Hệ thống quản lý trường học bằng PHP / MySQLi

1 <?php
2 include(
'connect.php');
3 ?>
4 <?php

5 //Start session

6 session_start();
7
8     
//Function to sanitize values received from the form. Prevents SQL injection
9 function clean($str) {
10         $str = @trim($str);
11         
if(get_magic_quotes_gpc()) {
12             $str = stripslashes($str);
13         }
14         
return mysqli_real_escape_string($str);
15     }
16     
17         
//Sanitize the POST values
18     $username = $_POST[
'username'];
19     $password = $_POST[
'password'];
20     $fname = ($_POST[
'fname']);
21     $lname = ($_POST[
'lname']);
22     $role = ($_POST[
'role']);
23     
24         
//Create query
25     $qry=
"SELECT * FROM admin WHERE username='$username' AND password='$password'";
26     $result=mysqli_query($db,$qry);
27     
28     

29 if
($result)
30  {
31         
if(mysqli_num_rows($result) > 0 ) {
32             
//Login Successful
33             session_regenerate_id();
34             $member = mysqli_fetch_assoc($result);
35             $_SESSION[
'username'] = $member['username'];
36             $_SESSION[
'password'] = $member['password'];
37             $_SESSION[
'fname'] = $member['fname'];
38             $_SESSION[
'lname'] = $member['lname'];
39             $_SESSION[
'role'] = $member['role'];
40             
41             session_write_close();
42             header(
"location: homepage.php?");
43             exit();
44             }
45         
46         
else
47          {
48             
//Login failed
49             header(
"location: login_error.php");
50             exit();
51         }
52         }

53 else

54     {
55     die(
"Query failed");
56     }
57     
58
59 ?>


Gõ tìm kiếm nhanh...