equal
deleted
inserted
replaced
45 $_SESSION["lastmod"] = time(); |
45 $_SESSION["lastmod"] = time(); |
46 |
46 |
47 if(isset($_SESSION["userlogin"]) && isset($_SESSION["userpwd"])) |
47 if(isset($_SESSION["userlogin"]) && isset($_SESSION["userpwd"])) |
48 { |
48 { |
49 //Username and password are set, lets try to authenticate. |
49 //Username and password are set, lets try to authenticate. |
50 $result = $db->query("SELECT id, fullname FROM users WHERE username=". $db->quote($_SESSION["userlogin"]) ." AND password=". $db->quote(md5($_SESSION["userpwd"])) ." AND active=1"); |
50 $result = $db->query("SELECT id, fullname FROM users WHERE username=". $db->quote($_SESSION["userlogin"], 'text') ." AND password=". $db->quote(md5($_SESSION["userpwd"]), 'text') ." AND active=1"); |
51 if($result->numRows() == 1) |
51 if($result->numRows() == 1) |
52 { |
52 { |
53 $rowObj = $result->fetchRow(); |
53 $rowObj = $result->fetchRow(); |
54 $_SESSION["userid"] = $rowObj["id"]; |
54 $_SESSION["userid"] = $rowObj["id"]; |
55 $_SESSION["name"] = $rowObj["fullname"]; |
55 $_SESSION["name"] = $rowObj["fullname"]; |