|
[x]
Posted via EE Mobile
|
||
Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again. |
||
| Question |
|
[x]
Attachment Details
|
||
|
[x]
The Solution Rating System
|
||
With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.
Your Input Matters If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support. Thank you! |
||
1: 2: 3: 4: 5: 6: 7: 8: 9: 10: 11: 12: 13: 14: 15: 16: 17: 18: 19: 20: 21: 22: 23: 24: 25: 26: 27: 28: 29: 30: 31: 32: 33: 34: 35: 36: 37: 38: 39: 40: 41: 42: 43: 44: 45: 46: 47: 48: 49: 50: 51: 52: 53: 54: 55: 56: 57: 58: 59: 60: 61: 62: 63: 64: 65: 66: 67: 68: 69: 70: 71: 72: 73: |
All files include check_login.php:
<?php
session_start();
if (!isset($_SESSION['user_id'])){
include("login.php");
exit();
}
?>
login.php:
<html>
<head>
</head>
<body>
<form action="login_submit.php" method="POST">
Username: <input type="text" name="username">
Password: <input type="password" name="password">
</form>
</body>
</html>
login_submit.php
<?php
include("includes/db_connect.php");
$username=$_POST['username'];
$password=$_POST['password'];
$qryGetUser="SELECT * FROM user WHERE username='$username' LIMIT 1";
$rsGetUser=mysql_query($qryGetUser) or die(mysql_error());
//USERNAME CORRECT?
if (mysql_num_rows($rsGetUser)==0){
echo "Username or password incorrect.";
exit();
}
$rowUser=mysql_fetch_array($rsGetUser);
//PASSWORD CORRECT?
if ($rowUser['password']!=md5($password)){
echo "Username or password incorrect.";
//LOCK ACCOUNT IF THIS IS THIRD ATTEMPT
if ($rowUser['failed_attempts']>1){
$qryUpdateUser="UPDATE user SET failed_attempts=failed_attempts+1, locked='1' WHERE user_id='".$rowUser['user_id']."'";
}
//ELSE INCREMENT FAILED ATTEMPTS
else{
$qryUpdateUser="UPDATE user SET failed_attempts=failed_attempts+1 WHERE user_id='".$rowUser['user_id']."'";
}
$rsUpdateUser=mysql_query($qryUpdateUser) or die(mysql_error());
exit();
}
//IF ACCOUNT LOCKED
if ($rowUser['locked']=="1"){
$qryUpdateUser="UPDATE user SET failed_attempts=failed_attempts+1 WHERE user_id='".$rowUser['user_id']."'";
$rsUpdateUser=mysql_query($qryUpdateUser) or die(mysql_error());
echo "<b>Error: </b>Your account has been disabled.<br/>Please contact your systems administrator.";
exit();
}
//LOGGED IN
session_start();
$_SESSION['username']=$rowUser['username'];
$_SESSION['user_id']=$rowUser['user_id'];
$_SESSION['login_time']=date(" H:i:s d-m-Y");
header("Location: main.php");
?>
|
Advertisement
| Hall of Fame |