<?php session_start();
	if(isset($_GET['login'])) {
		$sid = "?PHPSESSID=".session_id();
	  include ("inc/verbind.inc.php");
    $email = $_POST['email'];
 		$password = $_POST['password'];
		$stmt = $pdo->prepare("SELECT * FROM tbl_owners WHERE email = ?");
		$stmt->execute([$email]);
		$user = $stmt->fetch();    
    if ($user !== false && password_verify($password, $user['password']) AND ($_GET["logout"] != "1") ) {
        $_SESSION['userid'] = $user['id'];
				$_SESSION['gname'] = $user['gname'];
				$_SESSION['sname'] = $user['sname'];
				//header("Location: index.php?PHPSESSID=".sid);	
				$message = "Du bist eingeloggt. <a href=\"index.php".$sid."\">Lege los!</a>";
		 } else {
        $errorMessage = "<h2>E-Mail oder Passwort war ungültig!</h2><p>Versuche es bitte noch einmal.</p>";
     } 
		 
	 } else if ($_GET["logout"] == "1") {
	unset($_SESSION["userid"]);
	unset($_SESSION["gname"]);
	unset($_SESSION["sname"]);
	session_unset();
	session_destroy();
	$errorMessage = "<h2>Du bist ausgeloggt.</h2><p>Hier kannst du dich erneut einloggen:</p>";
}
		
if(isset($_SESSION["userid"])) {
	$department = "Startseite";
	$here = "startseite";
	include("inc/header.inc.php"); 
  include_once("icons/icons.svg");
	$sid = "?PHPSESSID=".session_id();
	$userid = $_SESSION['userid'];
	$name = $_SESSION['gname']." ".$_SESSION['sname'];
?>
<h2>Herzlich willkommen, <?=$name?>!</h2>
<?=$message?>
<p>Was möchtest du tun?</p>
<a href="dinge/get-object.php<?=$sid?>">
    <div class="icon">
    <svg viewBox="0 0 100 100" class="">
      <use xlink:href="#things"></use>
    </svg>
    </div>
</a>

<?php
 } else {
	$department = "Login";
	$here = "login";
	include("inc/header.inc.php"); 
  include_once("icons/icons.svg");
	 
?>
<?=$errorMessage?>
<div class="login-box">
  <form action="index.php?login=1" method="post" accept-charset="utf-8">
    <fieldset>
      <div class="icon">
        <svg viewBox="0 0 100 100" class="">
          <use xlink:href="#profile"></use>
        </svg>
      </div>
      <div>
      <label for="username">Benutzer:</label>
      <input type="email" name="email" placeholder="E-Mail-Adresse" id="email" required>
      </div>
      <div>
      <label for="password">Passwort:</label>
      <input type="password" name="password" placeholder="Passwort" id="password" required>
      </div>
      <input type="submit" value="Login">
    </fieldset>
  </form>
</div>
<?php } ?>
</body>
</html>
