".$db->cleanVar($_POST['acordPosta'])."', acordEmail='".$db->cleanVar($_POST['acordEmail'])."' where id='".$_SESSION['userId']."' LIMIT 1");
if (strlen($_POST['myPass'])<6) {$errors['parola']='Parola noua, minim 6 caractere'; $error=1; }
if ($_POST['myPass']!=$_POST['myConfirm']) {$errors['confirmare']='Parolele nu corespund'; $error=1; }
if (strlen($_POST['currentPass'])<6) {$errors['parolaCurenta']='Parola veche nu corespunde'; $error=1; }
else
{
if ($error==0)
{
$rUsers=$db->returnArray("SELECT * from users where id='".$_SESSION['userId']."' LIMIT 1");
foreach ($rUsers as $key=>$user)
{
if (password_verify($db->cleanVar($_POST['currentPass']),$user['password']))
{
$db->simpleQuery("UPDATE users set password='".password_hash($db->cleanVar($_POST['myPass']),PASSWORD_DEFAULT)."' where id='".$_SESSION['userId']."' LIMIT 1");
$mesajSucces='
Datele au fost actualizate
';
} else {$errors['parolaCurenta']='Parola veche nu corespunde'; $error=1; }
}
}
}
if ($_POST['myPass']=='' and $_POST['myConfirm']=='' and $_POST['currentPass']=='')
$error=0;
if ($error==1)
{
$smarty->assign('errors',$errors);
}
$smarty->assign('mesajSucces',$mesajSucces);
}
$rUsers=$db->returnArray("SELECT * from users where id='".$_SESSION['userId']."' LIMIT 1");
foreach ($rUsers as $key=>$user)
{
if ($user['acordEmail']==1) $checked['email']='checked';
if ($user['acordSms']==1) $checked['sms']='checked';
if ($user['acordPosta']==1) $checked['posta']='checked';
$smarty->assign('checked',$checked);
}
}
$rUsers=$db->returnArray("SELECT * from users where id='".$_SESSION['userId']."' LIMIT 1");
foreach ($rUsers as $key=>$user)
{
$smarty->assign('post',$user);
$smarty->assign('user',$user);
if ($tip==2 or $tip==1)
{
$judResult=$db->returnArray("SELECT * from judete order by denumire");
foreach ($judResult as $key=>$judet)
{
if ($judet['id']==$user['judet']) $judete.='';
else $judete.='';
if ($judet['id']==$user['judetInstitutie']) $judeteInstitutie.='';
else $judeteInstitutie.='';
}
$smarty->assign('judete', $judete);
$smarty->assign('judeteInstitutie', $judeteInstitutie);
$ocupatiiResult=$db->returnArray("SELECT * from ocupatii where denumire!='' and status=1 order by pozitie");
foreach ($ocupatiiResult as $key=>$ocupatie)
{
if ($ocupatie['id']==$user['ocupatia']) $ocupatii.='';
else $ocupatii.='';
}
$smarty->assign('ocupatii', $ocupatii);
if ($user['judet']>0)
{
$locResult=$db->returnArray("SELECT * from localitati where idjudet='".$db->cleanVar($user['judet'])."' order by denumire");
foreach ($locResult as $key=>$localitate)
{
if ($localitate['id']==$user['localitate']) $localitati.='';
else $localitati.='';
}
$smarty->assign('localitati', $localitati);
}
if ($user['judetInstitutie']>0)
{
$locResult=$db->returnArray("SELECT * from localitati where idjudet='".$db->cleanVar($user['judetInstitutie'])."' order by denumire");
foreach ($locResult as $key=>$localitate)
{
if ($localitate['id']==$user['localitateInstitutie']) $localitatiInstitutie.='';
else $localitatiInstitutie.='';
}
$smarty->assign('localitatiInstitutie', $localitatiInstitutie);
}
$specResult=$db->returnArray("SELECT specializari.id,specializari.denumire from specializari
