public function loginAction($params) { $db = new connection(); $user_name = $params['user_name']; $tableName = $this->table_name; $password = $db->encodeData($params['password']); $rawQry = "SELECT * FROM `system_user` WHERE 1 and `flag`=0 and `user_name`='{$user_name}' and `password`='{$password}'"; $res = $db->rawQry($rawQry); if ($res == true) { $sys_user = new SystemUserConrtoller(); $user_data = $sys_user->selectAction($where = " `flag`=0 and `user_name`='{$user_name}' and `password`='{$password}'"); $_SESSION['sys_user_id'] = $user_data[0]['sys_user_id']; $_SESSION['sys_user_name'] = $user_data[0]['sys_name']; $_SESSION['sys_role_id'] = $user_data[0]['sys_role_id']; header("Location:index.php"); } else { $msg = "Invalid Username and Password!"; return $msg; } }