include("config.inc.php");
$memberName = $POST['memberName'];
$memberPass = $POST['memberPass'];
$sql = "SELECT memberName FROM dp_members
WHERE memberName='{$memberName}'";
$result = mysql_query($sql)
or header("Location: ../index2.php?page=error&error=5");
$num = mysql_num_rows($result);
if ($num == 1) // login name was found
{
$sql = "SELECT memberName FROM dp_members
WHERE memberName='{$memberName}'
AND memberPass='{$memberPass}'";
$result2 = mysql_query($sql)
or header("Location: ../index2.php?page=error&error=5");
$num2 = mysql_num_rows($result2);
if ($num2 > 0) // password is correct
{
$auth="yes";
$logname=$memberName;
$today = date("Y-m-d HⓂs");
$sql = "INSERT INTO dp_login (loginName,loginTime)
VALUES ('$logname','$today')";
mysql_query($sql) or header("Location: ../index2.php?page=error&error=5");
header("Location: index2.php?page=submit");
}
else // password is not correct
{
header("Location: ../index2.php?page=error&error=8");
}
}
elseif ($num == 0) // login name not found
{
header("Location: ../index2.php?page=error&error=9");
}
ok, i have a form which posts memberName and memberPass which are picked up in the $POST['memberName'] and $POST['memberPass'] and converted into other variables which are the same name to make it easy. I know for a fact that my username and password is correct but it always says the password is wrong.
for reference,
error5= "Couldn't Execute Query"
error6= "Couldn't Connect to MySQL Server"
error7= "Couldn't Connect to MySQL Database"
error8= "Username Exists But Password Doesnt Match, Try Again"
error9= "Username Doesn't Exist, Try Again"
thanks in advance,
Daf.