% set rs_con=server.createobject("adodb.recordset") sql="select * from sf_user " rs_con.open sql,conn,1,3,1 dd=rs_con.recordcount rs_con.close if request("step")=2 then error = "" if request("username") = "" then error = "用户名错误" if request("password") = "" then error = error & "密码错误" StrSql = "select userid, username, password, pmpopup from sf_user where username = '" & ChkSql(request("username")) & "'" if error<>"" then response.Redirect("index.asp?errs="&error) Set rs2 = Conn.Execute(StrSql) if not (rs2.bof or rs2.eof) then if md5(request("password")) = rs2("password") then response.cookies("sf")("username")= ChkSql(rs2("username")) response.cookies("sf")("password")= md5(request("password")) response.cookies("sf")("userid")= rs2("userid") response.cookies("sf")("pmpop")= rs2("pmpopup") cookietime = ChkSql(request("cookietime")) if IsNumeric(cookietime) then cookietime = clng(cookietime) else cookietime = 0 end if if cookietime = 0 then 'response.cookies("sf").expires = 0 else response.cookies("sf").expires = dateadd("d", cookietime, date()) end if StrSql = "update sf_user set lastvisit = '" & now() & "', lastactivity = '" & now() & "' where username = '" & ChkSql(rs2("username")) & "'" Set rs2 = Conn.Execute(StrSql) response.Redirect("shenqing.asp") response.Redirect("index.asp") else response.Redirect("index.asp?errs=验证失败") end if else response.Redirect("index.asp?errs=验证失败") end if end if %>
|
|
|
|
|
|
|
|