T.ME/BIBIL_0DAY
CasperSecurity


Server : Apache/2
System : Linux server-15-235-50-60 5.15.0-164-generic #174-Ubuntu SMP Fri Nov 14 20:25:16 UTC 2025 x86_64
User : gositeme ( 1004)
PHP Version : 8.2.29
Disable Function : exec,system,passthru,shell_exec,proc_close,proc_open,dl,popen,show_source,posix_kill,posix_mkfifo,posix_getpwuid,posix_setpgid,posix_setsid,posix_setuid,posix_setgid,posix_seteuid,posix_setegid,posix_uname
Directory :  /home/gositeme/domains/soundstudiopro.com/public_html/api/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Current File : /home/gositeme/domains/soundstudiopro.com/public_html/api/save_variation.php
<?php
session_start();
header('Content-Type: application/json');

// Check if user is logged in
if (!isset($_SESSION['user_id'])) {
    echo json_encode([
        'success' => false,
        'message' => 'User not logged in'
    ]);
    exit;
}

$input = json_decode(file_get_contents('php://input'), true);
if (!$input) {
    echo json_encode([
        'success' => false,
        'message' => 'Invalid input data'
    ]);
    exit;
}

$track_id = $input['track_id'] ?? null;
$variation_id = $input['variation_id'] ?? null;
$action = $input['action'] ?? 'like'; // like, dislike, favorite, set_main

if (!$track_id || !$variation_id) {
    echo json_encode([
        'success' => false,
        'message' => 'Track ID and Variation ID required'
    ]);
    exit;
}

try {
    require_once '../config/database.php';
    $pdo = getDBConnection();
    
    // Create user_variation_preferences table if it doesn't exist
    $pdo->exec("
        CREATE TABLE IF NOT EXISTS user_variation_preferences (
            id INT AUTO_INCREMENT PRIMARY KEY,
            user_id INT NOT NULL,
            track_id INT NOT NULL,
            variation_id INT NOT NULL,
            is_main_track BOOLEAN DEFAULT FALSE,
            created_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP,
            updated_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
            FOREIGN KEY (user_id) REFERENCES users(id) ON DELETE CASCADE,
            FOREIGN KEY (track_id) REFERENCES music_tracks(id) ON DELETE CASCADE,
            FOREIGN KEY (variation_id) REFERENCES audio_variations(id) ON DELETE CASCADE,
            UNIQUE KEY unique_user_track_preference (user_id, track_id)
        )
    ");
    
    // Verify user owns the track
    $stmt = $pdo->prepare("SELECT id FROM music_tracks WHERE id = ? AND user_id = ?");
    $stmt->execute([$track_id, $_SESSION['user_id']]);
    $track = $stmt->fetch(PDO::FETCH_ASSOC);
    
    if (!$track) {
        echo json_encode([
            'success' => false,
            'message' => 'Track not found or access denied'
        ]);
        exit;
    }
    
    // Check if variation exists
    $stmt = $pdo->prepare("SELECT id FROM audio_variations WHERE id = ? AND track_id = ?");
    $stmt->execute([$variation_id, $track_id]);
    $variation = $stmt->fetch(PDO::FETCH_ASSOC);
    
    if (!$variation) {
        echo json_encode([
            'success' => false,
            'message' => 'Variation not found'
        ]);
        exit;
    }
    
    if ($action === 'set_main') {
        // Set this variation as the main track for the user
        // First, clear any existing main track preference for this track
        $stmt = $pdo->prepare("
            UPDATE user_variation_preferences 
            SET is_main_track = FALSE 
            WHERE user_id = ? AND track_id = ?
        ");
        $stmt->execute([$_SESSION['user_id'], $track_id]);
        
        // Then set this variation as the main track
        $stmt = $pdo->prepare("
            INSERT INTO user_variation_preferences (user_id, track_id, variation_id, is_main_track, created_at) 
            VALUES (?, ?, ?, TRUE, NOW())
            ON DUPLICATE KEY UPDATE 
                variation_id = VALUES(variation_id), 
                is_main_track = TRUE, 
                updated_at = NOW()
        ");
        
        $stmt->execute([$_SESSION['user_id'], $track_id, $variation_id]);
        
        echo json_encode([
            'success' => true,
            'message' => 'Variation set as main track successfully'
        ]);
    } else {
        // Handle other actions (like, dislike, favorite) - legacy support
        $stmt = $pdo->prepare("
            INSERT INTO user_variation_preferences (user_id, track_id, variation_id, is_main_track, created_at) 
            VALUES (?, ?, ?, FALSE, NOW())
            ON DUPLICATE KEY UPDATE 
                variation_id = VALUES(variation_id), 
                updated_at = NOW()
        ");
        
        $stmt->execute([$_SESSION['user_id'], $track_id, $variation_id]);
        
        echo json_encode([
            'success' => true,
            'message' => 'Variation preference saved successfully'
        ]);
    }
    
} catch (Exception $e) {
    error_log("Error saving variation preference: " . $e->getMessage());
    echo json_encode([
        'success' => false,
        'message' => 'Internal server error'
    ]);
}
?>

CasperSecurity Mini