<?php
// get input
$u=$_POST['u'];
$p=$_POST['p'];
// Database check
$q=sprintf(" SELECT id FROM user WHERE username='%s' AND password='%s' ",$u,$p);
$q=mysql_query($q);
if (mysql_num_rows($q)>0) {
// matched data
$r = mysql_fetch_row($q);
$id = $r[0];
session_start();
$_SESSION['user_id'] = $id;
header("Location: home.php");
die('');
exit;
}
?>
<?php
if (!isset($_SESSION['user_id']) || $_SESSION['user_id']=='') {
header("Location: login.php");
die('');
exit;
}
// display your main "home.php" from below
?>
<html>
<h1>Welcome, our lovely member</h1>
<?php
$_SESSION['user_id']='';
header("Location: index.php");
?>

