<?php require_once './auth1.php';

//Auswertung des Formulars mit den Userdaten
	if (!empty($_POST)) {
		if (
			empty($_POST['f']['username']) ||
			empty($_POST['f']['password'])
		) {
			$message['error'] = 'Es wurden nicht alle Felder ausgefuellt.';
		} else {
			$mysqli = @new mysqli('rdbms.strato.de', 'U3279746', '193nomoreDB', 'DB3279746');
			if ($mysqli->connect_error) {
				$message['error'] = 'Datenbankverbindung fehlgeschlagen: ' . $mysqli->connect_error;
			}
			$query = sprintf(
				"SELECT username, password FROM koordinator WHERE username = '%s'",
				$mysqli->real_escape_string($_POST['f']['username'])
			);
			$result = $mysqli->query($query);
			if ($row = $result->fetch_array(MYSQLI_ASSOC)) {
				if (crypt($_POST['f']['password'], $row['password']) == $row['password']) {
					session_start();
 
					$_SESSION = array(
						'login' => true,
						'user'  => array(
							'username'  => $row['username']
						)
					);
					$message['success'] = 'Anmeldung erfolgreich, <a href="wettkaempfeA.php">weiter zum Inhalt.';
					header('Location: http://' . $_SERVER['HTTP_HOST'] . '/wettkaempfeA.php');
				} else {
					$message['error'] = 'Das Kennwort ist nicht korrekt.';
				}
			} else {
				$message['error'] = 'Der Benutzer wurde nicht gefunden.';
			}
			$mysqli->close();
		}
	} else {
		$message['notice'] = 'Geben Sie Ihre Zugangsdaten ein um sich anzumelden.<br/><br/>';
	}
//Ab hier Darstellung der Website vor Formularaufruf
?>
<!DOCTYPE html>
<html>
	<head>
		<title>Homepage der Sporkoordinatoren des Main-Kinzig-Kreises</title>
		<meta http-equiv="content-type" content="text/html; charset=utf-8" />
		<meta name="description" content="" />
		<meta name="keywords" content="" />
		<!--[if lte IE 8]><script src="js/html5shiv.js"></script><![endif]-->
		<script src="js/jquery.min.js"></script>
		<script src="js/skel.min.js"></script>
		<script src="js/skel-layers.min.js"></script>
		<script src="js/init.js"></script>
		<noscript>
			<link rel="stylesheet" href="css/skel.css" />
			<link rel="stylesheet" href="css/style.css" />
			<link rel="stylesheet" href="css/style-xlarge.css" />
		</noscript>
	</head>
	<body>
		
		<!-- Header -->
		<header id="header">
			<nav id="nav">
				<ul>
					<li><a href="index.php">Home</a></li>
					<li><a href="vorstellung.php">Kontakt</a></li>
					<?php 
						if ($angemeldet == 0){
							echo "<li><a href='login.php' class='button fit small'>Intern</a></li>";
						}
						else {
							echo "<li><a href='logout.php' class='button fit small'>Abmelden..</a></li>";
						}
					?>
				</ul>
			</nav>
		</header>

		<!-- Main -->
		<section id="main" class="wrapper">
			<div class="container">
				<form action="./login.php" method="post">
					<?php if (isset($message['error'])): ?>
						<fieldset class="error"><legend>Fehler</legend><?php echo $message['error'] ?></fieldset>
					<?php endif;
					if (isset($message['success'])): ?>
						<fieldset class="success"><legend>Erfolg</legend><?php echo $message['success'] ?></fieldset>
					<?php endif;
						if (isset($message['notice'])): ?>
						<fieldset class="notice"><legend></legend><?php echo $message['notice'] ?></fieldset>
					<?php endif; ?>
					<fieldset>	
						<div>
							<label for="username">Benutzername</label>
							<input type="text" name="f[username]" id="username"<?php 
							echo isset($_POST['f']['username']) ? ' value="' . htmlspecialchars($_POST['f']['username']) . '"' : '' ?> />
						</div>
						<div>
							<label for="password">Kennnwort</label> <input type="password" name="f[password]" id="password" />
						</div>
					</fieldset>
					<br/>
					<fieldset>
						<div><ul class="actions"><li></li><input type="submit" name="submit" class="special" value="Anmelden" /></li></ul></div>
					</fieldset>
				</form>
			</div>
		</section>

		<!-- Footer -->
		<footer id="footer">
			<div class="container">
				<ul class="copyright">
					<li>&copy; I. Kaiser</li>
					<li>Design: <a href="http://templated.co">TEMPLATED</a></li>
					<li><a href="disclaimer.php">Disclaimer</a></li>
				</ul>
			</div>
		</footer>
		
	</body>
</html>