Vote count:
0
I am trying to implement a login in my index page. This would be so authenticated users may have access to otherwise forbidden pages, obviously. My php reads as:
<?php
if($_POST['submit']=='Login')
{
Login form submitted??
$err = array();
Hold errors
if(!$_POST['username'] || !$_POST['password'])
$err[] = 'All the fields must be filled in!';
if(!count($err))
{
$_POST['username'] = mysql_real_escape_string($_POST['username']);
$_POST['password'] = mysql_real_escape_string($_POST['password']);
Data escaping
$row = mysql_fetch_assoc(mysql_query("SELECT id,usr FROM tz_members WHERE usr='{$_POST['username']}' AND pass='".md5($_POST['password'])."'"));
if($row['usr'])
{
If kosher, Login
$_SESSION['usr']=$row['usr'];
$_SESSION['id'] = $row['id'];
Session storing data
setcookie('tzRemember');
}
else $err[]='Wrong username and/or password!';
}
if($err)
$_SESSION['msg']['login-err'] = implode('<br />',$err);
Save errors in session
header("Location: login.php/");
exit;
}
asked 37 secs ago
Aucun commentaire:
Enregistrer un commentaire