//Coded on 11th Feb 2008
include("includes/header.php");
include("myclass.php");
$myclass=new myclass();
//session_start();
if ($_POST['LOGIN'])
{
$myusername=trim($_POST['Email']);
$mypassword=trim($_POST['Password']);
if (!eregi("^[_a-z0-9-]+(\.[_a-z0-9-]+)*@[a-z0-9-]+(\.[a-z0-9-]+)*(\.[a-z]{2,3})$", $myusername)){
$message_alert= "Not a vallid email address !! Please try again";
} else {
$sql="SELECT * FROM customers WHERE customers_email_address='$myusername' ";
$result=$myclass->querydb($sql);
$count=$myclass->getNumberRows($result);
// mysql_close();
if($count==1)
{
$readpassword=mysql_fetch_object($result);
$dbpassword=$readpassword->customers_password;
$customerid=$readpassword->customers_id;
$typeuser=$readpassword->group_code;
$user_address_id=$readpassword->customers_default_address_id;
//Read customer country id
$sql_country="SELECT entry_country_id FROM address_book WHERE address_book_id=".$user_address_id." AND customers_id=".$customerid;
$result_country=$myclass->querydb($sql_country);
$readcountry=mysql_fetch_object($result_country);
$user_country_id=$readcountry->entry_country_id;
//end of customer country id
if (tep_validate_password($mypassword, $dbpassword))
{
session_register("myusername");
session_register("mypassword");
//session_register("dbcustomerid");
$_SESSION['dbcustomerid']=$customerid;
$_SESSION['usertype']=$typeuser;
$_SESSION['user_country']=$user_country_id;
//$dbcustomerid=$customerid;
//header("Location:main.php?cmd=accountdetails");
//exit("");
$message_alert= "Welcome to Computer Asset Manager";
}
else
{
//check master password
$sql_master_password="SELECT configuration_value FROM configuration WHERE configuration_key='MASTER_PASS' ";
$result_master_password=$myclass->querydb($sql_master_password);
$read_master_password=mysql_fetch_object($result_master_password);
$dbpassword=$read_master_password->configuration_value;
if (md5($mypassword) == $dbpassword)
{
$_SESSION['dbcustomerid']=$customerid;
$_SESSION['usertype']=$typeuser;
$_SESSION['user_country']=222;
$message_alert= "Welcome to Computer Asset Manager";
}else{
//========XXXXXXXXXXXXXX------XXXXXXXXXXXXX=======>>>
$message_alert= "Wrong Password !! Please try again";
}
}
}
else
{
$message_alert= "Wrong Username or Password !! Please try again";
}
}
}
//=======================================================
function tep_validate_password($plain, $encrypted) {
if (($plain<>"") && ($encrypted<>"")) {
$stack = explode(':', $encrypted);
if (sizeof($stack) != 2) return false;
if (md5($stack[1] . $plain) == $stack[0]) {
return true;
}
}
return false;
}
if ($_SESSION['dbcustomerid'] == "" )
{
?>
| |
|
}else{
?>
| include ("includes/leftmenu.php") ; ?> |
$cmd=$_GET['cmd'];
if ($cmd==""){
$welcomemessage= "Computer Asset Manager";
}
?>
| |
if ($cmd=="site")
{
include ("site.php") ;
}
if ($cmd=="editsite")
{
include ("edit_site.php") ;
}
if ($cmd=="create_account")
{
include ("create_account.php") ;
}
if ($cmd=="accountdetails")
{
include ("account-details.php") ;
}
if ($cmd=="contract")
{
include ("contract.php") ;
}
if ($cmd=="editcontract")
{
include ("edit_contract.php") ;
}
if ($cmd=="contractdetails")
{
include ("contract-details.php") ;
}
if ($cmd=="equipmentdetails")
{
include ("equipment-details.php") ;
}
if ($cmd=="equipment")
{
include ("equipment.php") ;
}
if ($cmd=="editequipment")
{
include ("edit_equipment.php") ;
}
if ($cmd=="sitedetails")
{
include ("site-details.php") ;
}
if ($cmd=="site-equipment-contract-details")
{
include ("site-equipment-contract-details.php") ;
}
if ($cmd=="site-equipment")
{
include ("site-equipment.php") ;
}
if ($cmd=="equipment_track")
{
include ("equipment_track.php") ;
}
if ($cmd=="reset_password")
{
include ("reset_password.php") ;
}
if ($cmd=="shopping_cart")
{
include ("shopping_cart.php") ;
}
if ($cmd=="order_confirmation")
{
include ("order_confirmation.php") ;
}
if ($cmd=="download")
{
include ("download_creation.php") ;
}
if ($cmd=="customer_download")
{
include ("customer_download_area.php") ;
}
if ($cmd=="payment")
{
include ("payment.php") ;
}
if ($cmd=="order_success")
{
include ("order_success.php") ;
}
if ($cmd=="reminder_email")
{
include ("reminder_email.php") ;
}
if ($cmd=="makeorder")
{
include ("makeorder.php") ;
}
if ($cmd=="customer_upload")
{
include ("customer_upload_area.php") ;
}
if ($cmd=="payment_confirmation")
{
include ("payment_confirmation.php") ;
}
if ($cmd=="contract_to_renew")
{
include ("contract_to_renew.php") ;
}
if ($cmd=="customer_upload_file")
{
include ("customer_upload_file.php") ;
}
if ($cmd==""){
include ("welcome.php") ;
}
?>
|
|
|
| |
| |
|
|
}
include("includes/footer.php");?>