Guest User

Untitled

a guest
Nov 23rd, 2017
105
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.82 KB | None | 0 0
  1. <?php
  2.  
  3. // START SESSION
  4. session_start();
  5.  
  6. // GRAB DATABASE DETAILS
  7. require('connect.php');
  8.  
  9. // SET BASIC VARIABLES FROM FORM
  10. $username = $_POST['username'];
  11. $password = $_POST['password'];
  12.  
  13. // PREVENT SQL INJECTION ESCAPE CHARS
  14. $username = mysql_real_escape_string($username);
  15. $password = mysql_real_escape_string($password);
  16.  
  17. // BUILD THE QUERY
  18. $sql = "SELECT * FROM users WHERE username = '$username' AND password = '$password'";
  19. $result = mysql_query($sql) or die ( mysql_error() );
  20.  
  21. $count = 0;
  22.  
  23. while ($line = mysql_fetch_assoc($result)) {
  24. $count++;
  25. }
  26.  
  27. // IF THERES A MATCH, REDIRECT TO DASHBOARD
  28. if ($count == 1) {
  29. $_SESSION['loggedIn'] = "true";
  30. header("Location: /reps/dashboard/");
  31. } else {
  32. $_SESSION['loggedIn'] = "false"; // OTHERWISE TELL THEM THEY'VE FAILED!
  33. echo "FAIL!";
  34. }
  35.  
  36. ?>
Add Comment
Please, Sign In to add comment