
Untitled
By: a guest on
Jun 15th, 2012 | syntax:
PHP | size: 0.95 KB | hits: 22 | expires: Never
<?php
session_start();
if (isset($_POST['username']) && isset($_POST['password'])) {
$preparedQuery = $oConn->stmt_init();
if($preparedQuery->prepare("SELECT username, password, firm_users.fk_rankID FROM firm_users INNER JOIN firm_rank ON firm_users.fk_rankID = firm_rank.rankID WHERE username=? AND password=?")){
$preparedQuery->bind_param("ss", $user, $pass);
$user = $_POST['username'];
$pass = $_POST['password'];
$preparedQuery->execute();
$preparedQuery->bind_result($username, $password, $fkRankID);
if($preparedQuery->fetch()){
$rank = $fkRankID;
$name = $username;
}
$preparedQuery->close();
}
if($rank == 1){
$_SESSION['admin'] = $name;
header('Location: ../index.php');
}
elseif($rank == 0) {
$_SESSION['user'] = $name;
header('Location: ../index.php');
}
} else{
$errorMessage .= "Insert your username and password.";
}
echo $errormessage;
?>