<?php
require_once __DIR__ . '/inc/secure.php'; // Security bootstrap
header('Content-Type: application/json');
require_once __DIR__ . '/admin-panal/includes/db.php';
$action = $_POST['action'] ?? '';
if ($action === 'register') {
$fullName = trim($_POST['full_name'] ?? '');
$email = trim($_POST['email'] ?? '');
$password = $_POST['password'] ?? '';
if (empty($fullName) || empty($email) || empty($password)) {
echo json_encode(['success' => false, 'message' => 'All fields are required.']);
exit;
}
if (!filter_var($email, FILTER_VALIDATE_EMAIL)) {
echo json_encode(['success' => false, 'message' => 'Invalid email address.']);
exit;
}
// Check if email exists
$stmt = $pdo->prepare('SELECT id FROM customers WHERE email = ?');
$stmt->execute([$email]);
if ($stmt->fetch()) {
echo json_encode(['success' => false, 'message' => 'Email address is already registered.']);
exit;
}
// Create user
$hash = password_hash($password, PASSWORD_DEFAULT);
$stmt = $pdo->prepare('INSERT INTO customers (full_name, email, password_hash) VALUES (?, ?, ?)');
try {
if ($stmt->execute([$fullName, $email, $hash])) {
echo json_encode(['success' => true, 'message' => 'Registration successful! You can now log in.']);
} else {
echo json_encode(['success' => false, 'message' => 'Registration failed. Please try again.']);
}
} catch (PDOException $e) {
echo json_encode(['success' => false, 'message' => 'Database error occurred.']);
}
} elseif ($action === 'login') {
$email = trim($_POST['email'] ?? '');
$password = $_POST['password'] ?? '';
if (empty($email) || empty($password)) {
echo json_encode(['success' => false, 'message' => 'Email and password are required.']);
exit;
}
$stmt = $pdo->prepare('SELECT id, full_name, password_hash FROM customers WHERE email = ?');
$stmt->execute([$email]);
$customer = $stmt->fetch(PDO::FETCH_ASSOC);
if ($customer && password_verify($password, $customer['password_hash'])) {
$_SESSION['customer_id'] = $customer['id'];
$_SESSION['customer_name'] = $customer['full_name'];
$_SESSION['customer_email'] = $email;
echo json_encode(['success' => true, 'message' => 'Login successful!']);
} else {
echo json_encode(['success' => false, 'message' => 'Invalid email or password.']);
}
} elseif ($action === 'logout') {
unset($_SESSION['customer_id']);
unset($_SESSION['customer_name']);
unset($_SESSION['customer_email']);
echo json_encode(['success' => true]);
} else {
echo json_encode(['success' => false, 'message' => 'Invalid action.']);
}