1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25
| <?php
session_start();
// on teste si le visiteur a soumis le formulaire de connexion
if (isset($_POST['login']) AND isset($_POST['pass'])) {
include ('connect_db.php');
$sql = 'SELECT id FROM membre WHERE login="'.mysql_escape_string($_POST['login']).'" AND pass_md5="'.mysql_escape_string(md5($_POST['pass'])).'"';
$req = mysql_query($sql) or die('Erreur SQL !<br />'.$sql.'<br />'.mysql_error());
$nb = mysql_num_rows($req);
if ($nb == 1) {
$data = mysql_fetch_array($req);
$_SESSION['id'] = $data['id'];
$_SESSION['login'] = $_POST['login'];
include ('membres/header_location.php');
exit();
}
elseif ($nb == 0) {
$erreur = '<span class="erreur">Mauvais identifiants</span>';
}
else {
$erreur = 'Problème';
}
}
?> |