include("core.php"); include($docroot."/include/header.php"); if( $_GET['op'] == 'login' ){ $q = mysql_query(" SELECT * FROM ( SELECT T0.idutente, T0.username, T0.password, T0.email, T0.nickname, T0.cellulare, '' AS prefix, '' AS iso_cell, T0.idgruppo, T0.enabled, T1.nome AS nome_gruppo, T0.idanagrafica, T2.ragione_sociale, T2.codice, T2.iso, T2.piva FROM zz_utenti T0 LEFT JOIN zz_gruppi T1 ON T0.idgruppo = T1.id LEFT JOIN an_anagrafiche T2 ON T0.idanagrafica = T2.idanagrafica WHERE T1.nome = 'Amministratori' OR T1.nome = 'Supervisori' UNION ALL SELECT T0.idutente, T0.username, T0.password, T0.email, T0.nickname, T0.cellulare, T0.prefix, T0.iso AS iso_cell, T0.idgruppo, T0.enabled, T1.nome AS nome_gruppo, T0.idanagrafica, T2.ragione_sociale, T2.codice, T2.iso, T2.piva FROM zz_d4yute T0 LEFT JOIN zz_gruppi T1 ON T0.idgruppo = T1.id LEFT JOIN an_anagrafiche T2 ON T0.idanagrafica = T2.idanagrafica WHERE T1.nome = 'Clienti' ) AS TX WHERE TX.username = \"".$html->form('username', 'post')."\" AND TX.password = MD5(\"".$html->form('password', 'post')."\") "); if( mysql_num_rows($q) == 0 ){ array_push( $_SESSION['errors'], ln('Username e/o password errati!')); } else{ $rs = mysql_fetch_assoc($q); //Utente disabilitato if( $rs['enabled'] == '0' ){ array_push( $_SESSION['errors'], ln('Il tuo profilo รจ disabilitato!')); } //Login ok else{ $_SESSION['d4y_userid'] = $rs['idutente']; $_SESSION['d4y_groupid_login'] = $rs['idgruppo']; $_SESSION['d4y_groupid'] = $rs['idgruppo']; $_SESSION['d4y_username'] = $rs['username']; $_SESSION['d4y_username_login'] = $rs['username']; $_SESSION['d4y_idanagrafica'] = $rs['idanagrafica']; $_SESSION['d4y_codice'] = $rs['codice']; $_SESSION['d4y_piva'] = $rs['iso'].$rs['piva']; $_SESSION['d4y_email'] = $rs['email']; $_SESSION['d4y_nazcell'] = $rs['iso_cell']; $_SESSION['d4y_prefisso'] = $rs['prefix']; $_SESSION['d4y_cellulare'] = $rs['cellulare']; $_SESSION['d4y_nome'] = $rs['nickname']; $_SESSION['d4y_autologin'] = 0; $_SESSION['d4y_anagrafica'] = $rs['ragione_sociale']; if ( $rs['ragione_sociale'] != '' ): $_SESSION['d4y_ragsoc'] = $rs['ragione_sociale']; else: $_SESSION['d4y_ragsoc'] = "S E R V I C E";; endif; // registro l'accesso if ($_SESSION['d4y_groupid']==4){ $q = mysql_query(" INSERT INTO `zz_d4yacc` ( `idutente`, `username`, `email`, `iso`, `prefix`, `cellulare`, `nickname`, `idanagrafica`, `data_accesso` ) VALUES ( ".$_SESSION['d4y_userid'].", '".$_SESSION['d4y_username']."', '".$_SESSION['d4y_email']."', '".$_SESSION['d4y_nazcell']."', '".$_SESSION['d4y_prefisso']."', '".$_SESSION['d4y_cellulare']."', '".$_SESSION['d4y_nome']."', ".$_SESSION['d4y_idanagrafica'].", NOW() ) "); } header("Location: go/"); exit; } } } //Logout else if( $_GET['op'] == 'logout' ){ unset( $_SESSION['d4y_userid'] ); unset( $_SESSION['d4y_groupid_login'] ); unset( $_SESSION['d4y_groupid'] ); unset( $_SESSION['d4y_username'] ); unset( $_SESSION['d4y_username_login'] ); unset( $_SESSION['d4y_idanagrafica'] ); unset( $_SESSION['d4y_codice'] ); unset( $_SESSION['d4y_piva'] ); unset( $_SESSION['d4y_email'] ); unset( $_SESSION['d4y_cellulare'] ); unset( $_SESSION['d4y_nome'] ); unset( $_SESSION['d4y_autologin'] ); unset( $_SESSION['d4y_ragsoc'] ); unset( $_SESSION['d4y_anagrafica'] ); unset( $_SESSION['d4y_nazcell'] ); unset( $_SESSION['d4y_prefisso'] ); unset( $_SESSION['lng'] ); //session_destroy(); header("Location: ".$rootdir); exit; } $lng_flag = $lng[ strtoupper($_SESSION['lng']) ]['flag']; $lng_lingua = $lng[ strtoupper($_SESSION['lng']) ]['lingua']; $lng_nazione = $lng[ strtoupper($_SESSION['lng']) ]['nazione']; $pathimg = $rootdir."/images/flags"; ?>