1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42
|
<?
require("config_server.php");
if(isset($_POST['edit_login']) && isset($_POST['edit_pass']))
{
extract($_POST);
$sql2="select acces_forum from clients where login='".$_POST['edit_login']."'";
$req2=mysql_query($sql2) or die ('erreur SQL !<br>'.$sql2.'<br>'.mysql_error());
$result2=mysql_num_rows($req2);
if ($result=="NON") {
echo "<script>alert ('acces non permis');</script>";
echo "<script>window.location= 'forum.php';</script>";
}
else
{
$sql = "select pass_md5 from clients where login='".$_POST['edit_login'].
"' AND pass_md5='".$_POST['edit_pass']."'";
$req = mysql_query($sql) or die('Erreur SQL !<br>'.$sql.'<br>'.mysql_error());
$result = mysql_num_rows($req);
if ($result > 0)
{
session_start();
$_SESSION['login'] = $_POST['edit_login'];
echo "<script>window.location= 'forum.php';</script>";
// tapage.php signifie la page où tu veux que l'utilisateur aille
header("Location:forum_index.php");
}
// else redirige vers ta page de login
else {
echo "<script>alert ('erreur de login');</script>";
echo "<script>window.location= 'forum.php';</script>";
}
}
}
?> |