Guest User

Untitled

a guest
Feb 19th, 2018
100
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 1.13 KB | None | 0 0
  1. <?php
  2. session_start();
  3. if (!isset($_SESSION["manager"])) {
  4.     header("location: admin_login.php");
  5.     exit();
  6. }
  7. // Be sure to check that this manager SESSION value is in fact in the database
  8. $managerID = preg_replace('#[^0-9]#i', '', $_SESSION["id"]); // filter everything but numbers and letters
  9. $manager = preg_replace('#[^A-Za-z0-9]#i', '', $_SESSION["manager"]); // filter everything but numbers and letters
  10. $password = preg_replace('#[^A-Za-z0-9]#i', '', $_SESSION["password"]); // filter everything but numbers and letters
  11. // Run mySQL query to be sure that this person is an admin and that their password session var equals the database information
  12. // Connect to the MySQL database  
  13. include "../include/scripts/mysql_connect.php";
  14. $sql = mysql_query("SELECT * FROM admin WHERE id='$managerID' AND username='$manager' AND password='$password' LIMIT 1"); // query the person
  15. // ------- MAKE SURE PERSON EXISTS IN DATABASE ---------
  16. $existCount = mysql_num_rows($sql); // count the row nums
  17. if ($existCount == 0) { // evaluate the count
  18.      echo "Your login session data is not on record in the database.";
  19.      exit();
  20. }
  21. ?>
Add Comment
Please, Sign In to add comment