-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathauthenticateadmin.php
66 lines (51 loc) · 1.65 KB
/
authenticateadmin.php
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
<?php
if ($_POST["login"] == 1)
{
$servername = "localhost";
$username = "root";
$password = "";
$database = "charliestore";
// create a connection
$con = mysqli_connect($servername, $username, $password, $database);
if(!$con)
{
echo "Unsuccessful";
}
$adminname = $_POST["adminname"];
$loginpassword = $_POST["adminpassword"];
$sql = "SELECT adminname, adminpassword FROM admin";
//WHERE email = '".$email."' AND userpassword = '".$loingpassword."'
$r = mysqli_query($con, $sql);
$count = 0;
while($row = mysqli_fetch_assoc($r))
{
if($adminname == $row["adminname"] && $loginpassword == $row["adminpassword"])
{
$count = $count + 1;
}
}
// $result1 = "SELECT userpassword FROM customers WHERE email = '".$email."'";
// $result2 = "SELECT email FROM customers WHERE userpassword = '".$loginpassword."'";
// mysqli_query($con, $result1 );
// mysqli_query($con, $result2 );
if ( $count > 0 )
{
?>
<form id="proceed" action="adminindex.php" method="POST">
<input type="hidden" name="loginsuccess" value=1>
</form>
<script>
document.getElementById('proceed').submit();
</script>
<?php
}
else
{
echo'The username or password are incorrect!';
}
}
else
{
header("Location: adminlogin.php");
}
?>