public function checkLogin($user, $pw) { $db = new DBConnect(); $mysql = $db->connect(); $sql = "SELECT * FROM user WHERE nickname = '" . $user . "' AND pw = '" . sha1($pw) . "'"; $result = $mysql->query($sql); if ($mysql->affected_rows == 1) { $row = $result->fetch_assoc(); $_SESSION['nickname'] = $row['nickname']; $_SESSION['firstname'] = $row['firstname']; $_SESSION['lastname'] = $row['lastname']; $_SESSION['email'] = $row['email']; $_SESSION['loggedin'] = true; $db->close(); return true; } $db->close(); return false; }