Posted by Hyshiro Fri 2nd Mar 2007 17:17 - Syntax is PHP - 96 views
Download | New Post | Modify | Hide line numbers
Download | New Post | Modify | Hide line numbers
PHP parser reported no syntax errors in this post!
-
-
/* Program: login.php
-
* Desc: Login program for the Members Only section of the pet store.
-
* It provides two options: (1) login using an existing login name and
-
* (2) enter a new login name. Login names and passwords are stored in mysql
-
*/
-
include("conf.inc");
-
switch (@$_GET['do'])
-
{
-
case "login";
-
-
$sql = "SELECT loginName FROM Member
-
WHERE loginName='$_POST[fusername]'";
-
if ($num == 1) // login name was found
-
{
-
$sql = "SELECT loginName FROM Member
-
WHERE loginName='$_POST[fusername]'
-
AND password=md5('$_POST[fpassword]')";
-
if ($num2 > 0) // password is correct
-
{
-
$_SESSION['auth']="yes";
-
$logname=$_POST['fusername'];
-
$_SESSION['logname'] = $logname;
-
$sql = "INSERT INTO Login (loginName,loginTime)
-
VALUES ('$logname','$today')";
-
}
-
else // password is not correct
-
{
-
$message="The Login Name, '$_POST[fusername]'
-
exists, but you have not entered the correct password, Please try
-
again.
"; -
include("login_form.inc");
-
}
-
}
-
elseif ($num == 0) // login name not found
-
{
-
$message = "The Login Name you entered does not exist!
-
Please try again.
"; -
include("login_form.inc");
-
}
-
break;
-
-
case "new";
-
foreach($_POST as $field => $value)
-
{
-
if ($field != "fax")
-
{
-
if ($value == "")
-
{
-
$message_new = "Required information is missing.
-
Please try again.";
-
include("login_form.inc");
-
}
-
}
-
{
-
{
-
$message_new = "$field is not a valid name.
-
Please try again.";
-
include('login_form.inc');
-
}
-
}
-
} // end foreach
-
{
-
$message_new = "$email is not a valid email address.
-
Please try again.";
-
include("login_form.inc");
-
}
-
/* check to see if login name already exists */
-
$sql = "SELECT loginName FROM Member
-
WHERE loginName='$newname'";
-
if ($num > 0)
-
{
-
$message_new = "$newname already used.
-
Select another Member ID.";
-
include("login_form.inc");
-
}
-
else
-
{
-
$sql = "INSERT INTO Member (loginName,createDate,password,firstName,lastName,
-
street,city,state,zip,phone,fax,email) VALUES
-
('$newname','$today',md5('$newpass'),
-
'$firstName','$lastName','$street','$city',
-
'$state','$zip','$phone','$fax','$email')";
-
$_SESSION['auth']="yes";
-
$_SESSION['logname'] = $newname;
-
-
/* send email to new member */
-
$emess = "A new Member Account has been setup. ";
-
$emess = "Your new Member ID and password are: ";
-
$emess = "\n\n\t$newname\n\t$newpass\n\n";
-
$emess = "We appreciate your interest BCSO";
-
$emess = " at www.bcso.co.uk! \n\n";
-
$emess = "If you have any questions or problems,";
-
$emess = " email ";
-
$ehead="From: ";
-
$subj = "Your new Member Account from BCSO";
-
}
-
break;
-
-
default;
-
include("login_form.inc");
-
}
-
?>
-
-
-
-
-
PermaLink to this entry https://pastebin.co.uk/11303
Posted by Hyshiro Fri 2nd Mar 2007 17:17 - Syntax is PHP - 96 views
Download | New Post | Modify | Hide line numbers
Download | New Post | Modify | Hide line numbers
Comments: 0