|
1 | 1 | <?php |
2 | 2 | /** |
3 | 3 | * Chess game actions |
| 4 | + * |
4 | 5 | * @package zorg\Games\Chess |
5 | 6 | */ |
| 7 | + |
6 | 8 | /** |
7 | 9 | * File includes |
8 | 10 | */ |
9 | | -require_once dirname(__FILE__).'/../includes/main.inc.php'; |
| 11 | +require_once __DIR__.'/../includes/config.inc.php'; |
10 | 12 | include_once INCLUDES_DIR.'chess.inc.php'; |
11 | 13 |
|
12 | | -/** move */ |
13 | | -if (isset($_GET['game']) && $_GET['game'] > 0 && isset($_GET['from']) && isset($_GET['to'])) |
| 14 | +/** Input validation and sanitization */ |
| 15 | +$doAction = filter_input(INPUT_GET, 'do', FILTER_DEFAULT, FILTER_REQUIRE_SCALAR) ?? null; // $_GET['do'] |
| 16 | +$gameId = filter_input(INPUT_GET, 'game', FILTER_VALIDATE_INT) ?? 0; // $_GET['game'] |
| 17 | +$fromField = filter_input(INPUT_GET, 'from', FILTER_DEFAULT, FILTER_REQUIRE_SCALAR) ?? null; // $_GET['from'] |
| 18 | +$toField = filter_input(INPUT_GET, 'to', FILTER_DEFAULT, FILTER_REQUIRE_SCALAR) ?? null; // $_GET['to'] |
| 19 | +$viewForm = filter_input(INPUT_POST, 'formid', FILTER_DEFAULT, FILTER_REQUIRE_SCALAR) ?? null; // $_POST['formid'] |
| 20 | +$userId = filter_input(INPUT_POST, 'user', FILTER_VALIDATE_INT) ?? null; // $_POST['user'] |
| 21 | + |
| 22 | +if (isset($gameId) && $gameId > 0) |
14 | 23 | { |
15 | | - $e = $db->query('SELECT *, IF(white=next_turn, "w", "b") player |
16 | | - FROM chess_games |
17 | | - WHERE id='.$_GET['game'].' AND next_turn='.$user->id, |
18 | | - __FILE__, __LINE__, 'move'); |
19 | | - $d = $db->fetch($e); |
| 24 | + /** move */ |
| 25 | + if (!empty($fromField) && !empty($toField)) |
| 26 | + { |
| 27 | + $e = $db->query('SELECT *, IF(white=next_turn, "w", "b") player FROM chess_games WHERE id=? AND next_turn=?', |
| 28 | + __FILE__, __LINE__, 'move', [$gameId, $user->id]); |
| 29 | + $d = $db->fetch($e); |
20 | 30 |
|
21 | | - |
22 | | - if ($d && Chess::is_valid_position($_GET['from']) && Chess::is_valid_position($_GET['to']) |
23 | | - && Chess::do_move($d['id'], $d['player'], $_GET['from'], $_GET['to']) |
24 | | - ) { |
25 | | - unset($_GET['from']); |
26 | | - unset($_GET['to']); |
27 | | - header('Location: /?'.url_params()); |
28 | | - }else{ |
29 | | - echo "Invalid chess move: <br /> game = ".$_GET['game']." <br /> from = ".$_GET['from']." <br /> to = ".$_GET['to']; |
| 31 | + |
| 32 | + if ($d && $chess->is_valid_position($fromField) && $chess->is_valid_position($toField) |
| 33 | + && $chess->do_move($d['id'], $d['player'], $fromField, $toField) |
| 34 | + ) { |
| 35 | + unset($_GET['from']); |
| 36 | + unset($_GET['to']); |
| 37 | + header('Location: /?'.url_params()); |
| 38 | + }else{ |
| 39 | + echo "Invalid chess move: <br /> game = ".$gameId." <br /> from = ".$fromField." <br /> to = ".$toField; |
| 40 | + } |
30 | 41 | exit; |
31 | 42 | } |
32 | | -} |
33 | 43 |
|
34 | | -/** offer remis */ |
35 | | -if (isset($_GET['game']) && $_GET['game'] > 0 && isset($_GET['do']) && $_GET['do'] == 'offer_remis') |
36 | | -{ |
37 | | - $e = $db->query('SELECT * FROM chess_games WHERE id='.$_GET['game'].' AND next_turn='.$user->id, __FILE__, __LINE__, 'offer remis'); |
38 | | - $d = $db->fetch($e); |
39 | | - if ($d) { |
40 | | - Chess::do_offer_remis($_GET['game']); |
41 | | - unset($_GET['do']); |
42 | | - header("Location: /?".url_params()); |
43 | | - }else{ |
44 | | - echo "'offer remis' is not allowed."; |
| 44 | + /** offer remis */ |
| 45 | + if ($doAction === 'offer_remis') |
| 46 | + { |
| 47 | + $e = $db->query('SELECT * FROM chess_games WHERE id=? AND next_turn=?', __FILE__, __LINE__, 'offer remis', [$gameId, $user->id]); |
| 48 | + $d = $db->fetch($e); |
| 49 | + if ($d) { |
| 50 | + $chess->do_offer_remis($gameId); |
| 51 | + |
| 52 | + unset($_GET['do']); |
| 53 | + header("Location: /?".url_params()); |
| 54 | + }else{ |
| 55 | + echo "'offer remis' is not allowed."; |
| 56 | + } |
45 | 57 | exit; |
46 | 58 | } |
47 | | -} |
48 | 59 |
|
49 | | -/** accept remis */ |
50 | | -if (isset($_GET['game']) && $_GET['game'] > 0 && isset($_GET['do']) && $_GET['do'] == 'accept_remis') |
51 | | -{ |
52 | | - $e = $db->query('SELECT * |
53 | | - FROM chess_games |
54 | | - WHERE id='.$_GET['game'].' AND (white='.$user->id.' OR black='.$user->id.') AND next_turn!='.$user->id.' AND offering_remis="1"', |
55 | | - __FILE__, __LINE__, 'accept remis'); |
56 | | - $d = $db->fetch($e); |
57 | | - if ($d) { |
58 | | - Chess::do_remis($_GET['game']); |
59 | | - unset($_GET['do']); |
60 | | - header("Location: /?".url_params()); |
61 | | - }else{ |
62 | | - echo "'accept remis' is not allowed."; |
| 60 | + /** accept remis */ |
| 61 | + if ($doAction === 'accept_remis') |
| 62 | + { |
| 63 | + $e = $db->query('SELECT * FROM chess_games WHERE id=? AND (white=? OR black=?) AND next_turn!=? AND offering_remis="1"', |
| 64 | + __FILE__, __LINE__, 'accept remis', [$gameId, $user->id, $user->id, $user->id]); |
| 65 | + $d = $db->fetch($e); |
| 66 | + if ($d) { |
| 67 | + $chess->do_remis($gameId); |
| 68 | + |
| 69 | + unset($_GET['do']); |
| 70 | + header("Location: /?".url_params()); |
| 71 | + }else{ |
| 72 | + echo "'accept remis' is not allowed."; |
| 73 | + } |
63 | 74 | exit; |
64 | 75 | } |
65 | | -} |
66 | 76 |
|
67 | | -/** deny remis */ |
68 | | -if (isset($_GET['game']) && $_GET['game'] > 0 && isset($_GET['do']) && $_GET['do'] == 'deny_remis') |
69 | | -{ |
70 | | - $e = $db->query('SELECT * |
71 | | - FROM chess_games |
72 | | - WHERE id='.$_GET['game'].' AND (white='.$user->id.' OR black='.$user->id.') AND next_turn!='.$user->id.' AND offering_remis="1"', |
73 | | - __FILE__, __LINE__, 'deny remis'); |
74 | | - $d = $db->fetch($e); |
75 | | - if ($d) { |
76 | | - Chess::deny_remis($_GET['game']); |
77 | | - header("Location: /?".url_params()); |
78 | | - }else{ |
79 | | - echo "'deny remis' is not allowed"; |
| 77 | + /** deny remis */ |
| 78 | + if ($doAction === 'deny_remis') |
| 79 | + { |
| 80 | + $e = $db->query('SELECT * FROM chess_games WHERE id=? AND (white=? OR black=?) AND next_turn!=? AND offering_remis="1"', |
| 81 | + __FILE__, __LINE__, 'deny remis', [$gameId, $user->id, $user->id, $user->id]); |
| 82 | + $d = $db->fetch($e); |
| 83 | + if ($d) { |
| 84 | + $chess->deny_remis($gameId); |
| 85 | + |
| 86 | + unset($_GET['do']); |
| 87 | + header("Location: /?".url_params()); |
| 88 | + }else{ |
| 89 | + echo "'deny remis' is not allowed"; |
| 90 | + } |
| 91 | + exit; |
| 92 | + } |
| 93 | + |
| 94 | + /** aufgeben */ |
| 95 | + if ($doAction === 'aufgeben') |
| 96 | + { |
| 97 | + $chess->aufgabe($gameId); |
| 98 | + |
| 99 | + unset($_GET['do']); |
| 100 | + header("Location: /tpl/141?".url_params()); |
80 | 101 | exit; |
81 | 102 | } |
82 | 103 | } |
83 | 104 |
|
84 | 105 | /** start new game */ |
85 | | -if (isset($_POST['formid']) && $_POST['formid'] == 'chess_start') |
| 106 | +elseif ($viewForm === 'chess_start') |
86 | 107 | { |
87 | | - if (Chess::new_game($_POST['user'])) { |
| 108 | + if ($chess->new_game($userId)) { |
88 | 109 | header("Location: /?tpl=139"); |
89 | 110 | }else{ |
90 | | - echo "invalid chess_start: <br /> user = ".$_POST['user']; |
91 | | - exit; |
| 111 | + echo "invalid chess_start: <br /> user = ".$userId; |
92 | 112 | } |
93 | | -} |
94 | | - |
95 | | -/** aufgeben */ |
96 | | -if (isset($_GET['game']) && $_GET['game'] > 0 && isset($_GET['do']) && $_GET['do'] == 'aufgeben') |
97 | | -{ |
98 | | - Chess::aufgabe($_GET['game']); |
99 | | - |
100 | | - unset($_GET['do']); |
101 | | - header("Location: /tpl/141?".url_params()); |
| 113 | + exit; |
102 | 114 | } |
0 commit comments