%
Option Explicit
'--------------------------------------------------------
'Purpose: Login
'Date: 07 April 2001
'Commenti:
'--------------------------------------------------------
Response.Buffer = True
Dim objConn, strConn, objRs, strsql
Dim submitted, login, password, pag
%>
Login
<%
submitted = Request.Querystring("submitted")
If Submitted then
strConn = Application("dbconn")
login = Request.Form("login")
password = Request.Form("password")
strsql = "Select id, login, password, pagina FROM tblg "
strsql = strsql & "WHERE login ='" & login & "' AND password = '" & password & "'"
Set objConn = Server.CreateObject("ADODB.Connection")
objConn.Open strConn
set objRs = objConn.Execute(strsql)
If objRs.EOF then
'Non è valido, mandalo indietro
response.redirect "login.asp"
Else
pag=objRS.Fields("pagina")
'è valido, fallo entrare
session("login") = True
objRs.close
Set objRs = Nothing
response.redirect pag
end if
else
'mostra la form
%>
Area Riservata
