1) $FF_newQS .= "&"; $FF_newQS .= $key . "=" . urlencode($val); } } if (strlen($FF_newQS) > 1) $FF_logoutRedirectPage .= $FF_newQS; } header("Location: $FF_logoutRedirectPage"); exit; } session_start(); $colname_User = "1"; if (isset($_SESSION['MM_Username'])) { $colname_User = (get_magic_quotes_gpc()) ? $_SESSION['MM_Username'] : addslashes($_SESSION['MM_Username']); } //mysql_select_db("test",$link) ; $query_User = sprintf("SELECT * FROM member WHERE m_username = '%s'", $colname_User); $User = mysql_query($query_User, $link) or die(mysql_error()); $row_User = mysql_fetch_assoc($User); $totalRows_User = mysql_num_rows($User); $pro ="Select movie from product WHERE pro_id=".$_GET['pro_id']; $pro_result=mysql_query ($pro,$link); $MM_paramName = ""; // *** Start the session session_start(); // *** Validate request to log in to this site. $FF_LoginAction = $_SERVER['PHP_SELF']; if (isset($_SERVER['QUERY_STRING']) && $_SERVER['QUERY_STRING']!="") $FF_LoginAction .= "?".$_SERVER['QUERY_STRING']; if ((isset($_POST['m_username'])&&($_POST['m_username']!=''))) { $FF_valUsername=$_POST['m_username']; $FF_valPassword=$_POST['m_password']; $FF_fldUserAuthorization="level"; $FF_redirectLoginSuccess="index.php"; $FF_redirectLoginFailed="index.php?errMsg=not"; $FF_rsUser_Source="SELECT m_username, m_password "; if ($FF_fldUserAuthorization != "") $FF_rsUser_Source .= "," . $FF_fldUserAuthorization; $FF_rsUser_Source .= " FROM member WHERE m_username='" . $FF_valUsername . "' AND m_password='" . $FF_valPassword . "'"; $FF_rsUser=mysql_query($FF_rsUser_Source, $link) or die(mysql_error()); $row_FF_rsUser = mysql_fetch_assoc($FF_rsUser); if(mysql_num_rows($FF_rsUser) > 0) { // username and password match - this is a valid user $MM_Username=$FF_valUsername; session_register("MM_Username"); if ($FF_fldUserAuthorization != "") { $MM_UserAuthorization=$row_FF_rsUser[$FF_fldUserAuthorization]; } else { $MM_UserAuthorization=""; } session_register("MM_UserAuthorization"); if (isset($accessdenied) && false) { $FF_redirectLoginSuccess = $accessdenied; } mysql_free_result($FF_rsUser); session_register("FF_login_failed"); $FF_login_failed = false; header ("Location: $FF_redirectLoginSuccess"); exit; } mysql_free_result($FF_rsUser); session_register("FF_login_failed"); $FF_login_failed = true; header ("Location: $FF_redirectLoginFailed"); exit; } $MM_removeList = "&test="; if ($MM_paramName != "") $MM_removeList .= "&".strtolower($MM_paramName)."="; $MM_keepURL=""; $MM_keepForm=""; $MM_keepBoth=""; $MM_keepNone=""; // add the URL parameters to the MM_keepURL string reset ($_GET); while (list ($key, $val) = each ($_GET)) { $nextItem = "&".strtolower($key)."="; if (!stristr($MM_removeList, $nextItem)) { $MM_keepURL .= "&".$key."=".urlencode($val); } } // add the URL parameters to the MM_keepURL string if(isset($_POST)){ reset ($_POST); while (list ($key, $val) = each ($_POST)) { $nextItem = "&".strtolower($key)."="; if (!stristr($MM_removeList, $nextItem)) { $MM_keepForm .= "&".$key."=".urlencode($val); } } } // create the Form + URL string and remove the intial '&' from each of the strings $MM_keepBoth = $MM_keepURL."&".$MM_keepForm; if (strlen($MM_keepBoth) > 0) $MM_keepBoth = substr($MM_keepBoth, 1); if (strlen($MM_keepURL) > 0) $MM_keepURL = substr($MM_keepURL, 1); if (strlen($MM_keepForm) > 0) $MM_keepForm = substr($MM_keepForm, 1); ?> 影片介紹
 
影片介紹