|
|
I'm tryin to do a login that when successful redirects the user to a page for their region. Here is my code...
<%
' *** Validate request to log in to this site.
MM_LoginAction = Request.ServerVariables("URL")
If Request.QueryString<>"" Then MM_LoginAction = MM_LoginAction + "?" + Server.HTMLEncode(Request.QueryString)
MM_valUsername=CStr(Request.Form("username"))
If MM_valUsername <> "" Then
MM_fldUserAuthorization=""
'MM_redirectLoginSuccess="/partnersite/regions/EMEA/index.asp"
MM_redirectLoginFailed="/partnersite/loginfailed.html"
MM_flag="ADODB.Recordset"
set MM_rsUser = Server.CreateObject(MM_flag)
MM_rsUser.ActiveConnection = MM_mdfWeb_STRING
MM_rsUser.Source = "SELECT U.UserName, U.Password, P.URLRedirect"
If MM_fldUserAuthorization <> "" Then MM_rsUser.Source = MM_rsUser.Source & "," & MM_fldUserAuthorization
MM_rsUser.Source = MM_rsUser.Source & " FROM dbo.User U INNER JOIN Partner P ON U.PartnerID=P.PartnerID WHERE U.UserName='" & Replace(MM_valUsername,"'","''") &"' AND U.Password='" & Replace(Request.Form("password"),"'","''") & "'"
MM_rsUser.CursorType = 0
MM_rsUser.CursorLocation = 2
MM_rsUser.LockType = 3
MM_rsUser.Open
If Not MM_rsUser.EOF Or Not MM_rsUser.BOF Then
' username and password match - this is a valid user
Session("MM_Username") = MM_valUsername
Session("svURL")=MM_rsUser.Fields.Item("URLRedirect")
If (MM_fldUserAuthorization <> "") Then
Session("MM_UserAuthorization") = CStr(MM_rsUser.Fields.Item(MM_fldUserAuthorization).Value)
Else
Session("MM_UserAuthorization") = ""
End If
if CStr(Request.QueryString("accessdenied")) <> "" And false Then
MM_redirectLoginSuccess = Request.QueryString("accessdenied")
End If
MM_rsUser.Close
Response.Redirect "/partnersite/" & Session("svURL") &""
'Response.Redirect(MM_redirectLoginSuccess)
End If
MM_rsUser.Close
Response.Redirect(MM_redirectLoginFailed)
End If
%>
I get the following error...
Microsoft OLE DB Provider for ODBC Drivers error '80040e14'
[Microsoft][ODBC SQL Server Driver][SQL Server]Incorrect syntax near the keyword 'User'.
/partnersite/loginMM2.asp, line 21
Line 21 is the following..
MM_rsUser.Open
Thanks in advance for your help.
J
|
|
|
|
hi jodtoad,
please double check this code,
MM_rsUser.Source = "SELECT U.UserName, U.Password, P.URLRedirect"
If MM_fldUserAuthorization <> "" Then MM_rsUser.Source = MM_rsUser.Source & "," & MM_fldUserAuthorization
MM_rsUser.Source = MM_rsUser.Source & " FROM dbo.User U INNER JOIN Partner P ON U.PartnerID=P.PartnerID WHERE U.UserName='" & Replace(MM_valUsername,"'","''") &"' AND U.Password='" & Replace(Request.Form("password"),"'","''") & "'"
i think you had missing some " or ' on your sql
statement.
please testing your exact sql statement before making
any dynamic variable.
hopefully it'll help you.
"Gain more knowledge at codetoad.com"
yusairi http://www.vss.com.my
|
|
|
|
|
|
|
|
|
|