<?php
require 'config.php';
if ($_POST['entered_user'] == null || $_POST['entered_pass'] == null)
echo '<META http-equiv="refresh" content="0;URL=index.php?page=login&message=0">';
else
{
$sql = "SELECT login, access_level from accounts where login='" . htmlentities($_POST['entered_user']) .
"' and password='" . base64_encode(pack('H*', sha1(utf8_encode($_POST['entered_pass'])))) .
"'";
//$result = $db->query($sql);
$result = $db->fetch_all_array($sql);
if (count($result) != 1)
{
echo '<META http-equiv="refresh" content="0;URL=index.php?page=login&message=1">';
} else
{
$admin = $result[0];
$admin_Id = $admin['login'];
unset($_SESSION['admin']);
$_SESSION['admin'] = $_POST['entered_user'];
if (!isset($_GET['url']))
echo '<META http-equiv="refresh" content="0;index.php">';
else
echo '<META http-equiv="refresh" content="0;' . $_GET['url'] . '">';
}
}
?>