Advertisement
Guest User

Untitled

a guest
Jun 21st, 2018
103
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.85 KB | None | 0 0
  1. <?php
  2. include("config.php");
  3. session_start();
  4.  
  5. $error = "";
  6. if($_SERVER["REQUEST_METHOD"] == "POST"){
  7. // SEND BY FORM
  8.  
  9. // protect from sqli
  10. // $username = mysqli_real_escape_string($db,$_POST['username']);
  11. $username = $_POST['username'];
  12. $password = $_POST['password'];
  13.  
  14. $sql = "SELECT id FROM users WHERE username = '$username' and password = '$password'";
  15. $result = mysqli_query($db, $sql);
  16. $row = mysqli_fetch_array($result, MYSQLI_ASSOC);
  17. $active = $row['id'];
  18.  
  19. $count = mysqli_num_rows($result);
  20. // sprawdzamy czy zostal zwrocony rezultat: if count ==1 protect sqli boolean
  21. if($count != 0){
  22. $_SESSION['login_user'] = $username;
  23.  
  24. header("location: welcome.php");
  25. } else {
  26. $error = "Incorrect input: pass or login dont match!";
  27. }
  28. }
  29. ?>
  30.  
  31. <html>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement