if(!defined("IN_BC")){
header("Location: ?page=my_account");
}
if($username == ""){
error("No access", "You must be logged in to use this page!");
} else {
$res = mysql_query("SELECT * from users where username='$username'");
$data = mysql_fetch_array($res);
$username = $data["username"];
$firstname = $data["firstname"];
$password = $data["password"];
$lastname = $data["lastname"];
$email = $data["email"];
$level = $data["level"];
$password = $data["password"];
$ip = $data["ip"];
$datereg = $data["date_reg"];
$datelog = $data["last_login"];
$points = $data["points"];
switch(strtolower($_REQUEST["function"])){
default;
startpage("Edit account");
?>
endpage();
break;
case "edit";
$lname = addslashes($_POST["lastname"]);
$fname = addslashes($_POST["firstname"]);
$email = addslashes($_POST["email"]);
$oldpass = $_POST["oldpass"];
$newpass = $_POST["newpassword"];
$oldusername = addslashes($_POST["oldusername"]);
if (strlen($lname) > 0) {
mysql_query("UPDATE users set lastname='$lname' where username='$oldusername'");
}
if (strlen($fname) > 0) {
mysql_query("UPDATE users set firstname='$fname' WHERE username='$oldusername'");
}
if (strlen($email) > 0){
mysql_query("UPDATE users set email='$email' WHERE username='$oldusername'");
}
if ($oldpass != "" && $newpass != ""){
$res = mysql_query("SELECT username, password from users where username='$oldusername'");
$data = mysql_fetch_array($res);
if($data["username"] == $oldusername && md5($oldpass) == $data["password"]){
mysql_query("UPDATE users set password='".md5($newpass)."' where username='$oldusername'");
} else {
Error("Incorrect Information", "Cannot update account");
}
}
print "Account Settings updated";
break;
}
}
?>