<?php
	session_start();
	$con = mysql_connect("localhost", "root", "root");
	mysql_select_db("tpo", $con);
	$_POST['login'] = stripslashes($_POST['login']);
	$_POST['login'] = strip_tags($_POST['login']);
	$_POST['password'] = stripslashes($_POST['password']);
	$_POST['password'] = strip_tags($_POST['password']);
	$auth = mysql_query("SELECT name FROM user WHERE login='{$_POST['login']}' AND password='{$_POST['password']}'");
	if(mysql_num_rows($auth)){
		$obj = mysql_fetch_object($auth);
		if($obj->name == ''){
			$_SESSION['username'] = $_POST['login'];
			$_SESSION['badauth'] = 0;
			$_SESSION['login'] = $_POST['login'];
		}else{
			$_SESSION['username'] = $obj->name;
			$_SESSION['badauth'] = 0;
			$_SESSION['login'] = $_POST['login'];
		}
		
	}else{
		$_SESSION['badauth'] = 1;
	}
	
	header('Location:'.$_SERVER['HTTP_REFERER']);
	//echo "<script type='text/javascript'>window.parent.location.reload();</script>";
?>