1 <?php
2 session_start();
3 include_once
"db.php";
4
5 $tbl_name=
"stock_user"; // Table name
6
7
8 // username and password sent
from form
9 $myusername=$_POST[
'myusername'];
10 $mypassword=$_POST[
'mypassword'];
11
12 // To protect MySQL injection (more detail about MySQL injection)

13 $myusername = stripslashes($myusername);
14 $mypassword = stripslashes($mypassword);
15 $myusername = mysql_real_escape_string($myusername);
16 $mypassword = mysql_real_escape_string($mypassword);
17
18 $sql=
"SELECT * FROM $tbl_name WHERE username='$myusername' and password='$mypassword'" ;
19 $result=mysql_query($sql);

20
21 // Mysql_num_row
is counting table row
22 $count=mysql_num_rows($result);

23 // If result matched $myusername and $mypassword, table row must be
1 row
24
25 if
($count==1){
26 // Register $myusername, $mypassword and redirect to file
"login_success.php"
27 $row = mysql_fetch_row($result);
28
29 $_SESSION[
'id']=$row[0];
30 $_SESSION[
'username']=$row[1];
31 $_SESSION[
'usertype']=$row[3];
32
33 if
($row[3]=="admin")
34 header(
"location:admin.php");
35 else
if($row[3]=="user")
36 header(
"location:user.php");
37 else

38 echo
"error in validate user";
39
40 }

41 else
{
42 header(
"location:index.php?msg=Wrong%20Username%20or%20Password");
43 }
44 ?>


Gõ tìm kiếm nhanh...