# More worries - login form with u/n and p/w in MySQL

**URL:** <https://forum.kirupa.com/t/more-worries-login-form-with-u-n-and-p-w-in-mysql/119184>\
**Category:** Uncategorized\
**Created:** [August 12, 2004, 5:41am UTC](https://forum.kirupa.com/t/more-worries-login-form-with-u-n-and-p-w-in-mysql/119184 "2004-08-12T05:41:15Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Carixpig](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/carixpig/32/304_2.png) [@Carixpig](https://forum.kirupa.com/u/Carixpig)\
**Post date:** [August 12, 2004, 5:41am UTC](https://forum.kirupa.com/t/more-worries-login-form-with-u-n-and-p-w-in-mysql/119184/1 "2004-08-12T05:41:15Z")

</div>

I’ve been hanging around this forum a bit lately, so thanks all for your help.

Now I need to get my login forms working with passwords and usernames from MySQL. I had it working for one session today, but then I must have changed something because I can’t get it to go again.

The login page has an included file as follows called login.php, which has the function for checking the database:

```php

<?php

function login($username, $password){
	$query = "SELECT * FROM itl_users WHERE user_login='$username' AND user_password='$password'";
	$result = mysql_query($query);
	if(!result)
	return 0;
	if (mysql_num_rows($result) > 0)
	return 1;
	else
	return 0;

}

?>

```

This is the page with the form and the protected area:

```php

<html>
<head>
<title>Add Client Downloads to ITL</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
</head>
<body bgcolor="#FFFFFF" text="#000000">

<?php

require '../include.php';
require '../login.php';

$username = $_POST['txtUsername'];
$password = $_POST['txtPassword'];

if(!login($username, $password)){

?>

<div align="center"> 
  <TABLE WIDTH=500 BORDER=0 CELLPADDING=0 CELLSPACING=0>
    <tr> 
      <td colspan=2> 
        <div align="center"></div>
        <p><b><font face="Arial, Helvetica, sans-serif"><br>
          Add ITL Clients<br>
          &nbsp; </font></b></p>
      </td>
    </tr>
    <tr>
      <td colspan=2> 
        <form name="form" method="post" action="<?php echo $_SERVER['PHP_SELF']; ?>">
          <p><font face="Arial, Helvetica, sans-serif" size="-1">Please enter 
            your Username and Password to make changes to the ITL Clients Area</font></p>
          <table border="0" cellpadding="5" cellspacing="0">
            <tr> 
              <td><font face="Arial, Helvetica, sans-serif" size="-1"><label for="txtUsername">Username</label> 
                </font></td>
              <td><font face="Arial, Helvetica, sans-serif" size="-1"> 
                <input type="text" title="Enter your Username" name="txtUsername" size="16" maxlength="16" />
                </font></td>
            </tr>
            <tr> 
              <td><font face="Arial, Helvetica, sans-serif" size="-1"><label for="txtpassword">Password</label> 
                </font></td>
              <td><font face="Arial, Helvetica, sans-serif" size="-1"> 
                <input type="password" title="Enter your password" name="txtPassword" size="16" maxlength="16" />
                </font></td>
            </tr>
          </table>
          <p><font face="Arial, Helvetica, sans-serif" size="-1"> 
            <input type="submit" name="Submit" value="Login" />
            </font></p>
          <p><font face="Arial, Helvetica, sans-serif" size="-1"><b><a href="index.php">back 
            to clients options</a></b></font> </p>
        </form>
      </td>
    </tr>
  </TABLE>
</div>

<font face="Arial, Helvetica, sans-serif" size="-1"> 
<?php
}
else 
{
?>
</font> 
<div align=center>
  <TABLE WIDTH=500 BORDER=0 CELLPADDING=0 CELLSPACING=0>
    <tr> 
      <td colspan=2> 
        <div align="center"></div>
        <p><b><font face="Arial, Helvetica, sans-serif"><br>
          Add ITL Clients</font></b><b><font face="Arial, Helvetica, sans-serif"><br>
          &nbsp; </font></b></p>
      </td>
    </tr>
    <tr> 
      <td colspan=2><font face="Arial, Helvetica, sans-serif" size="-1">more stuff 
        here...</font></td>
    </tr>
  </table>
</div>

<?php
}
?> 

</body>
</html>

```

Thanks  
C

---

<div class="post-metadata">

**Author:** ![Opiate](https://avatars.discourse-cdn.com/v4/letter/o/58f4c7/32.png) [@Opiate](https://forum.kirupa.com/u/Opiate)\
**Post date:** [August 17, 2004, 5:09pm UTC](https://forum.kirupa.com/t/more-worries-login-form-with-u-n-and-p-w-in-mysql/119184/2 "2004-08-17T17:09:00Z")

</div>

Do you call mysql\_connect and mysql\_select\_db with correct information in include.php? If not, that’s probably whats giving you trouble.

Also, for security reasons you should add the following lines before you call the login function with $username and $password:

if (!get\_magic\_quotes\_gpc())  
{  
$username = addslashes($username);  
$password = addslashes($password);  
}

---

<div class="post-metadata">

**Author:** ![ol4pr0](https://avatars.discourse-cdn.com/v4/letter/o/5fc32e/32.png) [@ol4pr0](https://forum.kirupa.com/u/ol4pr0)\
**Post date:** [August 17, 2004, 7:10pm UTC](https://forum.kirupa.com/t/more-worries-login-form-with-u-n-and-p-w-in-mysql/119184/3 "2004-08-17T19:10:24Z")

</div>

could be me but i do not see you executing the function

ie:

```php

login($_POST['username'],$_POST['password']);

```

---

<div class="post-metadata">

**Author:** ![Hans\_Kilian](https://avatars.discourse-cdn.com/v4/letter/h/838e76/32.png) [@Hans\_Kilian](https://forum.kirupa.com/u/Hans_Kilian)\
**Post date:** [August 17, 2004, 7:17pm UTC](https://forum.kirupa.com/t/more-worries-login-form-with-u-n-and-p-w-in-mysql/119184/4 "2004-08-17T19:17:42Z")

</div>

There’s a dollar sign missing in front of ‘result’ in the first if-statement in your login function. It should be  
if (!$result)

---

<div class="post-metadata">

**Author:** ![ol4pr0](https://avatars.discourse-cdn.com/v4/letter/o/5fc32e/32.png) [@ol4pr0](https://forum.kirupa.com/u/ol4pr0)\
**Post date:** [August 17, 2004, 8:30pm UTC](https://forum.kirupa.com/t/more-worries-login-form-with-u-n-and-p-w-in-mysql/119184/5 "2004-08-17T20:30:21Z")

</div>

see it now lol

```php

 $check = login($username, $password);
 if ($check == 0) {
 // do
 }
 else
 {
 // do
 }
 

```

- the if (!$result) as hans stated
