<?php
require('config.php');
session_start();
// If form submitted, insert values into the database.
if (isset($_POST['password'])){
$username = $_POST['username'];
$password = $_POST['password'];
$username = stripslashes($username);
$username = mysql_real_escape_string($username);
$password = stripslashes($password);
$password = mysql_real_escape_string($password);
//Checking is user existing in the database or not
$query = "SELECT * FROM `users` WHERE username='$username' and password='".sha1($password)."'";
$result = mysql_query($query) or die(mysql_error());
$rows = mysql_num_rows($result);
if($rows==1){
$_SESSION['username'] = $username;
header("Location: profile.php"); // Redirect user to index.php
}else{
echo "random text";
}
}else{
}
?>
form action="" method="post" name="login">
<input type="text" name="username" placeholder="Username" required />
<input type="password" name="password" placeholder="Password" required />
<input type="image" src="https://i.imgur.com/uVoJ8Kl.pngg" />
</form>
if($rows==1){
$_SESSION['username'] = $username;
header("Location: profile.php"); // Redirect user to index.php
}else{
echo "random text";
}
}else{
}
|
I don't know about php that much, but this part kind of bugging me:
PHP код:
|
<form action="profile.php" method="post" name="login">
<input type="text" name="username" placeholder="Username" required />
<input type="password" name="password" placeholder="Password" required />
<input type="submit" src="https://i.imgur.com/uVoJ8Kl.png" />
</form>
<?php*
*require('config.php');*
*session_start();*
*//*If*form*submitted,*insert*values*into*the*database.*
*if*(isset($_POST['password'])){*
*$username*=*$_POST['username'];*
*$password*=*$_POST['password'];*
*$username*=*stripslashes($username);*
*$username*=*mysql_real_escape_string($username);*
*$password*=*stripslashes($password);*
*$password*=*mysql_real_escape_string($password);*
*//Checking*is*user*existing*in*the*database*or*not*
*$query*=*"SELECT***FROM*`users`*WHERE*username='$username'*and*password='".sha1($password)."'";*
*$result*=*mysql_query($query)*or*die(mysql_error());*
*$rows*=*mysql_num_rows($result);*
*if($rows==1){*
*$_SESSION['username']*=*$username;*
*header("Location:*profile.php");*//*Redirect*user*to*index.php*
*}else{*
*echo*"random*text";*
*}*
*}else{*
echo 'form*action="login.php"*method="post"*name="login">*
<input*type="text"*name="username"*placeholder="Username"*required*/>*
<input*type="password"*name="password"*placeholder="Password"*required*/>*
<input*type="image"*src="https://i.imgur.com/uVoJ8Kl.pngg"*/>*
</form>**';
*}*
?>