PHP:
<html>
<head>
<title>Login</title>
</head>
<body>
<?php
if(isset($_POST['username'])){
$username = $_POST['username'];
}
else{echo 'Non hai inserito dati';}
if((strlen($username)=='0')){echo ' <form id="login" action="verifica.php" method="post">
<fieldset id="inputs">
<input id="username" name="username" type="text" placeholder="Username" autofocus required>
</fieldset>
<fieldset id="actions">
<input type="submit" id="submit" value="Entra">
</fieldset>
</form>';
}
else{ $connessione = mysqli_connect(//dati);
if (!$connessione) {
die('Connect Error (' . mysqli_connect_errno() . ') '
. mysqli_connect_error());
}
$strSQL = "SELECT * FROM tabella WHERE username = '".$username."";
function search_escape($strSQL, $char = '\\')
{
return ereg_replace('[%_]', $char . '\0', $strSQL);
}
$result = mysqli_query($strSQL);
$row = mysqli_fetch_row($result);
if(strlen($row[0]) == 0){echo 'Dati errati!';}
else{$_SESSION['logged'];
echo 'Login effettuato!
//eccetera';
}
}
?>
Secondo voi, cosa ho sbagliato?