-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathadmin.php
81 lines (67 loc) · 1.88 KB
/
admin.php
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
<?php
session_start();
if ($_GET['login'] && $_GET['passwd'] && $_GET['submit'] && $_GET['submit'] === "OK")
{
$con = mysqli_connect("localhost","root","0892","miniboutique");
if ($con)
echo "CONNECTION SUCCESS"."\n";
$name = $_GET['login'];
$mdp = $_GET['passwd'];
if ($res = mysqli_query($con, "SELECT login from users WHERE login = '$name'"))
{
$value = mysqli_fetch_array($res);
echo "New record created successfully";
if (isset($value) && $value[0] == $name)
{
echo "pseudo valide";
if ($res = mysqli_query($con, "SELECT passwd from users WHERE login = '$name'"))
{
$value = mysqli_fetch_array($res);
if (isset($value) && $value[0] == $mdp)
{
$_SESSION['login'] = $_GET['login'];
$_SESSION['passwd'] = $_GET['passwd'];
echo "PSEUDO EXISTE";
}
}
}
}
else
echo "Error: " . "SELECT '$name' from 'users'" . "<br>" . mysqli_error($con);
}
if (isset($_SESSION['login']) && isset($_SESSION['passwd']))
{
if (isset($_SESSION['cart']))
{
$name = $_SESSION['login'];
$generic = "NONAME";
mysqli_query($con, "UPDATE `panier` SET `id_user`='$name' WHERE 'id_user' = '$generic'");
}
header("Location: profile.php");
exit();
}
?>
<!DOCTYPE html>
<html>
<head>
<title>Authentification</title>
<link rel="stylesheet" type="text/css" href="all.css">
</head>
<body>
<?php Include("header.html"); ?>
<?php Include("menu.html"); ?>
<div id="main">
<div>
Se connecter
<form action="login.php" method="get">
Identifiant: <input type="text" name="login" value="" /><br / >
Mot de passe: <input type="password" name="passwd" value="" /><br / >
<input type="submit" name="submit" value="OK" />
</form>
</div>
<?php
if (!isset($_SESSION['login']) && !isset($_SESSION['passwd']) && $_GET['submit'] && $_GET['submit'] === "OK")
echo "Cet utilisateur n'existe pas, merci de vous inscrire\n";
?>
<a href="create.php"><p>Nouveau ?</p></a>
</div>