<?php
$properly_filled_in = true;
function validateEmail()
{
if(isset($_POST['email']))
{
if($_POST['email'] == "")
{
$properly_filled_in = false;
echo 'må fylles inn';
}
else if (!preg_match('/^[^0-9][a-zA-Z0-9_]+([.][a-zA-Z0-9_]+)*[@][a-zA-Z0-9_]+([.][a-zA-Z0-9_]+)*[.][a-zA-Z]{2,4}$/', $_POST['email']))
{
$properly_filled_in = false;
echo 'feil format på e-mail';
}
}
else
{
echo '*';
}
}
function validatePassword()
{
if(isset($_POST['password']))
{
if($_POST['password'] == "")
{
$properly_filled_in = false;
echo 'må fylles inn';
}
else if(strlen($_POST['password']) < 8)
{
$properly_filled_in = false;
echo 'passordet er for kort';
}
}
else
{
echo '*';
}
}
?>
<form action="?page=login" method="POST">
<div id="loginField">
<label for="email" class="label">E-mail</label>
<input type="text" name="email" class="justify textbox" />
<p id="emailValid" class="valid"><?php validateEmail(); ?></p>
<label for="password" class="label secondLabel">Passord</label>
<input type="password" name="password" class="justify textbox" />
<p id="passwordValid" class="valid"><?php validatePassword(); ?></p>
<div id="submit">
<a href="?page=registrer" id="registrer">Registrer bruker</a>
<input type="submit" class="button" id="submitButton" value="Logg inn" />
</div>
</div>
</form>
<?php
if($properly_filled_in)
{
$admin = new Admin($_POST);
$sql = 'SELECT PERSON_ID AS person_id FROM ADMIN WHERE PASSWORD = "'.$admin->password.'" AND EMAIL = "'.prepare($admin->email).'";';
$query = mysql_query($sql) or die(mysql_error());
if(mysql_affected_rows() == 1 && $res = mysql_fetch_array($query))
{
$res = mysql_fetch_array($query);
$_SESSION["person_id"] = $res["person_id"];
$success = true;
echo '<p id="feedback">Du er nå logget inn.</p>';
include FRAGMENTS_PATH.'timeout.php';
}
}
?>