protected void btnlogin_Click(object sender, EventArgs e)
{
string strcon = ConfigurationManager.ConnectionStrings["pranjalConnectionString"].ToString();
SqlConnection con = new SqlConnection(strcon);
con.Open();
string email = txtEmailid.Text.Trim();
string passwd = txtPassword.Text.Trim();
string sql = "Select Email,password from reg_vidyatbl where Email='" + txtEmailid+ "'and password='" + txtPassword + "'";
SqlCommand cmd = new SqlCommand(sql, con);
cmd.ExecuteNonQuery();
SqlDataAdapter da = new SqlDataAdapter(cmd);
DataSet dt = new DataSet();
da.Fill(dt);
if (dt.Tables[0].Rows.Count > 0)
{
Response.Redirect("home.aspx");
}
else
{
lblerrorlog.Text = "invalid usernane or password";
}
this is my login code but it is not working properly,im directly getting error msg.control is not going insid the if codition.let me know if i ha made any mistake
Loading
Shivanand ArurPosted Oct 4, 2012, 12:36 PM
using System;
using System.Data;
using System.Data.SqlClient;
using System.Configuration;
using System.Web;
using System.Web.Security;
using System.Web.UI;
using System.Web.UI.WebControls;
using System.Web.UI.WebControls.WebParts;
using System.Web.UI.HtmlControls;
public partial class _Default : System.Web.UI.Page
{
public void Page_Load(object sender, EventArgs e)
{
}
public void Button_Click(object sender, EventArgs e)
{
string name, pass;
name = Unametxt.Text;
pass = Passtxt.Text;
if (Unametxt.Text == "" || Passtxt.Text == "")
{
if (Unametxt.Text == "" )
{
Label1.Text = "Enter username";
}
else if (Passtxt.Text == "" )
{
Label1.Text = "Enter password" ;
}
}
else
{
string conString = ConfigurationManager.ConnectionStrings["SqlServer"].ConnectionString.ToString();
SqlConnection con = new SqlConnection(conString);
try
{
SqlCommand cmd = new SqlCommand("Select pass from tableName where uname='" + name +"'");
cmd.Connection = con;
con.Open();
SqlDataReader dr = null;
dr = cmd.ExecuteReader();
while (dr.Read())
{
if (pass == dr[0].ToString())
{
Response.Redirect("Default.aspx");
}
else
{
Label1.Text = "Invalid Username or Password.";
Unametxt.Text = " ";
Passtxt.Text = " ";
}
}
}
catch (SqlException E)
{
Label1.Text = "Not connected"; //E.ToString();
}
}
}
}
Just for knowledge -
This is a very ammature code... Such code can cause to threats like "SQLInjection" since you are directly passing the username in the Query above...
Select pass from tableName where uname='" + name +"'"...
But for general purpose, you can use this code. To make your login a bit secure, try using Stored Procedures instead of directly passing the Name and also encrypt your passwords when adding in the database.....
Please let me know if you have any doubts....
PLEASE MARK THE ANSWER AS ACCEPTED IF IT HELPED!!!
Shivanand ArurPosted Oct 13, 2012, 12:28 AM
http://www.codeproject.com/Articles/14150/Encrypt-and-Decrypt-Data-with-C
PunitaPosted Oct 12, 2012, 11:25 PM
How to encrypt the password when we are adding it into the database and how to decrypt it when accessing it from the database??
Pranjal MishraPosted Oct 8, 2012, 12:47 PM