<?php
$root_path = realpath(dirname(__FILE__).'/../../') . '/';
include("$root_path/upp/inc/class_template.php");
include("$root_path/upp/inc/config.php");
include("$root_path/upp/inc/funktionen.php");
require_once("$root_path/upp/errorHandling/mainErrorHandling.php");
$action = $_POST["action"];
$loggedin = false;
switch($action)
{
case "login":
$passwort = $_POST["passwort"];
$username = $_POST["username"];
$passwort = md5($passwort);
$
SQL = new mysqli(DB_HOST, DB_USER, DB_PW, DB_NAME);
$
query = $
SQL->prepare("SELECT password, aktiv FROM upp_users WHERE username = ?");
$
query->bind_param("s", $username);
$
query->execute();
$
query->bind_result($password, $aktiv);
$
query->fetch();
if($passwort == $password)
{
if($aktiv == 1) $loggedin = true;
}
break;
}
?>