Advertisement
Guest User

Untitled

a guest
May 8th, 2017
64
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.34 KB | None | 0 0
  1. protected void btn_login_Click(object sender, EventArgs e)
  2. {
  3. con.Open();
  4.  
  5. string query = "SELECT COUNT(*) FROM users WHERE username=@userName AND password=@password";
  6. string adquery = "SELECT COUNT(*) FROM users WHERE username=@userName AND password=@password AND isadmin='True'";
  7. SqlCommand cmd = new SqlCommand(query, con);
  8. SqlCommand cmd2 = new SqlCommand(adquery, con);
  9. cmd.Parameters.Add(new SqlParameter("@userName", txtUserName.Text));
  10. cmd.Parameters.Add(new SqlParameter("@password", txtPassWord.Text));
  11. cmd2.Parameters.Add(new SqlParameter("@userName", txtUserName.Text));
  12. cmd2.Parameters.Add(new SqlParameter("@password", txtPassWord.Text));
  13.  
  14.  
  15. string output = cmd.ExecuteScalar().ToString();
  16. string outputadmin = cmd2.ExecuteScalar().ToString();
  17.  
  18. if (output == "1" && outputadmin == "0")
  19. {
  20. //Creating a session for the user
  21. Session["user"] = txtUserName.Text;
  22. Response.Redirect("StudentZone.aspx");
  23. }
  24. else if (output == "1" && outputadmin == "1")
  25. {
  26. Session["admin"] = txtUserName.Text;
  27. Response.Redirect("admin.aspx");
  28. }
  29.  
  30. else
  31. {
  32. Response.Write("Login failed.");
  33. }
  34.  
  35. con.Close();
  36. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement