码迷,mamicode.com
首页 > 其他好文 > 详细

checkUser----dede

时间:2014-11-28 16:27:17      阅读:504      评论:0      收藏:0      [点我收藏+]

标签:io   ar   sp   on   log   bs   cti   ad   ef   

/**
     *  检验用户是否正确
     *
     * @access    public
     * @param     string    $username  用户名
     * @param     string    $userpwd  密码
     * @return    string
     */
    function checkUser($username, $userpwd)
    {
        global $dsql;

        //只允许用户名和密码用0-9,a-z,A-Z,‘@‘,‘_‘,‘.‘,‘-‘这些字符
        $this->userName = preg_replace("/[^0-9a-zA-Z_@!\.-]/", ‘‘, $username);
        $this->userPwd = preg_replace("/[^0-9a-zA-Z_@!\.-]/", ‘‘, $userpwd);
        $pwd = substr(md5($this->userPwd), 5, 20);
        $dsql->SetQuery("SELECT admin.*,atype.purviews FROM `#@__admin` admin LEFT JOIN `#@__admintype` atype ON atype.rank=admin.usertype WHERE admin.userid LIKE ‘".$this->userName."‘ LIMIT 0,1");
        $dsql->Execute();
        $row = $dsql->GetObject();
        if(!isset($row->pwd))
        {
            return -1;
        }
        else if($pwd!=$row->pwd)
        {
            return -2;
        }
        else
        {
            $loginip = GetIP();
            $this->userID = $row->id;
            $this->userType = $row->usertype;
            $this->userChannel = $row->typeid;
            $this->userName = $row->uname;
            $this->userPurview = $row->purviews;
            $inquery = "UPDATE `#@__admin` SET loginip=‘$loginip‘,logintime=‘".time()."‘ WHERE id=‘".$row->id."‘";
            $dsql->ExecuteNoneQuery($inquery);
            $sql = "UPDATE #@__member SET logintime=".time().", loginip=‘$loginip‘ WHERE mid=".$row->id;
            $dsql->ExecuteNoneQuery($sql);
            return 1;
        }
    }

checkUser----dede

标签:io   ar   sp   on   log   bs   cti   ad   ef   

原文地址:http://my.oschina.net/guomingliang/blog/350037

(0)
(0)
   
举报
评论 一句话评论(0
登录后才能评论!
© 2014 mamicode.com 版权所有  联系我们:gaon5@hotmail.com
迷上了代码!