<?php
	$where_to_copy_files = "./uploads/";
	/* The user www should have write acces on this directory */

	$user = "mooser";
	$pass = "mse-upload";
		
	function upload_form ()
	{
		?>
		<form action="upload.php" enctype="multipart/form-data" method="post">
		Upload new file: <input type="file" name="file"/><br/>
		<input type="submit">
		</form>
		<?php	
	}
	
	function login_form ()
	{
		?>
		Please login:
		<form action="upload.php">
		User: <input type="text" name="user"></input><br/>
		Pass: <input type="text" name="pass"></input><br/>
		<input type="submit"/>
		</form>
		<?php
	}
		
	function correct_login_info()
	{
		return 
			isset($_GET["user"]) && 
			isset ($_GET["pass"]) &&
			$_GET["user"] == $user &&
			$_GET["pass"] == $pass ;
	}
	
	if (!isset($_SESSION))
		session_start();
	
	if (correct_login_info ()) 
	{
		$_SESSION["logged"] = true;
		header ('Location: upload.php');
	}
	
	if (isset ($_FILES["file"]))
	{
		$tmp = $_FILES["file"]["tmp_name"] ;
		$name = $_FILES["file"]["name"] ;

		copy ( $tmp, $where_to_copy_files . $name );
		echo "<p>Succesfully uploaded file <i>$name</i></p>";
	}

	if (isset($_SESSION["logged"]))
		echo upload_form();
	else 
		echo login_form();

?>
