Advertisement
Guest User

Untitled

a guest
Apr 21st, 2016
98
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.04 KB | None | 0 0
  1. $user = $_POST['user_name'];
  2. $pass = md5($_POST['user_pass']);
  3.  
  4. require_once("connection_file.php");
  5. $sql = "SELECT * FROM login_table WHERE user_n = :us AND user_p = :password";
  6. $stmt = $conn->prepare($sql);
  7. $stmt->bindValue(':us', $user, PDO::PARAM_STR);
  8. $stmt->bindValue(':password', $pass, PDO::PARAM_STR);
  9. $stmt->execute();
  10. $result = $stmt->fetchAll();
  11. if($result)
  12. {
  13. //echo $msg = "user exist";
  14. if(session_status() == PHP_SESSION_NONE)
  15. {
  16. session_start();
  17. foreach($result as $row)
  18. {
  19. $hash = password_hash($row['user_pass'], PASSWORD_BCRYPT);
  20. if(password_verify($row['user_pass'], $hash))
  21. {
  22. $_SESSION['userid'] = $row['user_id'];
  23. $_SESSION['role'] = $row['user_role'];
  24. header("Location: homepage.php");
  25. }
  26. }
  27. }
  28. }
  29. else
  30. {
  31. $msg = "Wrong credentials";
  32. header("Location: login_page.php");
  33. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement