User.php 8.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227
  1. <?php
  2. class User {
  3. private $conn;
  4. private $table_name = "users";
  5. public $id;
  6. public $username;
  7. public $email;
  8. public $password_hash;
  9. public $first_name;
  10. public $last_name;
  11. public $role;
  12. public $is_active;
  13. public $last_login;
  14. public $created_at;
  15. public $updated_at;
  16. public function __construct($db) {
  17. $this->conn = $db;
  18. }
  19. public function create() {
  20. $query = "INSERT INTO " . $this->table_name . " SET username=:username, email=:email, password_hash=:password_hash, first_name=:first_name, last_name=:last_name, role=:role, is_active=:is_active, created_at=:created_at, updated_at=:updated_at";
  21. $stmt = $this->conn->prepare($query);
  22. $this->username = htmlspecialchars(strip_tags($this->username));
  23. $this->email = htmlspecialchars(strip_tags($this->email));
  24. $this->password_hash = password_hash($this->password_hash, PASSWORD_DEFAULT);
  25. $this->first_name = htmlspecialchars(strip_tags($this->first_name));
  26. $this->last_name = htmlspecialchars(strip_tags($this->last_name));
  27. $this->role = htmlspecialchars(strip_tags($this->role));
  28. $this->is_active = $this->is_active ? 1 : 0;
  29. $this->created_at = date('Y-m-d H:i:s');
  30. $this->updated_at = date('Y-m-d H:i:s');
  31. $stmt->bindParam(":username", $this->username);
  32. $stmt->bindParam(":email", $this->email);
  33. $stmt->bindParam(":password_hash", $this->password_hash);
  34. $stmt->bindParam(":first_name", $this->first_name);
  35. $stmt->bindParam(":last_name", $this->last_name);
  36. $stmt->bindParam(":role", $this->role);
  37. $stmt->bindParam(":is_active", $this->is_active);
  38. $stmt->bindParam(":created_at", $this->created_at);
  39. $stmt->bindParam(":updated_at", $this->updated_at);
  40. if($stmt->execute()) {
  41. return true;
  42. }
  43. return false;
  44. }
  45. public function read() {
  46. $query = "SELECT id, username, email, first_name, last_name, role, is_active, last_login, created_at, updated_at FROM " . $this->table_name . " ORDER BY username";
  47. $stmt = $this->conn->prepare($query);
  48. $stmt->execute();
  49. return $stmt;
  50. }
  51. public function readOne() {
  52. $query = "SELECT * FROM " . $this->table_name . " WHERE id = ? LIMIT 0,1";
  53. $stmt = $this->conn->prepare($query);
  54. $stmt->bindParam(1, $this->id);
  55. $stmt->execute();
  56. $row = $stmt->fetch(PDO::FETCH_ASSOC);
  57. $this->username = $row['username'];
  58. $this->email = $row['email'];
  59. $this->password_hash = $row['password_hash'];
  60. $this->first_name = $row['first_name'];
  61. $this->last_name = $row['last_name'];
  62. $this->role = $row['role'];
  63. $this->is_active = $row['is_active'];
  64. $this->last_login = $row['last_login'];
  65. $this->created_at = $row['created_at'];
  66. $this->updated_at = $row['updated_at'];
  67. }
  68. public function update($update_password = false) {
  69. if($update_password) {
  70. $query = "UPDATE " . $this->table_name . " SET username=:username, email=:email, password_hash=:password_hash, first_name=:first_name, last_name=:last_name, role=:role, is_active=:is_active, updated_at=:updated_at WHERE id=:id";
  71. } else {
  72. $query = "UPDATE " . $this->table_name . " SET username=:username, email=:email, first_name=:first_name, last_name=:last_name, role=:role, is_active=:is_active, updated_at=:updated_at WHERE id=:id";
  73. }
  74. $stmt = $this->conn->prepare($query);
  75. $this->username = htmlspecialchars(strip_tags($this->username));
  76. $this->email = htmlspecialchars(strip_tags($this->email));
  77. $this->first_name = htmlspecialchars(strip_tags($this->first_name));
  78. $this->last_name = htmlspecialchars(strip_tags($this->last_name));
  79. $this->role = htmlspecialchars(strip_tags($this->role));
  80. $this->is_active = $this->is_active ? 1 : 0;
  81. $this->updated_at = date('Y-m-d H:i:s');
  82. $stmt->bindParam(":username", $this->username);
  83. $stmt->bindParam(":email", $this->email);
