function login_post($username, $password, $referrer) { global $auth; if ($username == $auth['username'] && md5($password) == $auth['password']) { jabSetUser($username, $auth['rights']); jabRedirect(strlen($referrer) > 0 ? $referrer : "/"); } else { // No $model['username'] = $username; $model['password'] = $password; $model['referrer'] = $referrer; $model['login_failed'] = true; return jabRenderView("view_login.php", $model); } }
function login_post($username, $password, $referrer) { global $auth; // Lookup DB $stmt = $auth['pdo']->prepare("SELECT * FROM {$auth['tablePrefix']}Users WHERE username=:username and password=:password and enabled=1 and activated=1"); $stmt->bindValue(":username", $username); $stmt->bindValue(":password", md5($password)); $stmt->execute(); $row = $stmt->fetch(); // Found? if ($row !== false) { // Yes jabSetUser($row['username'], $row['rights']); jabRedirect(strlen($referrer) > 0 ? $referrer : "/"); } else { // No $model['username'] = $username; $model['password'] = $password; $model['referrer'] = $referrer; $model['login_failed'] = true; return jabRenderView("view_login.php", $model); } }