<?php
include("conn.php");
$username = trim($_POST['username']);
$paw = md5(trim($_POST['paw']));
if($_POST[check]){
if($_POST[check]==$_SESSION[check_pic]){
echo "正确";
}else {
echo "错误";
}
}
$errmsg = '';
if (!empty($username)) { 
    if (empty($username)) {
        $errmsg = '数据输入不完整';
    }
    if(empty($errmsg)) { 

        
        if (mysqli_connect_errno()) {
            $errmsg = "数据库连接失败!\n";
        }
        else {
           
            $sql = "SELECT * FROM user WHERE username='$username' AND pwd='$paw'";
            $result = mysql_query($sql);
           if ($result && mysql_num_rows($result) > 0) {              
              echo "<script>alert('登陆成功');window.location.href='../index.php'</script>";
                session_start();
                $_SESSION['login'] = 'true';
                $_SESSION['user']=$username;
 
           }else {
                echo "<script>alert('用户名或密码不正确');window.location.href='login.html'</script>";
            }
   
        mysql_free_result($result);
mysql_close($db);
        }
    }
}?>