[ Mini Kiebo ]
Server: Windows NT AKFAR_SERVER 10.0 build 26200 (Windows 10) AMD64
Path:
D:
/
xampp
/
htdocs
/
repository_afbs
/
user
/
[
Home
]
File: profile.php
<?php session_start(); require_once '../includes/config.php'; require_once '../includes/database.php'; require_once '../includes/functions.php'; require_once '../includes/auth.php'; if (!isLoggedIn()) { header('Location: ../login.php'); exit(); } $db = new Database(); $conn = $db->getConnection(); $user_id = $_SESSION['user_id']; $message = ''; $error = ''; // Ambil data user $query = "SELECT * FROM users WHERE id = :id"; $stmt = $conn->prepare($query); $stmt->bindParam(':id', $user_id); $stmt->execute(); $user = $stmt->fetch(PDO::FETCH_ASSOC); // Handle form submit if ($_SERVER['REQUEST_METHOD'] == 'POST') { $full_name = $_POST['full_name']; $email = $_POST['email']; $nim = $_POST['nim'] ?? null; $program_studi = $_POST['program_studi'] ?? 'Farmasi'; $angkatan = $_POST['angkatan'] ?? null; $no_telepon = $_POST['no_telepon'] ?? null; $alamat = $_POST['alamat'] ?? null; // Validasi if (empty($full_name) || empty($email)) { $error = "Nama dan email harus diisi!"; } else { try { $conn->beginTransaction(); // Update user data $update_query = "UPDATE users SET full_name = :full_name, email = :email, nim = :nim, program_studi = :program_studi, angkatan = :angkatan, no_telepon = :no_telepon, alamat = :alamat WHERE id = :id"; $update_stmt = $conn->prepare($update_query); $update_stmt->bindParam(':full_name', $full_name); $update_stmt->bindParam(':email', $email); $update_stmt->bindParam(':nim', $nim); $update_stmt->bindParam(':program_studi', $program_studi); $update_stmt->bindParam(':angkatan', $angkatan); $update_stmt->bindParam(':no_telepon', $no_telepon); $update_stmt->bindParam(':alamat', $alamat); $update_stmt->bindParam(':id', $user_id); $update_stmt->execute(); // Update session $_SESSION['full_name'] = $full_name; // Handle password change if (!empty($_POST['current_password']) && !empty($_POST['new_password'])) { // Verify current password $check_query = "SELECT password FROM users WHERE id = :id"; $check_stmt = $conn->prepare($check_query); $check_stmt->bindParam(':id', $user_id); $check_stmt->execute(); $current_hash = $check_stmt->fetch(PDO::FETCH_ASSOC)['password']; if (password_verify($_POST['current_password'], $current_hash)) { if ($_POST['new_password'] == $_POST['confirm_password']) { $new_hash = password_hash($_POST['new_password'], PASSWORD_DEFAULT); $pass_query = "UPDATE users SET password = :password WHERE id = :id"; $pass_stmt = $conn->prepare($pass_query); $pass_stmt->bindParam(':password', $new_hash); $pass_stmt->bindParam(':id', $user_id); $pass_stmt->execute(); $message = "Profil dan password berhasil diupdate!"; } else { $error = "Konfirmasi password tidak cocok!"; } } else { $error = "Password saat ini salah!"; } } // Handle foto profil upload if (isset($_FILES['foto_profil']) && $_FILES['foto_profil']['error'] == 0) { $allowed = ['jpg', 'jpeg', 'png', 'gif']; $filename = $_FILES['foto_profil']['name']; $file_ext = strtolower(pathinfo($filename, PATHINFO_EXTENSION)); if (in_array($file_ext, $allowed)) { $upload_dir = '../uploads/profiles/'; if (!file_exists($upload_dir)) { mkdir($upload_dir, 0777, true); } $new_filename = 'user_' . $user_id . '_' . time() . '.' . $file_ext; $upload_path = $upload_dir . $new_filename; if (move_uploaded_file($_FILES['foto_profil']['tmp_name'], $upload_path)) { // Hapus foto lama if (!empty($user['foto_profil']) && file_exists($upload_dir . $user['foto_profil'])) { unlink($upload_dir . $user['foto_profil']); } $foto_query = "UPDATE users SET foto_profil = :foto WHERE id = :id"; $foto_stmt = $conn->prepare($foto_query); $foto_stmt->bindParam(':foto', $new_filename); $foto_stmt->bindParam(':id', $user_id); $foto_stmt->execute(); } } } $conn->commit(); $message = "Profil berhasil diupdate!"; // Refresh user data $stmt->execute(); $user = $stmt->fetch(PDO::FETCH_ASSOC); } catch(Exception $e) { $conn->rollBack(); $error = "Gagal mengupdate profil: " . $e->getMessage(); } } } $page_title = 'Edit Profil'; include '../templates/header.php'; include '../templates/user-navbar.php'; ?> <div class="container-fluid"> <div class="row"> <?php include '../templates/user-sidebar.php'; ?> <main class="col-md-9 ms-sm-auto col-lg-10 px-md-4"> <div class="d-flex justify-content-between flex-wrap flex-md-nowrap align-items-center pt-3 pb-2 mb-3 border-bottom"> <h1 class="h2">Edit Profil</h1> </div> <?php if($message): ?> <div class="alert alert-success alert-dismissible fade show"> <?php echo $message; ?> <button type="button" class="btn-close" data-bs-dismiss="alert"></button> </div> <?php endif; ?> <?php if($error): ?> <div class="alert alert-danger alert-dismissible fade show"> <?php echo $error; ?> <button type="button" class="btn-close" data-bs-dismiss="alert"></button> </div> <?php endif; ?> <div class="row"> <div class="col-md-8"> <!