Files
skyview.astronomiemuseum.de/public/settings.php
T
2026-03-31 09:44:27 +02:00

779 lines
26 KiB
PHP

<?php
declare(strict_types=1);
ini_set('display_errors', '1');
error_reporting(E_ALL);
session_start();
if (!isset($_SESSION['user_id'])) {
header('Location: login.php');
exit;
}
$config = require __DIR__ . '/../config/database.php';
$dsn = sprintf(
'mysql:host=%s;dbname=%s;charset=%s',
$config['host'],
$config['dbname'],
$config['charset'] ?? 'utf8mb4'
);
$pdo = new PDO(
$dsn,
$config['user'],
$config['pass'],
[
PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION,
PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC,
]
);
$userId = (int)$_SESSION['user_id'];
$errors = [];
$successMessage = '';
function h(?string $value): string
{
return htmlspecialchars((string)$value, ENT_QUOTES, 'UTF-8');
}
function validTimezone(string $timezone): bool
{
return in_array($timezone, timezone_identifiers_list(), true);
}
/*
|--------------------------------------------------------------------------
| Benutzer laden
|--------------------------------------------------------------------------
*/
$stmtUser = $pdo->prepare("
SELECT
`id`,
`username`,
`email`,
`display_name`,
`role`,
`is_active`
FROM `app_users`
WHERE `id` = :id
LIMIT 1
");
$stmtUser->execute([':id' => $userId]);
$user = $stmtUser->fetch();
if (!$user) {
$_SESSION = [];
session_destroy();
header('Location: login.php');
exit;
}
/*
|--------------------------------------------------------------------------
| Aktionen verarbeiten
|--------------------------------------------------------------------------
*/
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
$action = $_POST['action'] ?? '';
if ($action === 'update_profile') {
$displayName = trim($_POST['display_name'] ?? '');
$email = trim($_POST['email'] ?? '');
if ($email === '' || !filter_var($email, FILTER_VALIDATE_EMAIL)) {
$errors[] = 'Bitte eine gültige E-Mail-Adresse eingeben.';
}
if ($displayName !== '' && mb_strlen($displayName) > 100) {
$errors[] = 'Der Anzeigename darf maximal 100 Zeichen lang sein.';
}
if (empty($errors)) {
$stmtCheck = $pdo->prepare("
SELECT `id`
FROM `app_users`
WHERE `email` = :email
AND `id` <> :id
LIMIT 1
");
$stmtCheck->execute([
':email' => $email,
':id' => $userId,
]);
if ($stmtCheck->fetch()) {
$errors[] = 'Die E-Mail-Adresse ist bereits vergeben.';
}
}
if (empty($errors)) {
$stmtUpdate = $pdo->prepare("
UPDATE `app_users`
SET
`display_name` = :display_name,
`email` = :email,
`updated_at` = NOW()
WHERE `id` = :id
");
$stmtUpdate->execute([
':display_name' => $displayName !== '' ? $displayName : null,
':email' => $email,
':id' => $userId,
]);
$_SESSION['display_name'] = $displayName !== '' ? $displayName : null;
$successMessage = 'Die Kontodaten wurden gespeichert.';
}
}
if ($action === 'change_password') {
$currentPassword = $_POST['current_password'] ?? '';
$newPassword = $_POST['new_password'] ?? '';
$newPasswordRepeat = $_POST['new_password_repeat'] ?? '';
$stmtPassword = $pdo->prepare("
SELECT `password_hash`
FROM `app_users`
WHERE `id` = :id
LIMIT 1
");
$stmtPassword->execute([':id' => $userId]);
$passwordRow = $stmtPassword->fetch();
if (!$passwordRow || !password_verify($currentPassword, $passwordRow['password_hash'])) {
$errors[] = 'Das aktuelle Passwort ist nicht korrekt.';
}
if ($newPassword === '') {
$errors[] = 'Bitte ein neues Passwort eingeben.';
} elseif (strlen($newPassword) < 8) {
$errors[] = 'Das neue Passwort muss mindestens 8 Zeichen lang sein.';
}
if ($newPassword !== $newPasswordRepeat) {
$errors[] = 'Die neuen Passwörter stimmen nicht überein.';
}
if (empty($errors)) {
$newHash = password_hash($newPassword, PASSWORD_DEFAULT);
$stmtUpdatePassword = $pdo->prepare("
UPDATE `app_users`
SET
`password_hash` = :password_hash,
`updated_at` = NOW()
WHERE `id` = :id
");
