06. oktober 2002 - 18:26
#1
her kommer kilden
her er "autologin.asp"
<%
Option Explicit
Dim objConn
Dim strSQL
Dim objRs
Dim strUID
Dim strPWD
strUID = Trim(Replace(Request.Form("brugernavn"),"'","''"))
strPWD = Trim(Replace(Request.Form("adgangskode"),"'","''"))
If Request.Form("rem") = "true" Then
Response.Cookies("brugernavn") = strUID
Response.Cookies("brugernavn").Expires = date() + 365
Response.Cookies("password") = strPWD
Response.Cookies("password").Expires = date() + 365
End If
Set objConn = Server.CreateObject("ADODB.Connection")
objConn.Open "DRIVER={Microsoft Access Driver (*.mdb)};DBQ="&Server.Mappath("db\bruger.mdb")
Set objRs = Server.CreateObject("ADODB.Recordset")
strSQL ="SELECT id, brugernavn, adgangskode FROM bruger WHERE (brugernavn ='" & strUID & "') AND (adgangskode ='" & strPWD & "');"
objRs.Open strSQL, objConn
If NOT(objRs.BOF AND objRs.EOF) Then
Session("userid") = objRs("id")
Session("username") = objRs("brugernavn")
Session("passwd") = objRs("adgangskode")
If Request.Form("autologin") = "true" Then
Response.Cookies("userid") = Session("userid")
Response.Cookies("userid").Expires = date() + 365
strSQL ="UPDATE bruger SET autologin = TRUE WHERE (id =" & Session("userid") & ");"
objConn.Execute(strSQL)
End If
Response.Redirect("4real/index.asp")
Else
Response.Redirect("login.asp")
End If
%>
<%@LANGUAGE="VBSCRIPT" CODEPAGE="1252"%>
<!--#include file="Connections/db.asp" -->
<%
' *** Validate request to log in to this site.
MM_LoginAction = Request.ServerVariables("URL")
If Request.QueryString<>"" Then MM_LoginAction = MM_LoginAction + "?" + Request.QueryString
MM_valUsername=CStr(Request.Form("username"))
If MM_valUsername <> "" Then
MM_fldUserAuthorization=""
MM_redirectLoginSuccess="4real/index.asp"
MM_redirectLoginFailed="login.asp"
MM_flag="ADODB.Recordset"
set MM_rsUser = Server.CreateObject(MM_flag)
MM_rsUser.ActiveConnection = MM_db_STRING
MM_rsUser.Source = "SELECT brugernavn, adgangskode"
If MM_fldUserAuthorization <> "" Then MM_rsUser.Source = MM_rsUser.Source & "," & MM_fldUserAuthorization
MM_rsUser.Source = MM_rsUser.Source & " FROM bruger WHERE brugernavn='" & Replace(MM_valUsername,"'","''") &"' AND adgangskode='" & Replace(Request.Form("password"),"'","''") & "'"
MM_rsUser.CursorType = 0
MM_rsUser.CursorLocation = 2
MM_rsUser.LockType = 3
MM_rsUser.Open
If Not MM_rsUser.EOF Or Not MM_rsUser.BOF Then
' username and password match - this is a valid user
Session("MM_Username") = MM_valUsername
If (MM_fldUserAuthorization <> "") Then
Session("MM_UserAuthorization") = CStr(MM_rsUser.Fields.Item(MM_fldUserAuthorization).Value)
Else
Session("MM_UserAuthorization") = ""
End If
if CStr(Request.QueryString("accessdenied")) <> "" And false Then
MM_redirectLoginSuccess = Request.QueryString("accessdenied")
End If
MM_rsUser.Close
Response.Redirect(MM_redirectLoginSuccess)
End If
MM_rsUser.Close
Response.Redirect(MM_redirectLoginFailed)
End If
%>
..........................................................................................................................
her er "login.asp"
<html>
<head>
<title>login.asp</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
</head>
<body>
<table cellpadding="0" cellspacing="0" border="0" align="center">
<form name="loginboxform" action="<%=MM_LoginAction%>" method="POST">
<input type="hidden" name="PHPSESSID" value="d1845c08e86eba80775affd1fe9fba48" />
<tr>
<td colspan="2"><img src="images/spacer.gif" width="5" height="5"></td>
</tr>
<tr>
<td class="loginbox" colspan="2">Brugernavn:</td>
</tr>
<tr>
<td colspan="2"><input type="text" name="brugernavn" size="15" class="forms"></td>
</tr>
<tr>
<td class="loginbox" colspan="2">Password:</td>
</tr>
<tr>
<td colspan="2"><input type="password" name="adgangskode" size="15" class="forms"></td>
</tr>
<tr>
<td colspan="2"><img src="images/spacer.gif" width="10" height="5"></td>
</tr>
<tr>
<td class="autologin" align="left" valign="middle"><input type="checkbox" name="autologin" onFocus="if (this.blur) this.blur();">Autologin</td>
<td class="autologin" align="right" valign="middle"><input type="image" src="gfx/ok.gif?PHPSESSID=d1845c08e86eba80775affd1fe9fba48" onClick="loginboxform.submit();" onFocus="if (this.blur) this.blur();"></td>
</tr>
<tr>
</tr>
</form>
</table>
</body>
</html>
.................................................................................................................
