Guest User

Untitled

a guest
Nov 22nd, 2018
149
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.68 KB | None | 0 0
  1. session_start();
  2. include($_SERVER['DOCUMENT_ROOT'].'/crm/connect/db.php');
  3. mysqli_select_db($conn, 'users');
  4.  
  5. if($_SERVER["REQUEST_METHOD"] == "POST") {
  6. $user=mysqli_real_escape_string($conn,$_POST['user']);
  7. $pass=mysqli_real_escape_string($conn,$_POST['pass']);
  8. $hashedpassword = password_hash ($pass, PASSWORD_DEFAULT);
  9. $sql="select * from users where username ='$user'";
  10. $result=mysqli_query($conn,$sql);
  11. $row=mysqli_fetch_array($result, MYSQLI_ASSOC);
  12. $role = $row["admin"];
  13.  
  14. if ($row["active"] == 0 && $pass = $row["password"]){
  15. header('location:initial_login.php');
  16. }
  17. elseif(password_verify($pass, $row["password"])){
  18. $_SESSION['username'] = $user;
  19. $_SESSION['admin'] = $role;
  20. header('location:index.php');
  21. }else{
  22. echo 'incorrect!';
  23. }
  24. }
  25.  
  26. session_start();
  27. include($_SERVER['DOCUMENT_ROOT'].'/crm/connect/db.php');
  28. mysqli_select_db($conn, 'users');
  29. if($_SERVER["REQUEST_METHOD"] == "POST") {
  30. $user=mysqli_real_escape_string($conn,$_POST['user']);
  31. $pass=mysqli_real_escape_string($conn,$_POST['pass']);
  32. $hashedpassword = password_hash ($pass, PASSWORD_DEFAULT);
  33. $sql="select * from users where username ='$user'";
  34. $result=mysqli_query($conn,$sql);
  35. $row=mysqli_fetch_array($result, MYSQLI_ASSOC);
  36. $role = $row["admin"];
  37.  
  38.  
  39. if ($row["active"] == 0 && $pass == $row["password"]){
  40. header('location:initial_login.php');
  41. }else{
  42. echo 'incorrect!';
  43. if(password_verify($pass, $row["password"])){
  44. $_SESSION['username'] = $user;
  45. $_SESSION['admin'] = $role;
  46. header('location:index.php');
  47. }else{
  48. echo 'incorrect!';
  49. }
  50. }
  51. }
Add Comment
Please, Sign In to add comment