$stmtUpdatePassword->execute([
':password_hash' => $newHash,
':id' => $userId,
]);
$successMessage = 'Das Passwort wurde geändert.';
}
}
if ($action === 'add_location') {
$name = trim($_POST['name'] ?? '');
$latitude = trim($_POST['latitude'] ?? '');
$longitude = trim($_POST['longitude'] ?? '');
$elevation = trim($_POST['elevation'] ?? '');
$timezone = trim($_POST['timezone'] ?? 'Europe/Berlin');
$isDefault = isset($_POST['is_default']) ? 1 : 0;
if ($name === '') {
$errors[] = 'Bitte einen Namen für den Standort eingeben.';
}
if ($latitude === '' || !is_numeric($latitude)) {
$errors[] = 'Bitte einen gültigen Breitengrad eingeben.';
} else {
$lat = (float)$latitude;
if ($lat < -90 || $lat > 90) {
$errors[] = 'Der Breitengrad muss zwischen -90 und 90 liegen.';
}
}
if ($longitude === '' || !is_numeric($longitude)) {
$errors[] = 'Bitte einen gültigen Längengrad eingeben.';
} else {
$lon = (float)$longitude;
if ($lon < -180 || $lon > 180) {
$errors[] = 'Der Längengrad muss zwischen -180 und 180 liegen.';
}
}
if ($elevation !== '' && !is_numeric($elevation)) {
$errors[] = 'Die Höhe muss numerisch sein.';
}
if (!validTimezone($timezone)) {
$errors[] = 'Bitte eine gültige IANA-Zeitzone angeben, z. B. Europe/Berlin.';
}
if (empty($errors)) {
$pdo->beginTransaction();
try {
if ($isDefault === 1) {
$stmtReset = $pdo->prepare("
UPDATE `app_user_locations`
SET `is_default` = 0
WHERE `user_id` = :user_id
");
$stmtReset->execute([
':user_id' => $userId,
]);
}
$stmtInsertLocation = $pdo->prepare("
INSERT INTO `app_user_locations` (
`user_id`,
`name`,
`latitude`,
`longitude`,
`elevation`,
`timezone`,
`is_default`,
`created_at`,
`updated_at`
) VALUES (
:user_id,
:name,
:latitude,
:longitude,
:elevation,
:timezone,
:is_default,
NOW(),
NOW()
)
");
$stmtInsertLocation->execute([
':user_id' => $userId,
':name' => $name,
':latitude' => (float)$latitude,
':longitude' => (float)$longitude,
':elevation' => $elevation !== '' ? (float)$elevation : null,
':timezone' => $timezone,
':is_default' => $isDefault,
]);
$pdo->commit();
$successMessage = 'Der Standort wurde gespeichert.';
$_POST = [];
} catch (Throwable $e) {
$pdo->rollBack();
$errors[] = 'Der Standort konnte nicht gespeichert werden.';
}
}
}
if ($action === 'set_default_location') {
$locationId = (int)($_POST['location_id'] ?? 0);
if ($locationId <= 0) {
$errors[] = 'Ungültiger Standort.';
}
if (empty($errors)) {
$stmtCheckLocation = $pdo->prepare("
SELECT `id`
FROM `app_user_locations`
WHERE `id` = :id
AND `user_id` = :user_id
LIMIT 1
");
$stmtCheckLocation->execute([
':id' => $locationId,
':user_id' => $userId,
]);
if (!$stmtCheckLocation->fetch()) {
$errors[] = 'Der Standort wurde nicht gefunden.';
}
}
if (empty($errors)) {
$pdo->beginTransaction();
try {
$stmtReset = $pdo->prepare("
UPDATE `app_user_locations`
SET `is_default` = 0
WHERE `user_id` = :user_id
");
$stmtReset->execute([
':user_id' => $userId,
]);
$stmtSet = $pdo->prepare("
UPDATE `app_user_locations`
SET `is_default` = 1
WHERE `id` = :id
AND `user_id` = :user_id
");
$stmtSet->execute([
':id' => $locationId,
':user_id' => $userId,
]);
$pdo->commit();
$successMessage = 'Der Standard-Standort wurde gesetzt.';
} catch (Throwable $e) {
$pdo->rollBack();
$errors[] = 'Der Standard-Standort konnte nicht gesetzt werden.';
}
}
}
if ($action === 'delete_location') {
$locationId = (int)($_POST['location_id'] ?? 0);
if ($locationId <= 0) {
$errors[] = 'Ungültiger Standort.';
}
if (empty($errors)) {
$stmtDelete = $pdo->prepare("
DELETE FROM `app_user_locations`
WHERE `id` = :id
AND `user_id` = :user_id
");
$stmtDelete->execute([
':id' => $locationId,
':user_id' => $userId,
]);
$successMessage = 'Der Standort wurde gelöscht.';
}
}
$stmtUser->execute([':id' => $userId]);
$user = $stmtUser->fetch();
}
/*
|--------------------------------------------------------------------------