INNER join ocupatii_specializari on specializari.id=ocupatii_specializari.idSpecializare
Where ocupatii_specializari.idOcupatie='".$db->cleanVar($user['ocupatia'])."' order by denumire");
foreach ($specResult as $key=>$specializare)
{
if ($specializare['id']==$user['specializarea']) $specializari.='';
else $specializari.='';
if ($specializare['id']==$user['specializarea2']) $specializari2.='';
else $specializari2.='';
}
$smarty->assign('specializari', $specializari);
$smarty->assign('specializari2', $specializari2);
}
}
}
function tryCookieLogin()
{
$db=new bazaDate();
if ($_SESSION['userId']<1 and $_COOKIE['user']>0)
{
if ($_COOKIE['secret']==md5($_COOKIE['user'].'proiectMedichub2022'))
{
$userId=$db->cleanVar($_COOKIE['user']);
$_SESSION['userName']=$db->getField("SELECT CONCAT (lastName,' ',firstName) as name from users where id=$userId and status=1 LIMIT 1",'name');
$_SESSION['firstName']=$db->getField("SELECT firstName as name from users where id=$userId and status=1 LIMIT 1",'name');
$_SESSION['userId']=$userId;
}
}
}
function chpass($userId)
{
$db=new bazaDate();
if (strlen($_POST['myPass'])<6) $error='Parola minim 6 caractere';
else if ($_POST['myPass']!=$_POST['confirm']) $error='Confirmarea parolei nu corespunde';
else
{
$db->simpleQuery("UPDATE usersCni set parola='".md5($_POST['myPass'])."' where id='$userId' LIMIT 1");
$db->simpleQuery("UPDATE usersLostPass set status=1 where status=0 and userId='$userId'");
// $_SESSION['userName']=$db->getField("SELECT CONCAT (lastName,' ',firstName) as name from usersCni where id=$userId and status=1 LIMIT 1",'name');
// $_SESSION['firstName']=$db->getField("SELECT firstName as name from usersCni where id=$userId and status=1 LIMIT 1",'name');
// $_SESSION['userId']=$userId;
// header("Location: ".$GLOBALS['dir'].$_SESSION['lastVisited']);
$error='
Parola a fost schimbata
';
}
return $error;
}
function verifyChange($act)
{
$db=new bazaDate();
if (strlen($act)>7)
{
$act=$db->cleanVar($act);
$userId=$db->getField("SELECT userId from usersLostPass where status=0 and act='$act' LIMIT 1",'userId');
}
return $userId;
}
function recoverPass()
{
$db=new bazaDate();
$smarty=$GLOBALS['smarty'];
if (strlen($_POST['email'])>5)
{
$userId=$db->getField("SELECT id from usersCni where status=1 and lower(email)='".strtolower($db->cleanVar($_POST['email']))."' LIMIT 1",'id');
if ($userId>0)
{
$db->simpleQuery("UPDATE usersLostPass set status=2 where userId='$userId'");
// $db->simpleQuery("UPDATE usersLostPassSMS set status=2 where userId='$userId'");
$act=md5($userId.'nmf-=a'.date("Y-m-d H:i:s").'---'.strtolower($db->cleanVar($_POST['email'])).'88'.rand(0,11111));
$myarr=array('userId'=>$userId,'act'=>$act);
$db->insert('usersLostPass',$myarr);
$linkActivare=$GLOBALS['dir'].'users/passwordchange/'.$act;
$mesaj='Buna ziua,
Pentru schimbarea parolei este nevoie sa accesati link-ul de mai jos: {linkChangePass}
Compania Nationala de Investitii';
$mesaj=str_replace('{linkChangePass}',$linkActivare,$mesaj);
mail_new(trim($db->cleanVar($_POST['email'])),'Recuperare parola cont achizitii.cni.ro',$mesaj);
}
$continut='