2007-04-03 14:10:23 +00:00
|
|
|
<?php
|
|
|
|
|
|
|
|
if($_GET['logout']) {
|
|
|
|
session_start();
|
|
|
|
session_destroy();
|
|
|
|
header('Location: /');
|
|
|
|
setcookie ("username", "", time() - 3600);
|
|
|
|
setcookie ("encrypted", "", time() - 3600);
|
|
|
|
echo("$_COOKIE[username]");
|
|
|
|
|
|
|
|
} else {
|
|
|
|
|
|
|
|
session_start();
|
|
|
|
|
|
|
|
if($_POST['username'] && $_POST['password']){
|
|
|
|
$_SESSION['username']=$_POST['username'];
|
|
|
|
$_SESSION['password']=$_POST['password'];
|
2007-11-21 14:26:24 +00:00
|
|
|
$_SESSION['encrypted'] = md5($_SESSION['password']);
|
2007-04-03 14:10:23 +00:00
|
|
|
} elseif($_COOKIE['username'] && $_COOKIE['encrypted'] && !$_SESSION['authenticated']) {
|
|
|
|
$_SESSION['username']=$_COOKIE['username'];
|
2007-11-21 14:26:24 +00:00
|
|
|
$_SESSION['encrypted']=$_COOKIE['encrypted'];
|
2007-04-03 14:10:23 +00:00
|
|
|
}
|
|
|
|
|
2008-03-09 21:13:27 +00:00
|
|
|
|
2007-11-21 14:26:24 +00:00
|
|
|
$sql = "select username, level, user_id from users where username='" . $_SESSION['username'] . "' and password='" . $_SESSION['encrypted'] . "'";
|
2008-03-09 21:13:27 +00:00
|
|
|
$query = mysql_query($sql);
|
|
|
|
$row = mysql_fetch_row($query);
|
2007-04-03 14:10:23 +00:00
|
|
|
|
|
|
|
if ( $_SESSION['username'] != "" && $row[0] == $_SESSION['username'] ) {
|
|
|
|
$_SESSION['userlevel'] = $row[1];
|
|
|
|
$_SESSION['authenticated'] = true;
|
2007-06-24 14:56:47 +00:00
|
|
|
$_SESSION['user_id'] = $row[2];
|
2007-04-03 14:10:23 +00:00
|
|
|
setcookie("username", $username);
|
|
|
|
setcookie("encrypted", $encrypted);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
?>
|