I us e the below code as an include on every page where the user needs to login. I left out all unneccesary code, so I hope it makes it easier to read.
Code:
<?php // ac.php
session_start();
$uid = isset($_POST['uid']) ? $_POST['uid'] : $_SESSION['uid'];
$pwd = isset($_POST['pwd']) ? $_POST['pwd'] : $_SESSION['pwd'];
if(!isset($uid)) {
?>
Form...
</body>
</html>
<?php
exit;
}
$_SESSION['uid'] = $uid;
$_SESSION['pwd'] = $pwd;
dbConnect('...');
$sql = "SELECT klant_id, username, wachtwoord FROM klanten WHERE
username = '$uid' AND wachtwoord = '$pwd'";
$result = mysql_query($sql);
if (mysql_num_rows($result) == 0) {
unset($_SESSION['uid']);
unset($_SESSION['pwd']);
?>
Unsuccessful login
</body>
</html>
<?php exit; }
$uid = mysql_result($result,0,'username');
$pwd = mysql_result($result,0,'wachtwoord');
?>
Bookmarks