update('accounts', ['password' => encryptPassword($VARS['newpass'])], ['uid' => $_SESSION['uid']]); $_SESSION['password'] = $VARS['newpass']; returnToSender("password_updated"); } else { returnToSender("new_password_mismatch"); } } else { returnToSender("old_password_mismatch"); } break; case "add2fa": if (is_empty($VARS['secret'])) { returnToSender("invalid_parameters"); } $database->update('accounts', ['authsecret' => $VARS['secret']], ['uid' => $_SESSION['uid']]); returnToSender("2fa_enabled"); case "rm2fa": $database->update('accounts', ['authsecret' => ""], ['uid' => $_SESSION['uid']]); returnToSender("2fa_removed"); break; }