<?php
include('functions/functions_general.php');
include('config.php');
// BEGIN ACTIONS
if ($_GET['action'] == 'logout') {
$_SESSION[$program_prefix . 'admin_username'] = '';
$_SESSION[$program_prefix . 'admin_password'] = '';
$_SESSION[$program_prefix . 'admin_id'] = '';
$_SESSION[$program_prefix . 'admin_level'] = '';
$result_div .= getResultDiv('You have been logged out.','success');
}
if ($_POST['action'] == 'admin_login') {
$i = 0;
if (!$_POST['administrators_username']) {
$error[$i] = "Please enter your username.";
$i++;
}
if (!$_POST['administrators_pass']) {
$error[$i] = "Please enter a password.";
$i++;
}
if ($i == 0) {
$sql = '
SELECT *
FROM ' . $program_prefix . 'administrators
WHERE administrators_username = "' . $_POST['administrators_username'] . '" and
administrators_pass = PASSWORD("' . $_POST['administrators_pass'] . '")';
$user_result = mysql_query($sql);
echo mysql_error();
if (mysql_num_rows($user_result) < 1) {
$error[$i] = "That username and password don't match, please try again.";
$i++;
} else {
$admin = mysql_fetch_array($user_result);
$_SESSION[$program_prefix . 'admin_username'] = $admin['administrators_username'];
$_SESSION[$program_prefix . 'admin_password'] = $admin['administrators_pass'];
$_SESSION[$program_prefix . 'admin_id'] = $admin['administrators_id'];
$_SESSION[$program_prefix . 'admin_level'] = $admin['administrators_level'];
header("Location:admin-home.php");
}
}
$result_div .= getResultDiv($error);
}
?>
<head>
<link href="styles/admin.css" rel="stylesheet" type="text/css"></link>
<title>Admin Log In</title>
</head>
<body>
<div class="main">
<h1>Admin Log In</h1>
<?php echo $result_div; ?>
<form action="admin-login.php" method="post">
<input name="action" type="hidden" value="admin_login" />
<table>
<tr>
<td>Username</td>
<td><input type="text" name="administrators_username" /></td>
</tr>
<tr>
<td>Password</td>
<td><input type="password" name="administrators_pass" /></td>
</tr>
</table>
<input type="submit" value="Log In" />
</form>
</div>
</body>