| Standorte laden
|--------------------------------------------------------------------------
*/
$stmtLocations = $pdo->prepare("
SELECT
`id`,
`name`,
`latitude`,
`longitude`,
`elevation`,
`timezone`,
`is_default`
FROM `app_user_locations`
WHERE `user_id` = :user_id
ORDER BY `is_default` DESC, `name` ASC
");
$stmtLocations->execute([
':user_id' => $userId,
]);
$locations = $stmtLocations->fetchAll();
$defaultLocation = null;
foreach ($locations as $location) {
if ((int)$location['is_default'] === 1) {
$defaultLocation = $location;
break;
}
}
$mapLat = isset($_POST['latitude']) && is_numeric($_POST['latitude'])
? (float)$_POST['latitude']
: ($defaultLocation ? (float)$defaultLocation['latitude'] : 51.1657);
$mapLon = isset($_POST['longitude']) && is_numeric($_POST['longitude'])
? (float)$_POST['longitude']
: ($defaultLocation ? (float)$defaultLocation['longitude'] : 10.4515);
$mapZoom = $defaultLocation ? 10 : 6;
$loggedIn = true;
?>
<?php require __DIR__ . '/header.php'; ?>
<link
rel="stylesheet"
href="https://unpkg.com/leaflet@1.9.4/dist/leaflet.css"
integrity="sha256-p4NxAoJBhIIN+hmNHrzRCf9tD/miZyoHS5obTRR9BMY="
crossorigin=""
>
<?php if ($successMessage !== ''): ?>
<p class="msg-success"><?= h($successMessage) ?></p>
<?php endif; ?>
<?php if (!empty($errors)): ?>
<ul class="msg-error">
<?php foreach ($errors as $error): ?>
<li><?= h($error) ?></li>
<?php endforeach; ?>
</ul>
<?php endif; ?>
<div class="grid-2">
<div class="card">
<h2>Kontodaten</h2>
<table class="data-table" style="margin-bottom:1.2rem;">
<tr><td>Benutzername</td><td><?= h($user['username']) ?></td></tr>
<tr><td>Rolle</td><td><?= h($user['role']) ?></td></tr>
</table>
<form method="post" action="" class="form-stack">
<input type="hidden" name="action" value="update_profile">
<div class="form-group">
<label for="display_name">Anzeigename <span class="form-optional">(optional)</span></label>
<input
type="text"
id="display_name"
name="display_name"
maxlength="100"
value="<?= h($user['display_name'] ?? '') ?>"
>
</div>
<div class="form-group">
<label for="email">E-Mail-Adresse</label>
<input
type="email"
id="email"
name="email"
required
maxlength="190"
value="<?= h($user['email']) ?>"
>
</div>
<button type="submit" class="btn btn-primary btn-full">Speichern</button>
</form>
</div>
<div class="card">
<h2>Passwort ändern</h2>
<form method="post" action="" class="form-stack">
<input type="hidden" name="action" value="change_password">
<div class="form-group">
<label for="current_password">Aktuelles Passwort</label>
<input type="password" id="current_password" name="current_password" required>
</div>
<div class="form-group">
<label for="new_password">Neues Passwort</label>
<input type="password" id="new_password" name="new_password" required>
</div>
<div class="form-group">
<label for="new_password_repeat">Neues Passwort wiederholen</label>
<input type="password" id="new_password_repeat" name="new_password_repeat" required>
</div>
<button type="submit" class="btn btn-primary btn-full">Passwort ändern</button>
</form>
</div>
</div>
<div class="card">
<h2>Standorte</h2>
<?php if (empty($locations)): ?>
<p class="hint">Es sind noch keine Standorte gespeichert.</p>
<?php else: ?>
<table class="data-table">
<thead>
<tr>
<th>Name</th>
<th>Breitengrad</th>
<th>Längengrad</th>
<th>Höhe</th>
<th>Zeitzone</th>
<th>Standard</th>
<th></th>
</tr>
</thead>
<tbody>
<?php foreach ($locations as $location): ?>
<tr>
<td><?= h($location['name']) ?></td>
<td><?= h((string)$location['latitude']) ?></td>
<td><?= h((string)$location['longitude']) ?></td>
<td><?= h($location['elevation'] !== null ? (string)$location['elevation'] . ' m' : '—') ?></td>
<td><?= h($location['timezone']) ?></td>
<td><?= (int)$location['is_default'] === 1 ? '★' : '—' ?></td>
<td class="action-cell">
