01.
<?php
02.
03.
session_start();
04.
05.
06.
$errmsg_arr
=
array
();
07.
08.
09.
$errflag
= false;
10.
11.
12.
$link
= mysql_connect(
'localhost'
,
'root'
,
""
);
13.
if
(!
$link
) {
14.
die
(
'Failed to connect to server: '
. mysql_error());
15.
}
16.
17.
18.
$db
= mysql_select_db(
'sales'
,
$link
);
19.
if
(!
$db
) {
20.
die
(
"Unable to select database"
);
21.
}
22.
23.
24.
function
clean(
$str
) {
25.
$str
= @trim(
$str
);
26.
if
(get_magic_quotes_gpc()) {
27.
$str
=
stripslashes
(
$str
);
28.
}
29.
return
mysql_real_escape_string(
$str
);
30.
}
31.
32.
33.
$login
= clean(
$_POST
[
'username'
]);
34.
$password
= clean(
$_POST
[
'password'
]);
35.
36.
37.
if
(
$login
==
''
) {
38.
$errmsg_arr
[] =
'Username missing'
;
39.
$errflag
= true;
40.
}
41.
if
(
$password
==
''
) {
42.
$errmsg_arr
[] =
'Password missing'
;
43.
$errflag
= true;
44.
}
45.
46.
47.
if
(
$errflag
) {
48.
$_SESSION
[
'ERRMSG_ARR'
] =
$errmsg_arr
;
49.
session_write_close();
50.
header(
"location: index.php"
);
51.
exit
();
52.
}
53.
54.
55.
$qry
=
"SELECT * FROM user WHERE username='$login' AND password='$password'"
;
56.
$result
=mysql_query(
$qry
);
57.
58.
59.
if
(
$result
) {
60.
if
(mysql_num_rows(
$result
) > 0) {
61.
62.
session_regenerate_id();
63.
$member
= mysql_fetch_assoc(
$result
);
64.
$_SESSION
[
'SESS_MEMBER_ID'
] =
$member
[
'id'
];
65.
$_SESSION
[
'SESS_FIRST_NAME'
] =
$member
[
'name'
];
66.
$_SESSION
[
'SESS_LAST_NAME'
] =
$member
[
'position'
];
67.
68.
session_write_close();
69.
header(
"location: main/index.php"
);
70.
exit
();
71.
}
else
{
72.
73.
header(
"location: index.php"
);
74.
exit
();
75.
}
76.
}
else
{
77.
die
(
"Query failed"
);
78.
}
79.
?>