  84. $stmt->bindParam(":first_name", $this->first_name);
  85. $stmt->bindParam(":last_name", $this->last_name);
  86. $stmt->bindParam(":role", $this->role);
  87. $stmt->bindParam(":is_active", $this->is_active);
  88. $stmt->bindParam(":updated_at", $this->updated_at);
  89. $stmt->bindParam(":id", $this->id);
  90. if($update_password) {
  91. $this->password_hash = password_hash($this->password_hash, PASSWORD_DEFAULT);
  92. $stmt->bindParam(":password_hash", $this->password_hash);
  93. }
  94. if($stmt->execute()) {
  95. return true;
  96. }
  97. return false;
  98. }
  99. public function delete() {
  100. $query = "DELETE FROM " . $this->table_name . " WHERE id = ?";
  101. $stmt = $this->conn->prepare($query);
  102. $stmt->bindParam(1, $this->id);
  103. if($stmt->execute()) {
  104. return true;
  105. }
  106. return false;
  107. }
  108. public function authenticate($username, $password) {
  109. $query = "SELECT * FROM " . $this->table_name . " WHERE username = ? AND is_active = TRUE LIMIT 0,1";
  110. $stmt = $this->conn->prepare($query);
  111. $stmt->bindParam(1, $username);
  112. $stmt->execute();
  113. $row = $stmt->fetch(PDO::FETCH_ASSOC);
  114. if($row && password_verify($password, $row['password_hash'])) {
  115. // Update last login
  116. $update_query = "UPDATE " . $this->table_name . " SET last_login = ? WHERE id = ?";
  117. $update_stmt = $this->conn->prepare($update_query);
  118. $current_time = date('Y-m-d H:i:s');
  119. $update_stmt->bindParam(1, $current_time);
  120. $update_stmt->bindParam(2, $row['id']);
  121. $update_stmt->execute();
  122. // Remove password hash from response
  123. unset($row['password_hash']);
  124. return $row;
  125. }
  126. return false;
  127. }
  128. public function findByEmail($email) {
  129. $query = "SELECT * FROM " . $this->table_name . " WHERE email = ? LIMIT 0,1";
  130. $stmt = $this->conn->prepare($query);
  131. $stmt->bindParam(1, $email);
  132. $stmt->execute();
  133. return $stmt->fetch(PDO::FETCH_ASSOC);
  134. }
  135. public function updatePassword($user_id, $new_password) {
  136. $query = "UPDATE " . $this->table_name . " SET password_hash = ?, updated_at = ? WHERE id = ?";
  137. $stmt = $this->conn->prepare($query);
  138. $password_hash = password_hash($new_password, PASSWORD_DEFAULT);
  139. $updated_at = date('Y-m-d H:i:s');
  140. $stmt->bindParam(1, $password_hash);
  141. $stmt->bindParam(2, $updated_at);
  142. $stmt->bindParam(3, $user_id);
  143. return $stmt->execute();
  144. }
  145. public function getRoleBadge() {
  146. $badges = [
  147. 'admin' => '<span style="background-color: #dc3545; color: white; padding: 2px 6px; border-radius: 4px; font-size: 12px;">Admin</span>',
  148. 'manager' => '<span style="background-color: #6f42c1; color: white; padding: 2px 6px; border-radius: 4px; font-size: 12px;">Manager</span>',
  149. 'user' => '<span style="background-color: #6c757d; color: white; padding: 2px 6px; border-radius: 4px; font-size: 12px;">User</span>'
  150. ];
  151. return $badges[$this->role] ?? $this->role;
  152. }
  153. public function getFullName() {
  154. return trim($this->first_name . ' ' . $this->last_name);
  155. }
  156. public function isActive() {
  157. return $this->is_active;
  158. }
  159. public function getStatusBadge() {
  160. if($this->is_active) {
  161. return '<span style="background-color: #28a745; color: white; padding: 2px 6px; border-radius: 4px; font-size: 12px;">Active</span>';
  162. } else {
  163. return '<span style="background-color: #6c757d; color: white; padding: 2px 6px; border-radius: 4px; font-size: 12px;">Inactive</span>';
  164. }
  165. }
  166. public function findByUsername($username) {
  167. $query = "SELECT id, username, email, first_name, last_name, role, is_active, last_login, created_at, updated_at FROM " . $this->table_name . " WHERE username = ? LIMIT 0,1";
  168. $stmt = $this->conn->prepare($query);
  169. $stmt->bindParam(1, $username);
  170. $stmt->execute();
  171. $row = $stmt->fetch(PDO::FETCH_ASSOC);
  172. if($row) {
  173. return $row;
  174. }
  175. return false;
  176. }
  177. }
  178. ?>