her er "opret bruger.asp"
<%@LANGUAGE="VBSCRIPT" CODEPAGE="1252"%>
<!--#include file="Connections/db.asp" -->
<%
' *** Edit Operations: declare variables
Dim MM_editAction
Dim MM_abortEdit
Dim MM_editQuery
Dim MM_editCmd
Dim MM_editConnection
Dim MM_editTable
Dim MM_editRedirectUrl
Dim MM_editColumn
Dim MM_recordId
Dim MM_fieldsStr
Dim MM_columnsStr
Dim MM_fields
Dim MM_columns
Dim MM_typeArray
Dim MM_formVal
Dim MM_delim
Dim MM_altVal
Dim MM_emptyVal
Dim MM_i
MM_editAction = CStr(Request.ServerVariables("SCRIPT_NAME"))
If (Request.QueryString <> "") Then
MM_editAction = MM_editAction & "?" & Request.QueryString
End If
' boolean to abort record edit
MM_abortEdit = false
' query string to execute
MM_editQuery = ""
%>
<%
' *** Redirect if username exists
MM_flag="MM_insert"
If (CStr(Request(MM_flag)) <> "") Then
MM_dupKeyRedirect="opret bruger.asp"
MM_rsKeyConnection=MM_db_STRING
MM_dupKeyUsernameValue = CStr(Request.Form("brugernavn"))
MM_dupKeySQL="SELECT brugernavn FROM bruger WHERE brugernavn='" & MM_dupKeyUsernameValue & "'"
MM_adodbRecordset="ADODB.Recordset"
set MM_rsKey=Server.CreateObject(MM_adodbRecordset)
MM_rsKey.ActiveConnection=MM_rsKeyConnection
MM_rsKey.Source=MM_dupKeySQL
MM_rsKey.CursorType=0
MM_rsKey.CursorLocation=2
MM_rsKey.LockType=3
MM_rsKey.Open
If Not MM_rsKey.EOF Or Not MM_rsKey.BOF Then
' the username was found - can not add the requested username
MM_qsChar = "?"
If (InStr(1,MM_dupKeyRedirect,"?") >= 1) Then MM_qsChar = "&"
MM_dupKeyRedirect = MM_dupKeyRedirect & MM_qsChar & "requsername=" & MM_dupKeyUsernameValue
Response.Redirect(MM_dupKeyRedirect)
End If
MM_rsKey.Close
End If
%>
<%
' *** Insert Record: set variables
If (CStr(Request("MM_insert")) = "form1") Then
MM_editConnection = MM_db_STRING
MM_editTable = "bruger"
MM_editRedirectUrl = "login.asp"
MM_fieldsStr = "fornavn|value|efternavn|value|email|value|rgang|value|gade|value|bynavn|value|postnummer|value|brugernavn|value|adgangskode|value"
MM_columnsStr = "fornavn|',none,''|efternavn|',none,''|email|',none,''|årgang|none,none,NULL|gade|',none,''|bynavn|',none,''|postnummer|none,none,NULL|brugernavn|',none,''|adgangskode|',none,''"
' create the MM_fields and MM_columns arrays
MM_fields = Split(MM_fieldsStr, "|")
MM_columns = Split(MM_columnsStr, "|")
' set the form values
For MM_i = LBound(MM_fields) To UBound(MM_fields) Step 2
MM_fields(MM_i+1) = CStr(Request.Form(MM_fields(MM_i)))
Next
' append the query string to the redirect URL
If (MM_editRedirectUrl <> "" And Request.QueryString <> "") Then
If (InStr(1, MM_editRedirectUrl, "?", vbTextCompare) = 0 And Request.QueryString <> "") Then
MM_editRedirectUrl = MM_editRedirectUrl & "?" & Request.QueryString
Else
MM_editRedirectUrl = MM_editRedirectUrl & "&" & Request.QueryString
End If
End If
End If
%>
<%
' *** Insert Record: construct a sql insert statement and execute it
Dim MM_tableValues
Dim MM_dbValues
If (CStr(Request("MM_insert")) <> "") Then
' create the sql insert statement
MM_tableValues = ""
MM_dbValues = ""
For MM_i = LBound(MM_fields) To UBound(MM_fields) Step 2
MM_formVal = MM_fields(MM_i+1)
MM_typeArray = Split(MM_columns(MM_i+1),",")
MM_delim = MM_typeArray(0)
If (MM_delim = "none") Then MM_delim = ""
MM_altVal = MM_typeArray(1)
If (MM_altVal = "none") Then MM_altVal = ""
MM_emptyVal = MM_typeArray(2)
If (MM_emptyVal = "none") Then MM_emptyVal = ""
If (MM_formVal = "") Then
MM_formVal = MM_emptyVal
Else
If (MM_altVal <> "") Then
MM_formVal = MM_altVal
ElseIf (MM_delim = "'") Then ' escape quotes
MM_formVal = "'" & Replace(MM_formVal,"'","''") & "'"
Else
MM_formVal = MM_delim + MM_formVal + MM_delim
End If
End If
If (MM_i <> LBound(MM_fields)) Then
MM_tableValues = MM_tableValues & ","
MM_dbValues = MM_dbValues & ","
End If
MM_tableValues = MM_tableValues & MM_columns(MM_i)
MM_dbValues = MM_dbValues & MM_formVal
Next