<?php if ((int)$location['is_default'] !== 1): ?>
<form method="post" action="">
<input type="hidden" name="action" value="set_default_location">
<input type="hidden" name="location_id" value="<?= (int)$location['id'] ?>">
<button type="submit" class="btn btn-sm btn-secondary">Als Standard</button>
</form>
<?php endif; ?>
<form method="post" action="" onsubmit="return confirm('Standort wirklich löschen?');">
<input type="hidden" name="action" value="delete_location">
<input type="hidden" name="location_id" value="<?= (int)$location['id'] ?>">
<button type="submit" class="btn btn-sm btn-danger">Löschen</button>
</form>
</td>
</tr>
<?php endforeach; ?>
</tbody>
</table>
<?php endif; ?>
</div>
<div class="card">
<h2>Neuen Standort hinzufügen</h2>
<p class="hint" style="margin-bottom:1rem;">Suche einen Ort, nutze den Browser-Standort oder klicke direkt in die Karte.</p>
<div class="input-row" style="margin-bottom:0.75rem;">
<input type="text" id="place-search" placeholder="Ort oder Adresse, z. B. Berlin, Wien">
<button type="button" id="search-place" class="btn btn-primary">Suchen</button>
<button type="button" id="lookup-elevation" class="btn btn-secondary">Höhe ermitteln</button>
<button type="button" id="detect-location" class="btn btn-secondary">Browser-Standort</button>
</div>
<div id="map" class="map"></div>
<form method="post" action="" class="form-stack" style="margin-top:1.5rem;">
<input type="hidden" name="action" value="add_location">
<div class="grid-2" style="gap:0.8rem;">
<div class="form-group">
<label for="name">Name</label>
<input type="text" id="name" name="name" required value="<?= h($_POST['name'] ?? '') ?>">
</div>
<div class="form-group">
<label for="timezone">Zeitzone (IANA)</label>
<input type="text" id="timezone" name="timezone" required value="<?= h($_POST['timezone'] ?? ($defaultLocation['timezone'] ?? 'Europe/Berlin')) ?>">
</div>
<div class="form-group">
<label for="latitude">Breitengrad</label>
<input type="text" id="latitude" name="latitude" required value="<?= h($_POST['latitude'] ?? ($defaultLocation['latitude'] ?? '')) ?>">
</div>
<div class="form-group">
<label for="longitude">Längengrad</label>
<input type="text" id="longitude" name="longitude" required value="<?= h($_POST['longitude'] ?? ($defaultLocation['longitude'] ?? '')) ?>">
</div>
<div class="form-group">
<label for="elevation">Höhe (optional, Meter)</label>
<input type="text" id="elevation" name="elevation" value="<?= h($_POST['elevation'] ?? '') ?>">
</div>
</div>
<label class="form-checkbox">
<input type="checkbox" name="is_default" value="1" <?= isset($_POST['is_default']) ? 'checked' : '' ?>>
Als Standard-Standort speichern
</label>
<button type="submit" class="btn btn-primary">Standort speichern</button>
</form>
</div>
<script
src="https://unpkg.com/leaflet@1.9.4/dist/leaflet.js"
integrity="sha256-20nQCchB9co0qIjJZRGuk2/Z9VM+kNiyxNV1lvTlZBo="
crossorigin=""
></script>
<script>
(function () {
const latInput = document.getElementById('latitude');
const lonInput = document.getElementById('longitude');
const elevationInput = document.getElementById('elevation');
const timezoneInput = document.getElementById('timezone');
const detectButton = document.getElementById('detect-location');
const searchInput = document.getElementById('place-search');
const searchButton = document.getElementById('search-place');
const elevationButton = document.getElementById('lookup-elevation');
const nameInput = document.getElementById('name');
const initialLat = parseFloat(<?= json_encode($mapLat) ?>);
const initialLon = parseFloat(<?= json_encode($mapLon) ?>);
const initialZoom = parseInt(<?= json_encode($mapZoom) ?>, 10);
const map = L.map('map').setView([initialLat, initialLon], initialZoom);
L.tileLayer('https://{s}.tile.openstreetmap.org/{z}/{x}/{y}.png', {
maxZoom: 19,
