All user/ pages require authentication against database users.

This commit is contained in:
Elyrith
2013-08-10 01:38:23 -04:00
parent 4dd163139f
commit 18a067a902
5 changed files with 12 additions and 6 deletions

View File

@@ -1,9 +1,6 @@
<?php
if (!$_COOKIE['session'] && ($_POST['do'] !== "authenticate")) {
echo "Please login:";
include "login_form.inc";
break;
} else {
if ( $_COOKIE['session'] ) { // Do nothing
} else if ($_POST['do'] == "authenticate") {
require "dbconnect.php";
$sql = "SELECT id,username FROM users WHERE username='$_POST[username]' and password=PASSWORD('$_POST[password]')";
@@ -13,7 +10,7 @@ if (!$_COOKIE['session'] && ($_POST['do'] !== "authenticate")) {
if (mysql_num_rows($result) === 1) {
unset($_POST['do']);
$_COOKIE['session'] = 1;
$_COOKIE['session'] = '1';
setcookie('session',$_COOKIE['session']);
} else {
unset($_POST['do']);
@@ -22,5 +19,9 @@ if (!$_COOKIE['session'] && ($_POST['do'] !== "authenticate")) {
include("login_form.inc");
break;
}
} else {
echo "Please login:";
include "login_form.inc";
break;
}
?>