<?php
declare(strict_types=1);

session_name('JINNTEVA_SESSION');
session_set_cookie_params([
    'lifetime' => 0,
    'path' => '/',
    'secure' => !empty($_SERVER['HTTPS']) && $_SERVER['HTTPS'] !== 'off',
    'httponly' => true,
    'samesite' => 'Lax',
]);
session_start();

$userId = (int)($_SESSION['user_id'] ?? 0);
if ($userId < 1) {
    header('Location: ./login.html?next=admin.php', true, 302);
    exit;
}

$dbPath = dirname(__DIR__) . DIRECTORY_SEPARATOR . 'jinnteva-private' . DIRECTORY_SEPARATOR . 'store.sqlite';
$pdo = new PDO('sqlite:' . $dbPath, null, null, [PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION]);
$statement = $pdo->prepare('SELECT role FROM users WHERE id = ? AND status = "active"');
$statement->execute([$userId]);
if ($statement->fetchColumn() !== 'admin') {
    header('Location: ./account.html', true, 302);
    exit;
}

header('Location: ./admin.html', true, 302);
exit;
