I'm fairly new to sessions, but have already encountered a problem. The login system doesn't work and I'm not sure what's wrong so I've pasted both pages below:
PAGE 1 <login.php>
<?
if ($action=="login") {
session_start();
mysql_connect ("localhost");
mysql_select_db ("user") or die("Unable to select database");
$query="SELECT fname, lname, username FROM user WHERE username='$username' AND password='$password'";
$result = mysql_query ($query) or die(mysql_error());
}
?>
<head>
<title>Untitled Document</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<?
if (IsSet($verified_user)) {
echo "Welcome, $fname";
} else {
?>
<form name="login" method="post" action="verify_user.php">
<table border="0" cellspacing="2" cellpadding="2">
<tr>
<td>Username:</td>
<td>
<input type="text" name="username" maxlength="20" size="20">
</td>
</tr>
<tr>
<td>Password:</td>
<td>
<input type="password" name="password" maxlength="10" size="10">
</td>
</tr>
</table>
<input type="submit" name="login" value="Login">
<input type="reset" name="reset" value="Reset">
</form>
<?}?>
</body>
PAGE 2 <verify_user.php>
<?
session_start();
if (@$username && @$password) {
$result = @("SELECT username FROM user WHERE username='$username' AND password='password'");
if (@mysql_num_rows($result) != 0) {
$verified_user = $username;
session_register("verified_user");
}
}
Header("Location: login.php");
?>
Please tell me what I've done wrong!
Thanks in advance...