require_once("../common.php"); require_once("../users.php"); $mode = "showlogin"; if (isset($_POST['mode'])) $mode = $_POST['mode']; if ($mode == "showlogin") { ?>
} else if ($mode == "dologin") { $username = $_POST['username']; $password = $_POST['password']; if (!isVarGood($username, false) || !isVarGood($password, false)) die("Form variables are invalid and/or incomplete!"); $db = getDBConnection(); $result = mysql_query("SELECT login,pwsalt,pwhash FROM AdminUser", $db); if (!$result) die("Error while reading admin info from database!"); $row = mysql_fetch_row($result); $storedusername = trim($row[ 0 ]); $storedpwsalt = $row[ 1 ]; $storedpwhash = $row[ 2 ]; if (($username == $storedusername) && Users::checkPassword($password, $storedpwsalt, $storedpwhash)) { $_SESSION['adminLoggedIn'] = true; header("Location: $CMS_BASE_PATH/admin/admin_main.html"); } else { $_SESSION['adminLoggedIn'] = false; echo 'Admin login failed.'; } } ?>