<%@LANGUAGE="VBSCRIPT" CODEPAGE="65001"%> <% ' *** Validate request to log in to this site. MM_LoginAction = Request.ServerVariables("URL") If Request.QueryString <> "" Then MM_LoginAction = MM_LoginAction + "?" + Server.HTMLEncode(Request.QueryString) MM_valUsername = CStr(Request.Form("userid")) If MM_valUsername <> "" Then Dim MM_fldUserAuthorization Dim MM_fldUserNome Dim MM_fldUserCognome Dim MM_redirectLoginSuccess Dim MM_redirectLoginFailed Dim MM_loginSQL Dim MM_rsUser Dim MM_rsUser_cmd MM_fldUserAuthorization = "tipo_utente" MM_fldUserNome = "nome" MM_fldUserCognome = "cognome" MM_redirectLoginSuccess = "admin_menu.asp" MM_redirectLoginFailed = "admin_login.asp" MM_loginSQL = "SELECT userid, password, nome, cognome" If MM_fldUserAuthorization <> "" Then MM_loginSQL = MM_loginSQL & "," & MM_fldUserAuthorization MM_loginSQL = MM_loginSQL & " FROM utenti WHERE userid = ? AND password = ?" Set MM_rsUser_cmd = Server.CreateObject ("ADODB.Command") MM_rsUser_cmd.ActiveConnection = MM_surfacetreatments_STRING MM_rsUser_cmd.CommandText = MM_loginSQL MM_rsUser_cmd.Parameters.Append MM_rsUser_cmd.CreateParameter("param1", 200, 1, 255, MM_valUsername) ' adVarChar MM_rsUser_cmd.Parameters.Append MM_rsUser_cmd.CreateParameter("param2", 200, 1, 255, Request.Form("password")) ' adVarChar MM_rsUser_cmd.Prepared = true Set MM_rsUser = MM_rsUser_cmd.Execute If Not MM_rsUser.EOF Or Not MM_rsUser.BOF Then ' username and password match - this is a valid user ' Session("MM_Username") = MM_valUsername Session("MM_Username") = CStr(MM_rsUser.Fields.Item(MM_fldUserAuthorization).Value) nome = CStr(MM_rsUser.Fields.Item(MM_fldUserNome).Value) cognome = CStr(MM_rsUser.Fields.Item(MM_fldUserCognome).Value) If (MM_fldUserAuthorization <> "") Then Session("MM_UserAuthorization") = CStr(MM_rsUser.Fields.Item(MM_fldUserAuthorization).Value) nome = CStr(MM_rsUser.Fields.Item(MM_fldUserNome).Value) cognome = CStr(MM_rsUser.Fields.Item(MM_fldUserCognome).Value) Else Session("MM_UserAuthorization") = "" nome = "" cognome = "" End If if CStr(Request.QueryString("accessdenied")) <> "" And false Then MM_redirectLoginSuccess = Request.QueryString("accessdenied") End If MM_rsUser.Close 'Response.Redirect(MM_redirectLoginSuccess & "?nome=" & nome & "&cognome=" & cognome) Response.Cookies ("surfacetreatmentsuser")("references") = nome & "_" & cognome Response.Cookies ("surfacetreatmentsuser").Expires = DATE + 365 Const ForAppending = 8 strLogFileName = "/surfacetreatments/upload/" & Request.Cookies ("surfacetreatmentsuser")("references") & ".txt" dim fs, f set fs = Server.CreateObject("Scripting.FileSystemObject") If Request.Cookies ("surfacetreatmentsuser")("references") <> "" Then set f = fs.OpenTextFile(Server.MapPath(strLogFileName), ForAppending) Else Set f = fs.CreateTextFile(Server.MapPath(strLogFileName)) End If 'If fs.FileExists(strLogFileName) Then 'set f = fs.OpenTextFile(Server.MapPath(strLogFileName), ForAppending) 'Else 'Set f = fs.CreateTextFile(Server.MapPath(strLogFileName)) 'End If f.WriteLine(Now() & " - " & Request.Cookies ("surfacetreatmentsuser")("references") & " LOGGED IN ") f.Close set f=nothing set fs=nothing Response.Redirect(MM_redirectLoginSuccess) End If MM_rsUser.Close Response.Redirect(MM_redirectLoginFailed) End If %> :::: RESTRICTED AREA :::::::::::........... SURFACE TREATMENTS

Restricted Area - Login

LOGIN PAGE
LOGIN PAGE User ID:
Password:
 
Vai all'Homepage