<?php
if($_SESSION['UserID']!='')
{
echo '<META HTTP-EQUIV="Refresh" Content="0; URL=main.php">';
}
?>
<?php
$UserName = $_POST["txtUser"];
$userCheck = 0;
if ($UserName != null)
{
$Password = $_POST["txtPassWord"];
$db = new LoginDBManager();
$SQL = "SELECT
`user`.id,
`user`.username,
`user`.email,
`user`.`password`
FROM
user` WHERE username='$UserName' AND password='".md5($Password)."';";
$SQL ="SELECT UserID FROM users where UserName='". $UserName."' and Password='". md5($Password) ."';";
echo $SQL;
$result = $db->RunQuery($SQL);
$validUser = false;
$db = NULL;
if(mysql_num_rows($result)>0)
{
while($row = mysql_fetch_array($result))
{
$_SESSION["UserID"] = $row["id"];
$_SESSION["UserName"] = $row["username"];
$_SESSION["Password"] = $row["password"];
}
echo '<META HTTP-EQUIV="Refresh" Content="0; URL=main.php">';
}
else
//$userCheck= "User Name / Password Error";
echo "<script>alert('User Name / Password Error')</script>";
}?>
No comments:
Post a Comment