diff --git a/website/.htaccess b/website/.htaccess
new file mode 100644
index 0000000..5c0147b
--- /dev/null
+++ b/website/.htaccess
@@ -0,0 +1,14 @@
+Options +FollowSymLinks
+RewriteEngine On
+
+ErrorDocument 404 /error404.jpg
+
+RewriteCond %{SCRIPT_FILENAME} !-d
+RewriteCond %{SCRIPT_FILENAME} !-f
+
+# Resolve .php file for extensionless php urls
+RewriteRule ^([^/.]+)$ $1.php [L]
+
+RewriteRule ^([^/.]+)\/$ $1.php [L]
+
+RewriteRule ^profile/([A-z0-9]+)\/?$ profile.php?username=$1 [NC]
\ No newline at end of file
diff --git a/website/mysql_config.xml b/website/mysql_config.xml
deleted file mode 100644
index de2d929..0000000
--- a/website/mysql_config.xml
+++ /dev/null
@@ -1,7 +0,0 @@
-
-
- localhost
- myhyvesbookplus
- mhbp
- qdtboXhCHJyL2szC
-
\ No newline at end of file
diff --git a/website/public/login.php b/website/public/login.php
index f889f2f..65babdf 100644
--- a/website/public/login.php
+++ b/website/public/login.php
@@ -4,27 +4,34 @@
include("../views/login_head.php");
require_once("../queries/connect.php");
include_once("../queries/login.php");
+ include_once("../queries/checkInput.php")
?>
+ window.onload=checkLoggedIn();
+ ";
+ }
+
// Define variables and set to empty values
$uname = $psw ="";
$loginErr ="";
// Trying to login
if ($_SERVER["REQUEST_METHOD"] == "POST") {
- $uname=strtolower($_POST["uname"]);
// Empty username or password field
if (empty($_POST["uname"]) || empty($_POST["psw"])) {
$loginErr = "Gebruikersnaam of wachtwoord is niet ingevuld";
}
else {
- $psw=$_POST["psw"];
- $hash=getUser()["password"];
- $userid=getUser()["userID"];
+ $uname = strtolower(test_input($_POST["uname"]));
+ $psw = test_input($_POST["psw"]);
+ $hash = getUser()["password"];
+ $userid = getUser()["userID"];
// If there's an account, go to the profile page
if(password_verify($psw, $hash)) {
@@ -41,5 +48,18 @@
/* This view adds login view */
include("../views/login-view.php");
?>
+
+
+