Hi!
I'm doing a small website with some mysql and php, and have difficulties with doing a login site. I have the form sending the username and password, and this site should check them.
Here's the code:
<?php
session_start();
if(!($connection = mysql_connect("host","user","pass")))
die("Can't connect to database.");
if(!(mysql_select_db("db", $connection)))
die("ERROR ".mysql_errno($connection)."-". mysql_error($connection));
if(isset($_POST["username"]) AND isset($_POST["password"])) {
$uname = $_POST["username"];
$pword = $_POST["password"];
$loginquery = "SELECT * FROM Users WHERE Username = '{$uname}' AND Password = '{$pword}' ORDER BY UserID";
if(!$loginresult = mysql_query($loginquery, $connection))
$error = "No connection.";
if (mysql_num_rows($loginresult) != 1){
$error .= "Username / password error!";
}
else {
$datas = mysql_fetch_assoc($loginresult);
$uid2 = $datas["UserID"];
$uname2 = $datas["Username"];
$pword2 = $datas["Userpassword"];
$artist2 = $datas["Artist"];
$moderator2 = $datas["Moderator"];
$_SESSION["userid"] = $uid2;
$_SESSION["username"] = $uname2;
$_SESSION["password"] = $pword2;
$_SESSION["artist"] = $artist2;
$_SESSION["moderator"] = $moderator2;
}
}
?>
This php page is included in every page on the site. Some variables may be named badly, ignore them. Just help me, please?