<?php
include("checklogin.php");
include("config.php");

$npwd = $_POST["newpwd"];
$npwd2 = $_POST["newpwd2"];

if($npwd != $npwd2) {
	die("Passwords do not match.");
}

$connectionID = mysql_connect($hostname,$username,$password);

if(!mysql_select_db($database,$connectionID)) {
	die("Connection failed.");
}

$sql = "SELECT password FROM userdata WHERE idx='".$_SESSION["user_id"]."'";
$result = mysql_query($sql);

if(mysql_num_rows($result) > 0) {
	$data = mysql_fetch_array($result);
	$opwd = $data["password"];
	if(($_POST["oldpwd"] != '') && (md5($_POST["oldpwd"]) != $opwd)) {
		echo $opwd;
		die("Old password is not correct.");
	}
	
	if(md5($_POST["oldpwd"]) == $opwd) {
		$sql = "UPDATE userdata SET password='".md5($npwd)."' WHERE idx='".$_SESSION["user_id"]."'";
		mysql_query($sql);
		if(mysql_affected_rows($connectionID) > 0) {
			echo "Password successfully updated.";
		}
	}
}

?>

<html>
	<head>
		<title>Edit Password</title>
	</head>
	
	<body>
		<form action="edit_password.php" method="post">
			Old Password: <input type="password" name="oldpwd" size="20"><br>
			New Password: <input type="password" name="newpwd" size="20"><br>
			Repeat New Password: <input type="password" name="newpwd2" size="20"><br>
			<input type="submit" value="Apply">
			<input type="reset" value="Clear">
		</form>
		<a href="intern.php">Go back</a>
	</body>
</html>

<?php
mysql_close($connectionID);
?>