attribution: '&copy; OpenStreetMap-Mitwirkende'
}).addTo(map);
let marker = L.marker([initialLat, initialLon], {
draggable: true
}).addTo(map);
function setInputs(lat, lon) {
latInput.value = Number(lat).toFixed(7);
lonInput.value = Number(lon).toFixed(7);
}
function setBrowserTimezoneIfEmpty() {
if (!timezoneInput.value.trim()) {
try {
const tz = Intl.DateTimeFormat().resolvedOptions().timeZone;
if (tz) {
timezoneInput.value = tz;
}
} catch (e) {
}
}
}
function moveMarker(lat, lon, zoom = null) {
marker.setLatLng([lat, lon]);
if (zoom !== null) {
map.setView([lat, lon], zoom);
} else {
map.panTo([lat, lon]);
}
setInputs(lat, lon);
setBrowserTimezoneIfEmpty();
}
async function lookupElevation() {
const lat = parseFloat(latInput.value);
const lon = parseFloat(lonInput.value);
if (!Number.isFinite(lat) || !Number.isFinite(lon)) {
alert('Bitte zuerst einen gültigen Standort wählen.');
return;
}
try {
const url = 'https://api.open-elevation.com/api/v1/lookup?locations='
+ encodeURIComponent(lat + ',' + lon);
const response = await fetch(url, {
method: 'GET'
});
if (!response.ok) {
throw new Error('HTTP ' + response.status);
}
const data = await response.json();
if (
!data ||
!data.results ||
!Array.isArray(data.results) ||
data.results.length === 0 ||
typeof data.results[0].elevation === 'undefined'
) {
throw new Error('Keine Höhendaten erhalten.');
}
elevationInput.value = data.results[0].elevation;
} catch (error) {
alert('Die Höhe konnte nicht automatisch ermittelt werden.');
console.error(error);
}
}
marker.on('dragend', function (event) {
const pos = event.target.getLatLng();
setInputs(pos.lat, pos.lng);
});
map.on('click', function (event) {
moveMarker(event.latlng.lat, event.latlng.lng);
});
detectButton.addEventListener('click', function () {
if (!navigator.geolocation) {
alert('Der Browser unterstützt keine Standortbestimmung.');
return;
}
navigator.geolocation.getCurrentPosition(
function (position) {
moveMarker(position.coords.latitude, position.coords.longitude, 13);
setBrowserTimezoneIfEmpty();
},
function (error) {
let message = 'Standort konnte nicht ermittelt werden.';
if (error && error.message) {
message += ' ' + error.message;
}
alert(message);
},
{
enableHighAccuracy: true,
timeout: 10000,
maximumAge: 0
}
);
});
async function doSearch() {
const query = searchInput.value.trim();
if (!query) {
alert('Bitte einen Ort oder eine Adresse eingeben.');
return;
}
try {
const url = 'https://photon.komoot.io/api/?q=' + encodeURIComponent(query) + '&limit=5';
const response = await fetch(url, {
method: 'GET'
});
if (!response.ok) {
throw new Error('HTTP ' + response.status);
}
const data = await response.json();
if (!data.features || data.features.length === 0) {
alert('Kein passender Ort gefunden.');
return;
}
const feature = data.features[0];
const coords = feature.geometry.coordinates;
const lon = parseFloat(coords[0]);
const lat = parseFloat(coords[1]);
moveMarker(lat, lon, 13);
const props = feature.properties || {};
const parts = [];
if (props.name) parts.push(props.name);
if (props.city && props.city !== props.name) parts.push(props.city);
if (props.state) parts.push(props.state);
if (props.country) parts.push(props.country);
if (parts.length > 0) {
nameInput.value = parts.join(', ');
} else {
nameInput.value = query;
}
setBrowserTimezoneIfEmpty();
} catch (error) {
alert('Die Ortssuche ist fehlgeschlagen.');
console.error(error);
}
}
searchButton.addEventListener('click', doSearch);
elevationButton.addEventListener('click', lookupElevation);
searchInput.addEventListener('keydown', function (event) {
if (event.key === 'Enter') {
event.preventDefault();
doSearch();
}
});
if (!latInput.value || !lonInput.value) {
setInputs(initialLat, initialLon);
}
setBrowserTimezoneIfEmpty();
})();
</script>
<?php require __DIR__ . '/footer.php'; ?>