MM_editQuery = "insert into " & MM_editTable & " (" & MM_tableValues & ") values (" & MM_dbValues & ")"
If (Not MM_abortEdit) Then
' execute the insert
Set MM_editCmd = Server.CreateObject("ADODB.Command")
MM_editCmd.ActiveConnection = MM_editConnection
MM_editCmd.CommandText = MM_editQuery
MM_editCmd.Execute
MM_editCmd.ActiveConnection.Close
If (MM_editRedirectUrl <> "") Then
Response.Redirect(MM_editRedirectUrl)
End If
End If
End If
%>
<html>
<head>
<title>Ny bruger</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<script language="JavaScript" type="text/JavaScript">
<!--
function MM_findObj(n, d) { //v4.01
var p,i,x; if(!d) d=document; if((p=n.indexOf("?"))>0&&parent.frames.length) {
d=parent.frames[n.substring(p+1)].document; n=n.substring(0,p);}
if(!(x=d[n])&&d.all) x=d.all[n]; for (i=0;!x&&i<d.forms.length;i++) x=d.forms[i][n];
for(i=0;!x&&d.layers&&i<d.layers.length;i++) x=MM_findObj(n,d.layers[i].document);
if(!x && d.getElementById) x=d.getElementById(n); return x;
}
function MM_validateForm() { //v4.0
var i,p,q,nm,test,num,min,max,errors='',args=MM_validateForm.arguments;
for (i=0; i<(args.length-2); i+=3) { test=args[i+2]; val=MM_findObj(args[i]);
if (val) { nm=val.name; if ((val=val.value)!="") {
if (test.indexOf('isEmail')!=-1) { p=val.indexOf('@');
if (p<1 || p==(val.length-1)) errors+='- '+nm+' must contain an e-mail address.\n';
} else if (test!='R') { num = parseFloat(val);
if (isNaN(val)) errors+='- '+nm+' must contain a number.\n';
if (test.indexOf('inRange') != -1) { p=test.indexOf(':');
min=test.substring(8,p); max=test.substring(p+1);
if (num<min || max<num) errors+='- '+nm+' must contain a number between '+min+' and '+max+'.\n';
} } } else if (test.charAt(0) == 'R') errors += '- '+nm+' is required.\n'; }
} if (errors) alert('The following error(s) occurred:\n'+errors);
document.MM_returnValue = (errors == '');
}
//-->
</script>
</head>
<body>
<form action="<%=MM_editAction%>" method="post" name="form1" onSubmit="MM_validateForm('fornavn','','R','efternavn','','R','email','','RisEmail','rgang','','RinRange1900:1984','gade','','R','bynavn','','R','postnummer','','RisNum','brugernavn','','R','adgangskode','','R');return document.MM_returnValue">
<table align="center">
<tr valign="baseline">
<td nowrap align="right">Fornavn:</td>
<td> <input type="text" name="fornavn" value="" size="32"> </td>
</tr>
<tr valign="baseline">
<td nowrap align="right">Efternavn:</td>
<td> <input type="text" name="efternavn" value="" size="32"> </td>
</tr>
<tr valign="baseline">
<td nowrap align="right">Email:</td>
<td> <input type="text" name="email" value="" size="32"> </td>
</tr>
<tr valign="baseline">
<td nowrap align="right">Årgang:</td>
<td> <input type="text" name="rgang" value="" size="32"> </td>
</tr>
<tr valign="baseline">
<td nowrap align="right">Gade:</td>
<td> <input type="text" name="gade" value="" size="32"> </td>
</tr>
<tr valign="baseline">
<td nowrap align="right">Bynavn:</td>
<td> <input type="text" name="bynavn" value="" size="32"> </td>
</tr>
<tr valign="baseline">
<td nowrap align="right">Postnummer:</td>
<td> <input type="text" name="postnummer" value="" size="32"> </td>
</tr>
<tr valign="baseline">
<td nowrap align="right">Brugernavn:</td>
<td> <input type="text" name="brugernavn" value="" size="32"> </td>
</tr>
<tr valign="baseline">
<td nowrap align="right">passwoord</td>
<td> <input type="password" name="adgangskode" value="" size="32"> </td>
</tr>
<tr valign="baseline">
<td nowrap align="right"> </td>
<td> <input type="submit" value="opret bruger"> </td>
</tr>
</table>
<input type="hidden" name="MM_insert" value="form1">
</form>
<p>
<% If (Request.QueryString("requsername")) <> ("") Then 'script %>
<script language="JavaScript" type="text/JavaScript">
('Brugernavnet <%=Request.QueryString("requsername")%>er optaget. Vælg et nyt');
</script>
<% End If ' end If (Request.QueryString("requsername")) <> ("") script %>
</p>
</body>
</html>