private void ImageButton1_Click(object sender, System.Web.UI.ImageClickEventArgs e)
{
sqlstr = "select * from t_user where u_code='"+txtU_code.Value.ToString().Replace("'","")+"'";
SqlConnection conn = new SqlConnection();
conn.Open();
SqlCommand sqlcmd=new SqlCommand(sqlstr,conn.connstr);
dr=sqlcmd.ExecuteReader();
if(dr.Read())
{
//通过验证
Session["u_code"] = dr["u_code"].ToString();
Session["u_name"] = dr["u_name"].ToString();
Page.Response.Redirect("index.aspx");
}
}