% Dim nSort nSort = Trim(Request.QueryString("sort")) If nSort="login" Then Dim AdminName,AdminPWD,strErr strErr = "" AdminName = Replace(Trim(Request.Form("AdminName")),"'","''") AdminPWD = Trim(Request.Form("AdminPWD")) sql = "SELECT * FROM WindStep_Config WHERE Admin='"&AdminName&"'" rs.Open sql,conn,1,1 If rs.BOF And rs.EOF Then strErr = "该管理帐号不存在" Else If AdminPWD<>rs("AdminPassword") Then strErr = "密码错误" Else Response.Cookies()("AdminName") = rs("Admin") Response.Cookies()("AdminPWD") = rs("AdminPassword") session("loginok")="yes" End If End If rs.Close Set rs = Nothing If strErr="" Then conn.Execute("UPDATE WindStep_Config SET LastLoginDate='"&Now()&"',LastLoginIP='"&Request.ServerVariables("REMOTE_ADDR")&"'") Call CloseConn() If strErr<>"" Then Response.Redirect("login.asp?err="&strErr) Else Response.Redirect("test.htm") End If ElseIf nSort="logout" Then Response.Cookies()("AdminName") = "" Response.Cookies()("AdminPWD") = "" session("loginok")="" Set rs = Nothing Call CloseConn() Response.Redirect("test.htm") End If Set rs = Nothing Call CloseConn() %>
|
|||||||||||||||||