<?php
session_start();
unset($_SESSION['user']);
unset($_SESSION['password']);
session_destroy();
header("refresh: 2; url=/index.php");
?>
<html>
<head>
<title>Goodbye</title>
<link rel="stylesheet" type="text/css" href="content/css/logout/logout.css"/>
</head>
<body>
<h3>Goodbye.</h3>
</body>
</html>
<form method="post" action="authorization.php">
<div class="logReg">
<input type="text" class="loginTextField" placeholder="LOGIN" name="login" autocomplete="off">
<input type="password" class="passTextField" placeholder="PASSWORD" name="password" autocomplete="off">
<input type="submit" class="enterButton" value="Enter">
</div>
</form>
<?php
include("dbconnect.php");
$query = mysql_query("SELECT * FROM Users WHERE login='".$_POST['login']."' AND password='".md5($_POST['password'])."'") or die("Invalid query: " . mysql_error());
if(mysql_num_rows($query) > 0)
{
$_SESSION['flag'] = true;
$_SESSION['user'] = $_POST['login'];
$_SESSION['password'] = md5($_POST['password']);
$login = $_SESSION['user'];
$adminLogin = "admin";
if($login == $adminLogin )
{
echo "<HTML><HEAD><META HTTP-EQUIV='Refresh' CONTENT='0; URL=cms.php'></HEAD><body>";
}
else
echo "<HTML><HEAD><META HTTP-EQUIV='Refresh' CONTENT='0; URL=index.php'></HEAD><body>";
}
else
{
echo "<HTML>
<HEAD>
<TITLE>Authorization</TITLE>
<META HTTP-EQUIV='Refresh' CONTENT='2; URL=index.php'>
<link rel='stylesheet' type='text/css' href='content/css/registration/createuser.css'/>
</HEAD>
<BODY>
<h3>An incorrect user name or password. </h3>
</BODY>
</HTML>";
}
?>