User.php 6.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193
  1. <?php
  2. class User {
  3. private $conn;
  4. private $table_name = "users";
  5. public $id;
  6. public $username;
  7. public $email;
  8. public $password_hash;
  9. public $first_name;
  10. public $last_name;
  11. public $role;
  12. public $is_active;
  13. public $last_login;
  14. public $created_at;
  15. public $updated_at;
  16. public function __construct($db) {
  17. $this->conn = $db;
  18. }
  19. public function create() {
  20. $query = "INSERT INTO " . $this->table_name . " SET username=:username, email=:email, password_hash=:password_hash, first_name=:first_name, last_name=:last_name, role=:role, is_active=:is_active, created_at=:created_at, updated_at=:updated_at";
  21. $stmt = $this->conn->prepare($query);
  22. $this->username = htmlspecialchars(strip_tags($this->username));
  23. $this->email = htmlspecialchars(strip_tags($this->email));
  24. $this->password_hash = password_hash($this->password_hash, PASSWORD_DEFAULT);
  25. $this->first_name = htmlspecialchars(strip_tags($this->first_name));
  26. $this->last_name = htmlspecialchars(strip_tags($this->last_name));
  27. $this->role = htmlspecialchars(strip_tags($this->role));
  28. $this->is_active = $this->is_active ? 1 : 0;
  29. $this->created_at = date('Y-m-d H:i:s');
  30. $this->updated_at = date('Y-m-d H:i:s');
  31. $stmt->bindParam(":username", $this->username);
  32. $stmt->bindParam(":email", $this->email);
  33. $stmt->bindParam(":password_hash", $this->password_hash);
  34. $stmt->bindParam(":first_name", $this->first_name);
  35. $stmt->bindParam(":last_name", $this->last_name);
  36. $stmt->bindParam(":role", $this->role);
  37. $stmt->bindParam(":is_active", $this->is_active);
  38. $stmt->bindParam(":created_at", $this->created_at);
  39. $stmt->bindParam(":updated_at", $this->updated_at);
  40. if($stmt->execute()) {
  41. return true;
  42. }
  43. return false;
  44. }
  45. public function read() {
  46. $query = "SELECT id, username, email, first_name, last_name, role, is_active, last_login, created_at, updated_at FROM " . $this->table_name . " ORDER BY username";
  47. $stmt = $this->conn->prepare($query);
  48. $stmt->execute();
  49. return $stmt;
  50. }
  51. public function readOne() {
  52. $query = "SELECT * FROM " . $this->table_name . " WHERE id = ? LIMIT 0,1";
  53. $stmt = $this->conn->prepare($query);
  54. $stmt->bindParam(1, $this->id);
  55. $stmt->execute();
  56. $row = $stmt->fetch(PDO::FETCH_ASSOC);
  57. $this->username = $row['username'];
  58. $this->email = $row['email'];
  59. $this->password_hash = $row['password_hash'];
  60. $this->first_name = $row['first_name'];
  61. $this->last_name = $row['last_name'];
  62. $this->role = $row['role'];
  63. $this->is_active = $row['is_active'];
  64. $this->last_login = $row['last_login'];
  65. $this->created_at = $row['created_at'];
  66. $this->updated_at = $row['updated_at'];
  67. }
  68. public function update() {
  69. $query = "UPDATE " . $this->table_name . " SET username=:username, email=:email, first_name=:first_name, last_name=:last_name, role=:role, is_active=:is_active, updated_at=:updated_at WHERE id=:id";
  70. $stmt = $this->conn->prepare($query);
  71. $this->username = htmlspecialchars(strip_tags($this->username));
  72. $this->email = htmlspecialchars(strip_tags($this->email));
  73. $this->first_name = htmlspecialchars(strip_tags($this->first_name));
  74. $this->last_name = htmlspecialchars(strip_tags($this->last_name));
  75. $this->role = htmlspecialchars(strip_tags($this->role));
  76. $this->is_active = $this->is_active ? 1 : 0;
  77. $this->updated_at = date('Y-m-d H:i:s');
  78. $stmt->bindParam(":username", $this->username);
  79. $stmt->bindParam(":email", $this->email);
  80. $stmt->bindParam(":first_name", $this->first_name);
  81. $stmt->bindParam(":last_name", $this->last_name);
  82. $stmt->bindParam(":role", $this->role);
  83. $stmt->bindParam(":is_active", $this->is_active);
  84. $stmt->bindParam(":updated_at", $this->updated_at);
  85. $stmt->bindParam(":id", $this->id);
  86. if($stmt->execute()) {
  87. return true;
  88. }
  89. return false;
  90. }
  91. public function delete() {
  92. $query = "DELETE FROM " . $this->table_name . " WHERE id = ?";
  93. $stmt = $this->conn->prepare($query);
  94. $stmt->bindParam(1, $this->id);
  95. if($stmt->execute()) {
  96. return true;
  97. }
  98. return false;
  99. }
  100. public function authenticate($username, $password) {
  101. $query = "SELECT * FROM " . $this->table_name . " WHERE username = ? AND is_active = TRUE LIMIT 0,1";
  102. $stmt = $this->conn->prepare($query);
  103. $stmt->bindParam(1, $username);
  104. $stmt->execute();
  105. $row = $stmt->fetch(PDO::FETCH_ASSOC);
  106. if($row && password_verify($password, $row['password_hash'])) {
  107. // Update last login
  108. $update_query = "UPDATE " . $this->table_name . " SET last_login = ? WHERE id = ?";
  109. $update_stmt = $this->conn->prepare($update_query);
  110. $update_stmt->bindParam(1, date('Y-m-d H:i:s'));
  111. $update_stmt->bindParam(2, $row['id']);
  112. $update_stmt->execute();
  113. // Remove password hash from response
  114. unset($row['password_hash']);
  115. return $row;
  116. }
  117. return false;
  118. }
  119. public function findByEmail($email) {
  120. $query = "SELECT * FROM " . $this->table_name . " WHERE email = ? LIMIT 0,1";
  121. $stmt = $this->conn->prepare($query);
  122. $stmt->bindParam(1, $email);
  123. $stmt->execute();
  124. return $stmt->fetch(PDO::FETCH_ASSOC);
  125. }
  126. public function updatePassword($user_id, $new_password) {
  127. $query = "UPDATE " . $this->table_name . " SET password_hash = ?, updated_at = ? WHERE id = ?";
  128. $stmt = $this->conn->prepare($query);
  129. $password_hash = password_hash($new_password, PASSWORD_DEFAULT);
  130. $updated_at = date('Y-m-d H:i:s');
  131. $stmt->bindParam(1, $password_hash);
  132. $stmt->bindParam(2, $updated_at);
  133. $stmt->bindParam(3, $user_id);
  134. return $stmt->execute();
  135. }
  136. public function getRoleBadge() {
  137. $badges = [
  138. 'admin' => '<span style="background-color: #dc3545; color: white; padding: 2px 6px; border-radius: 4px; font-size: 12px;">Admin</span>',
  139. 'manager' => '<span style="background-color: #6f42c1; color: white; padding: 2px 6px; border-radius: 4px; font-size: 12px;">Manager</span>',
  140. 'user' => '<span style="background-color: #6c757d; color: white; padding: 2px 6px; border-radius: 4px; font-size: 12px;">User</span>'
  141. ];
  142. return $badges[$this->role] ?? $this->role;
  143. }
  144. public function getFullName() {
  145. return trim($this->first_name . ' ' . $this->last_name);
  146. }
  147. public function isActive() {
  148. return $this->is_active;
  149. }
  150. }
  151. ?>