File: /home/muratemr/theotto.tr/api/admin/profile.php
<?php
/**
* api/admin/profile.php
* Şifre değiştirme endpoint
*/
declare(strict_types=1);
require_once __DIR__ . '/../../includes/db.php';
require_once __DIR__ . '/../../includes/auth.php';
require_once __DIR__ . '/../../includes/csrf.php';
require_once __DIR__ . '/../../includes/functions.php';
require_login();
csrf_required();
if (post_str('action') !== 'change_password') json_response(false, 'Geçersiz işlem.');
$current = post_str('current_password');
$new = post_str('new_password');
if (!$current) json_response(false, 'Mevcut şifre zorunlu.');
if (!$new) json_response(false, 'Yeni şifre zorunlu.');
if (strlen($new) < 8) json_response(false, 'Yeni şifre en az 8 karakter olmalı.');
$me = current_user();
$user = db_row("SELECT password_hash FROM users WHERE id = ?", [$me['id']]);
if (!$user || !password_verify($current, $user['password_hash'])) {
json_response(false, 'Mevcut şifre hatalı.');
}
$hash = password_hash($new, PASSWORD_DEFAULT);
db_run("UPDATE users SET password_hash = ? WHERE id = ?", [$hash, $me['id']]);
json_response(true, 'Şifreniz başarıyla güncellendi.');