-- Form Edit Profil --> <div class="card mb-4"> <div class="card-header"> <h5 class="mb-0">Informasi Pribadi</h5> </div> <div class="card-body"> <form method="POST" enctype="multipart/form-data"> <div class="row"> <div class="col-md-6 mb-3"> <label for="full_name" class="form-label">Nama Lengkap *</label> <input type="text" class="form-control" id="full_name" name="full_name" value="<?php echo htmlspecialchars($user['full_name']); ?>" required> </div> <div class="col-md-6 mb-3"> <label for="email" class="form-label">Email *</label> <input type="email" class="form-control" id="email" name="email" value="<?php echo htmlspecialchars($user['email']); ?>" required> </div> </div> <div class="row"> <div class="col-md-6 mb-3"> <label for="nim" class="form-label">NIM</label> <input type="text" class="form-control" id="nim" name="nim" value="<?php echo htmlspecialchars($user['nim'] ?? ''); ?>"> </div> <div class="col-md-6 mb-3"> <label for="program_studi" class="form-label">Program Studi</label> <select class="form-select" id="program_studi" name="program_studi"> <option value="Farmasi" <?php echo $user['program_studi'] == 'Farmasi' ? 'selected' : ''; ?>>Farmasi</option> <option value="Farmasi Klinis" <?php echo $user['program_studi'] == 'Farmasi Klinis' ? 'selected' : ''; ?>>Farmasi Klinis</option> <option value="Farmasi Industri" <?php echo $user['program_studi'] == 'Farmasi Industri' ? 'selected' : ''; ?>>Farmasi Industri</option> </select> </div> </div> <div class="row"> <div class="col-md-6 mb-3"> <label for="angkatan" class="form-label">Angkatan</label> <select class="form-select" id="angkatan" name="angkatan"> <option value="">Pilih Angkatan</option> <?php for($year = date('Y'); $year >= 2015; $year--): ?> <option value="<?php echo $year; ?>" <?php echo $user['angkatan'] == $year ? 'selected' : ''; ?>> <?php echo $year; ?> </option> <?php endfor; ?> </select> </div> <div class="col-md-6 mb-3"> <label for="no_telepon" class="form-label">No. Telepon</label> <input type="text" class="form-control" id="no_telepon" name="no_telepon" value="<?php echo htmlspecialchars($user['no_telepon'] ?? ''); ?>"> </div> </div> <div class="mb-3"> <label for="alamat" class="form-label">Alamat</label> <textarea class="form-control" id="alamat" name="alamat" rows="3"><?php echo htmlspecialchars($user['alamat'] ?? ''); ?></textarea> </div> <hr class="my-4"> <h5 class="mb-3">Ganti Password</h5> <p class="text-muted small">Kosongkan jika tidak ingin mengganti password</p> <div class="row"> <div class="col-md-4 mb-3"> <label for="current_password" class="form-label">Password Saat Ini</label> <input type="password" class="form-control" id="current_password" name="current_password"> </div> <div class="col-md-4 mb-3"> <label for="new_password" class="form-label">Password Baru</label> <input type="password" class="form-control" id="new_password" name="new_password"> </div> <div class="col-md-4 mb-3"> <label for="confirm_password" class="form-label">Konfirmasi Password</label> <input type="password" class="form-control" id="confirm_password" name="confirm_password"> </div> </div> <button type="submit" class="btn btn-primary"> <i class="fas fa-save"></i> Simpan Perubahan </button> </form> </div> </div> </div> <div class="col-md-4"> <!-- Foto Profil --> <div class="card mb-4"> <div class="card-header"> <h5 class="mb-0">Foto Profil</h5> </div> <div class="card-body text-center"> <div class="mb-3"> <?php if(!empty($user['foto_profil'])): ?> <img src="../uploads/profiles/<?php echo $user['foto_profil']; ?>" alt="Foto Profil" class="img-fluid rounded-circle" style="width: 150px; height: 150px; object-fit: cover;"> <?php else: ?> <div class="bg-secondary text-white rounded-circle d-flex align-items-center justify-content-center mx-auto" style="width: 150px; height: 150px; font-size: 64px;"> <?php echo strtoupper(substr($user['full_name'], 0, 1)); ?> </div> <?php endif; ?> </div> <form method="POST" enctype="multipart/form-data"> <div class="mb-3"> <label for="foto_profil" class="form-label">Upload Foto Baru</label> <input type="file" class="form-control" id="foto_profil" name="foto_profil" accept="image/jpeg,image/png,image/gif"> <div class="form-text">Format: JPG, PNG, GIF. Maks: 2MB</div> </div> <button type="submit" class="btn btn-outline-primary"> <i class="fas fa-upload"></i> Upload Foto </button> </form> </div> </div> <!-- Informasi Akun --> <div class="card"> <div class="card-header"> <h5 class="mb-0">Informasi Akun</h5> </div> <div class="card-body"> <table class="table table-sm"> <tr> <td>Username</td> <td><strong><?php echo htmlspecialchars($user['username']); ?></strong></td> </tr> <tr> <td>Role</td> <td><span class="badge bg-primary"><?php echo $user['role']; ?></span></td> </tr> <tr> <td>Status</td> <td> <?php if($user['is_active']): ?> <span class="badge bg-success">Active</span> <?php else: ?> <span class="badge bg-secondary">Inactive</span> <?php endif; ?> </td> </tr> <tr> <td>Bergabung</td> <td><?php echo date('d F Y', strtotime($user['created_at'])); ?></td> </tr> <tr> <td>Terakhir Login</td> <td><?php echo $user['last_login'] ? waktuLalu($user['last_login']) : 'Belum pernah'; ?></td> </tr> </table> </div> </div> </div> </div> </main> </div> </div> <?php include '../templates/footer.php'; ?>