<!DOCTYPE HTML>
<html>
<head>
</head>
<body>
<?php
$footer = "<a href='welcome.php'>return to main screen</a><br /></body></html>";
session_start();

if(!isset($_SESSION['uid']))
{
    ?>
    not logged in<br />
    <?php
    echo $footer;
    exit;
}
if(isset($_GET["name"]))
{
    $uid = $_SESSION['uid'];
    $name = $_GET["name"];
    if($name == NULL)
    {
        ?>
        No name?<br />
        <?php
        echo $footer;
        exit;
    }
        require('conf.php');
        /*make sure no character share the same name*/
        if(mysql_fetch_array(mysql_query("SELECT * FROM characters WHERE name = '" . $name . "'")))
        {
            echo "name exist, choose another one<br />".$footer;
            exit;
        }
            mysql_query("INSERT INTO characters (name, uid, type)VALUES ('" . $name . "', '" . $uid . "', 'player')");
            if($character = mysql_fetch_array(mysql_query("SELECT * FROM characters WHERE name = '" . $name . "'")))
            {
                echo "success<br />";
                nfo($character);
            }
            else
            {
                echo "failed<br />";
            }
}
elseif(isset($_GET['id']))
{
    $uid = $_SESSION['uid'];
    $id = $_GET['id'];
    require('conf.php');
    /*load character and make sure id match UID*/
    $character = mysql_fetch_array(mysql_query("SELECT * FROM characters WHERE id = '" . $id . "'"));
    if(!$character)
    {
        echo "trying to edit non-existent player<br />";
    }
    elseif($character['uid'] != $uid)
    {
        echo "The logged user does not own the character he's trying to edit<br />";
    }
    else
    {
        nfo($character);
    }

    mysql_close($sql);
}

function nfo($character)
{
        echo $character['name'] . "<br />";
        echo $character['about'] . "<br />";
        echo "you currently cant change anything<br />";
}
?>
<a href='characters.php'>return to character list</a><br />
<a href='welcome.php'>return to main screen</a>
</body>
</html>
