. */ require_once dirname(__DIR__, 3).DIRECTORY_SEPARATOR.'bootstrap.php'; use nntmux\db\DB; use nntmux\Users; use nntmux\ColorCLI; $colorCLI = new ColorCLI(); $warning = <<<'WARNING' This script will (re)set the password hashes for older hashes, before the change of hashing mchanism, with the user's email ..as the new password. It is intended for use ONLY if you have a *lot* of users, as this is not secure (a user's email addresses may be known to other users). If you only have a few users then run setUsersPasswordHash.php for each of them instead. WARNING; $usage = "\nUsage: php {$argv[0]} "; echo $colorCLI->warning($warning); if ($argc != 2) { exit($colorCLI->error("\nWrong number of parameters$usage")); } elseif ($argv[1] !== 1 && $argv[1] != '' && $argv[1] != 'IUnderStandTheRisks' && $argv[1] != 'true') { exit($colorCLI->error("\nInvalid parameter(s)$usage")); } $pdo = new DB(); $users = $pdo->query('SELECT id, username, email, password FROM users'); $update = $pdo->Prepare('UPDATE users SET password = :password WHERE id = :id'); $Users = new Users(); foreach ($users as $user) { if (needUpdate($user)) { $hash = $Users->hashPassword($user['email']); if ($hash !== false) { $update->execute([':password' => $hash, ':id' => $user['id']]); echo $colorCLI->primary('Updating hash for user:').$user['username']; } else { echo $colorCLI->error('Error updating hash for user:').$user['username']; } } } function needUpdate($user) { global $colorCLI; $status = true; if (empty($user['email'])) { $status = false; echo $colorCLI->error('Cannot update password hash - Email is not set for user: '.$user['username']); } elseif (preg_match('#^\$.+$#', $user['password'])) { $status = false; echo $user['username'].$colorCLI->primary(' is already using new style hash ;-)'); } return $status; }