window.location.href = "/leads";'; } if ($_SERVER['REQUEST_METHOD'] == "POST" && isset($_POST['pass']) && isset($_POST['email'])) { try { $password = md5($_POST['pass']); $email = $_POST['email']; $conn = new PDO("mysql:host=$mariaServer;dbname=$mariaDb", $mariaUser, $mariaPass); $conn->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); $stmt = $conn->prepare("SELECT * FROM users WHERE email = :email AND pass = :pass"); $stmt->bindParam(':email', $email); $stmt->bindParam(':pass', $password); $stmt->execute(); $rows = $stmt->fetchAll(PDO::FETCH_ASSOC); // var_dump($rows); $num_rows = $stmt->rowCount(); if ($num_rows == 1) { foreach($rows as $row){ $_SESSION["loggedin"] = true; $_SESSION["log_status"] = 1; $_SESSION["user_type"] = $row['type']; $_SESSION["access"] = $row['access']; $_SESSION["states"] = $row['states']; $_SESSION["name"] = $row['name']; $_SESSION["email"] = $row['email']; echo ''; // echo $_SESSION["loggedin"].$_SESSION["log_status"].$_SESSION["access"].$_SESSION["name"].$_SESSION["email"]; } } else{ $loginErrorMessage = "Credentials did not match"; } // else echo "credentials did not match";+ } catch (PDOException $e) { echo "
Error: " . $e->getMessage() . "
"; } } ?>