<?php
session_start();
include('includes/db.php');

if ($_SERVER['REQUEST_METHOD'] === 'POST') {
    $password = mysqli_real_escape_string($conn, $_POST['password']);
    
    // Get stored password from shop_settings
    $sql = "SELECT setting_value FROM shop_settings WHERE setting_key = 'admin_password'";
    $result = mysqli_query($conn, $sql);
    
    if ($result && mysqli_num_rows($result) > 0) {
        $stored_password = mysqli_fetch_assoc($result)['setting_value'];
        
        // Check password (plain text comparison)
        if ($password === $stored_password) {
            $_SESSION['admin_logged_in'] = true;
            $_SESSION['last_activity'] = time();
            
            // Redirect to intended page or dashboard
            $redirect = $_SESSION['redirect_after_unlock'] ?? 'index.php';
            unset($_SESSION['redirect_after_unlock']);
            header('Location: ' . $redirect);
            exit;
        }
    }
    
    // Invalid password
    header('Location: lockscreen.php?error=1');
    exit;
}

header('Location: lockscreen.php');
exit;
?>