Changeset 108
- Timestamp:
- 31/05/05 15:11:33 (4 years ago)
- Files:
-
- admin.lib.php (modified) (3 diffs)
Legend:
- Unmodified
- Added
- Removed
- Modified
- Copied
- Moved
admin.lib.php
r106 r108 106 106 } 107 107 else { 108 $sql = db_query("SELECT id, name from users where enabled = true and username = '".$username."' and password = '".md5($password)."';");108 $sql = db_query("SELECT id, name, password from users where enabled = true and username = '".$username."';"); 109 109 $sqlNum = db_num_rows($sql); 110 110 if ($sqlNum != 1) { … … 114 114 else { 115 115 $sqlRow = db_getrow($sql); 116 $_SESSION['id'] = $sqlRow['id']; 117 $_SESSION['userName'] = $username; 118 $_SESSION['realName'] = $sqlRow['name']; 119 $this->id = $_SESSION['id']; 120 $this->userName = $_SESSION['userName']; 121 $this->realName = $_SESSION['realName']; 116 if ($sqlRow['password']!=crypt($_POST['password'], $sqlRow['password'])) { 117 $this->sessionError=_("Invalid Username or Password"); 118 } 119 else { 120 $_SESSION['id'] = $sqlRow['id']; 121 $_SESSION['userName'] = $username; 122 $_SESSION['realName'] = $sqlRow['name']; 123 $this->id = $_SESSION['id']; 124 $this->userName = $_SESSION['userName']; 125 $this->realName = $_SESSION['realName']; 126 } 122 127 } 123 128 } … … 343 348 if ($_POST['pass1'] != "") { 344 349 if ((isset($_POST['pass1']) && trim($_POST['pass1']) != "" && (int)$_POST['pass1'] == 0) && ($_POST['pass1']==$_POST['pass2'])) { 345 $password = md5($_POST['pass1']);350 $password = crypt($_POST['pass1']); 346 351 $setpass = true; 347 352 } else {
