login.php 3.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113
  1. <?php
  2. include "conn.php";
  3. $act = $_GET['act'] ?? '';
  4. if ($act == "logout") {
  5. // Clear all session variables
  6. addSession('loginid', '');
  7. addSession('loginuser', '');
  8. addSession('loginname', '');
  9. addSession('loginpower', '');
  10. session_destroy();
  11. }
  12. if ($act == "login") {
  13. checkPost();
  14. $loginuser = textEncode($_POST['loginuser'] ?? '');
  15. $loginpwd = textEncode($_POST['loginpwd'] ?? '');
  16. $logincode = $_POST['logincode'] ?? '';
  17. if ($loginuser == "") {
  18. echo "1";
  19. exit;
  20. }
  21. if ($loginpwd == "") {
  22. echo "2";
  23. exit;
  24. }
  25. if ($logincode != $_SESSION['zengscode']) {
  26. echo "3";
  27. exit;
  28. }
  29. $sql = "SELECT id, loginuser, loginpwd, loginstate, loginname, loginlasttime, loginlastip,
  30. loginthistime, loginthisip, loginpower, logincount
  31. FROM login WHERE loginuser = '" . mysqli_real_escape_string($conn, $loginuser) . "'";
  32. $result = mysqli_query($conn, $sql);
  33. if (mysqli_num_rows($result) == 0) {
  34. echo "4";
  35. exit;
  36. }
  37. $row = mysqli_fetch_assoc($result);
  38. if ($row['loginpwd'] != md5($loginpwd)) {
  39. echo "5";
  40. exit;
  41. }
  42. if ($row['loginstate'] < 1) {
  43. echo "6";
  44. exit;
  45. }
  46. // Check power status
  47. $sql = "SELECT COUNT(powerstate) as count, powerstate FROM power WHERE id = '" . mysqli_real_escape_string($conn, $row['loginpower']) . "' GROUP BY powerstate";
  48. $result = mysqli_query($conn, $sql);
  49. $power = mysqli_fetch_assoc($result);
  50. if (!$power || $power['count'] == 0 || $power['powerstate'] == 0) {
  51. echo "6";
  52. exit;
  53. }
  54. $_SESSION['zengscode'] = "";
  55. // Update login information
  56. $sql = "UPDATE login SET
  57. loginlasttime = loginthistime,
  58. loginlastip = loginthisip,
  59. loginthistime = NOW(),
  60. loginthisip = '" . mysqli_real_escape_string($conn, getIp()) . "',
  61. logincount = logincount + 1
  62. WHERE id = '" . mysqli_real_escape_string($conn, $row['id']) . "'";
  63. mysqli_query($conn, $sql);
  64. // Set session variables
  65. addSession('loginid', $row['id']);
  66. addSession('loginuser', $row['loginuser']);
  67. addSession('loginname', $row['loginname']);
  68. addSession('loginpower', $row['loginpower']);
  69. echo "7";
  70. exit;
  71. }
  72. ?>
  73. <!DOCTYPE html>
  74. <html xmlns="http://www.w3.org/1999/xhtml">
  75. <head>
  76. <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
  77. <meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" />
  78. <link href="css/loginlayout.css" type="text/css" rel="stylesheet" />
  79. <title><?php echo $webname; ?> - 网站后台管理</title>
  80. <script language="javascript" src="js/jquery-1.7.2.min.js"></script>
  81. <script type="text/javascript" src="js/loginjs.js"></script>
  82. </head>
  83. <body>
  84. <div id="container">
  85. <form id="loginform" name="loginform" method="post">
  86. <div class="loginuser"><label for="loginuser">用户帐号:</label><input type="text" id="loginuser" name="loginuser" maxlength="50" /></div>
  87. <div class="loginpwd"><label for="loginpwd">用户密码:</label><input type="password" id="loginpwd" name="loginpwd" maxlength="50" /></div>
  88. <div class="logincode"><label for="logincode">验 证 码:</label><input type="text" id="logincode" name="logincode" maxlength="5" /><span id="showlogincode"></span></div>
  89. <div><input type="submit" id="loginbtn" name="loginbtn" value="登陆" /></div>
  90. <div id="formmsg"></div>
  91. </form>
  92. <div id="copyright">Copyright © Mietubl All Rights Reserved</div>
  93. </div>
  94. </body>
  95. </html>