APO-Epsilon/apo-website

View on GitHub
pw_reset.php

Summary

Maintainability
A
0 mins
Test Coverage

show_active accesses the super-global variable $_POST.
Open

function show_active() {
    include('mysql_access.php');
    $email = $_POST['email'];
    $default = '$P$BLcP9TBqSqFi6r6jkJHC8EVgoXfy01.';
    $SQL ="UPDATE  `apo`.`contact_information` SET  `password` = '" . $default . "' WHERE  `contact_information`.`email` ='" . $email . "';";
Severity: Minor
Found in pw_reset.php by phpmd

Superglobals

Since: 0.2

Accessing a super-global variable directly is considered a bad practice. These variables should be encapsulated in objects that are provided by a framework, for instance.

Example

class Foo {
    public function bar() {
        $name = $_POST['foo'];
    }
}

Source

Avoid using undefined variables such as '$db' which will lead to PHP notices.
Open

    $result = $db->query($SQL) or die("failed to reset password");
Severity: Minor
Found in pw_reset.php by phpmd

UndefinedVariable

Since: 2.8.0

Detects when a variable is used that has not been defined before.

Example

class Foo
{
    private function bar()
    {
        // $message is undefined
        echo $message;
    }
}

Source https://phpmd.org/rules/cleancode.html#undefinedvariable

Avoid using undefined variables such as '$db' which will lead to PHP notices.
Open

    $response=$db->query("SELECT username FROM contact_information WHERE email ='$email'");
Severity: Minor
Found in pw_reset.php by phpmd

UndefinedVariable

Since: 2.8.0

Detects when a variable is used that has not been defined before.

Example

class Foo
{
    private function bar()
    {
        // $message is undefined
        echo $message;
    }
}

Source https://phpmd.org/rules/cleancode.html#undefinedvariable

The function show_active() contains an exit expression.
Open

    $result = $db->query($SQL) or die("failed to reset password");
Severity: Minor
Found in pw_reset.php by phpmd

ExitExpression

Since: 0.2

An exit-expression within regular code is untestable and therefore it should be avoided. Consider to move the exit-expression into some kind of startup script where an error/exception code is returned to the calling environment.

Example

class Foo {
    public function bar($param)  {
        if ($param === 42) {
            exit(23);
        }
    }
}

Source https://phpmd.org/rules/design.html#exitexpression

A file should declare new symbols (classes, functions, constants, etc.) and cause no other side effects, or it should execute logic with side effects, but should not do both. The first symbol is defined on line 27 and the first side effect is on line 2.
Open

<?php
Severity: Minor
Found in pw_reset.php by phpcodesniffer

TRUE, FALSE and NULL must be lowercase; expected "false" but found "False"
Open

$exec_page = False;
Severity: Minor
Found in pw_reset.php by phpcodesniffer

TRUE, FALSE and NULL must be lowercase; expected "false" but found "False"
Open

$public_page = False;
Severity: Minor
Found in pw_reset.php by phpcodesniffer

TRUE, FALSE and NULL must be lowercase; expected "true" but found "True"
Open

$active_page = True;
Severity: Minor
Found in pw_reset.php by phpcodesniffer

Line exceeds 120 characters; contains 141 characters
Open

    $SQL ="UPDATE  `apo`.`contact_information` SET  `password` = '" . $default . "' WHERE  `contact_information`.`email` ='" . $email . "';";
Severity: Minor
Found in pw_reset.php by phpcodesniffer

End of line character is invalid; expected "\n" but found "\r\n"
Open

<?php
Severity: Minor
Found in pw_reset.php by phpcodesniffer

Spaces must be used to indent lines; tabs are not allowed
Open

    $response=$db->query("SELECT username FROM contact_information WHERE email ='$email'");
Severity: Minor
Found in pw_reset.php by phpcodesniffer

Spaces must be used to indent lines; tabs are not allowed
Open

    echo "Password Reset!<br>";
Severity: Minor
Found in pw_reset.php by phpcodesniffer

Spaces must be used to indent lines; tabs are not allowed
Open

    $default = '$P$BLcP9TBqSqFi6r6jkJHC8EVgoXfy01.';
Severity: Minor
Found in pw_reset.php by phpcodesniffer

Spaces must be used to indent lines; tabs are not allowed
Open

    include('mysql_access.php');
Severity: Minor
Found in pw_reset.php by phpcodesniffer

Spaces must be used to indent lines; tabs are not allowed
Open

    $email = $_POST['email'];
Severity: Minor
Found in pw_reset.php by phpcodesniffer

Spaces must be used to indent lines; tabs are not allowed
Open

    $result = $db->query($SQL) or die("failed to reset password");
Severity: Minor
Found in pw_reset.php by phpcodesniffer

Spaces must be used to indent lines; tabs are not allowed
Open

    echo "email : " . $email . "<br>";
Severity: Minor
Found in pw_reset.php by phpcodesniffer

Spaces must be used to indent lines; tabs are not allowed
Open

    echo "username : " . $result['username'] . "<br>";
Severity: Minor
Found in pw_reset.php by phpcodesniffer

Spaces must be used to indent lines; tabs are not allowed
Open

    echo "password : password<br>";
Severity: Minor
Found in pw_reset.php by phpcodesniffer

Spaces must be used to indent lines; tabs are not allowed
Open

    $SQL ="UPDATE  `apo`.`contact_information` SET  `password` = '" . $default . "' WHERE  `contact_information`.`email` ='" . $email . "';";
Severity: Minor
Found in pw_reset.php by phpcodesniffer

Space before opening parenthesis of function call prohibited
Open

require_once ('mysql_access.php');
Severity: Minor
Found in pw_reset.php by phpcodesniffer

Opening brace should be on a new line
Open

function show_active() {
Severity: Minor
Found in pw_reset.php by phpcodesniffer

Space before opening parenthesis of function call prohibited
Open

require_once ('session.php');
Severity: Minor
Found in pw_reset.php by phpcodesniffer

The variable $SQL is not named in camelCase.
Open

function show_active() {
    include('mysql_access.php');
    $email = $_POST['email'];
    $default = '$P$BLcP9TBqSqFi6r6jkJHC8EVgoXfy01.';
    $SQL ="UPDATE  `apo`.`contact_information` SET  `password` = '" . $default . "' WHERE  `contact_information`.`email` ='" . $email . "';";
Severity: Minor
Found in pw_reset.php by phpmd

CamelCaseVariableName

Since: 0.2

It is considered best practice to use the camelCase notation to name variables.

Example

class ClassName {
    public function doSomething() {
        $data_module = new DataModule();
    }
}

Source

The variable $SQL is not named in camelCase.
Open

function show_active() {
    include('mysql_access.php');
    $email = $_POST['email'];
    $default = '$P$BLcP9TBqSqFi6r6jkJHC8EVgoXfy01.';
    $SQL ="UPDATE  `apo`.`contact_information` SET  `password` = '" . $default . "' WHERE  `contact_information`.`email` ='" . $email . "';";
Severity: Minor
Found in pw_reset.php by phpmd

CamelCaseVariableName

Since: 0.2

It is considered best practice to use the camelCase notation to name variables.

Example

class ClassName {
    public function doSomething() {
        $data_module = new DataModule();
    }
}

Source

There are no issues that match your filters.

Category
Status