Conn.php
<?php
include('xxx.inc.php');
include('xxx.php');
$DB = NewADOConnection('mysql');
$host = "localhost" ;
$username = "xxxx" ;
$password = "xxx" ;
$db = "xxx" ;
$DB->Connect($host, $username, $password, $db);# M'soft style data retrieval with binds
$DB->Execute("SET NAMES UTF8");
?>
checklogin.php
<?php
session_start();
session_save_path("./session/");
if($_REQUEST[code]==""){
echo"กรุณาป้อนโค้ด";
echo"<br><br><input type='button' value='back to edit' onclick='history.back();'></center>";
exit();
}
include "include/Conn.php";
mysql_select_db("$db");
$strSQL = "SELECT * FROM member WHERE username = '".trim($_POST['txtusername'])."' and password = '".trim($_POST['txtpassword'])."'";
$objQuery = mysql_query($strSQL);
$objResult = mysql_fetch_array($objQuery);
if(!$objResult)
{
echo"<script language="javascript"> alert('กรุณากรอก username และ password'); </script>";
echo"<meta http-equiv='refresh' content='2;url=login.php'>";
}
else
{
$_SESSION["username"] = $objResult["username"];
$_SESSION["status"] = $objResult["status"];
session_write_close();
if($objResult["status"] == "ADMIN")
{
header("location:admin_page.php");// ADMIN
exit();
}
else
{
header("location:user_page.php");// user
exit();
}
}
$name=$_SESSION['username'];
mysql_close();
?>
[/code]