后台登陆部分.
private void Button1_Click(object sender, System.EventArgs e)
{
string UserName=Request.Form["sys_name"];
string Password=Request.Form["sys_password"];
if (UserName.ToString()=="")
{
Response.Write("<script>alert('用户名不能为空');</script>");
}
else
{
if (Password.ToString()=="")
{
Response.Write("<script>alert('密码不能为空');</script>");
}
else
{
SqlConnection myConn=DBCONN.CreateCon();
myConn.Open();
string SqlStr = "select * from sys_admin where sys_name='"+UserName+"' and sys_password='"+Password+"'";
SqlCommand StrCmd=new SqlCommand(SqlStr,myConn);
SqlDataReader myRead=StrCmd.ExecuteReader();
if (myRead.Read())
{
Session["UserName"]="UserName";
Response.Write("<script>location.href='Admin_Index.aspx';</script>");
}
else
{
Response.Write("<script>alert('用户名或者密码错误,请重试');</script>");
}
myRead.Close();
myConn.Close();
}
}
reg.aspx.cs
|
string UserName=Request.Form["name"]; string upassword=Request.Form["password"]; string urpassword=Request.Form["rpassword"];
SqlConnection myConn=DBCONN.CreateCon(); myConn.Open(); string strSql = "select * from user01 where name='"+UserName+"'"; SqlCommand cmd= new SqlCommand(strSql,myConn); SqlDataReader myrs = cmd.ExecuteReader(); if (myrs.Read()) { L_Check.Text="对不起,该会员名已经存在,请更换再注册,谢谢!"; } else { myConn.Close(); myConn.Open(); string SqlStr="insert into user01 (name,password,rpassword) values" +"('"+UserName+"','"+upassword+"','"+urpassword+"')"; SqlCommand SqlCmd=new SqlCommand(SqlStr,myConn); SqlCmd.ExecuteNonQuery(); Session["UserName"]=name.Text ;//生成用户的Session Response.Redirect ("index.aspx");//转向首页,起刷新作用 } myrs.Close ();//一切读取行为结束后,一定要关闭阅读器 myConn.Close();
|
|
订单页面验证是否
private void Page_Load(object sender, System.EventArgs e) { // 在此处放置用户代码以初始化页面 SqlConnection myConn=DBCONN.CreateCon(); myConn.Open(); if(Session["UserName"]==null) { //如果用户未登陆 Response.Write("<script>alert('您还没有登陆请到首页登陆!');location.href='Index.aspx'</script>"); } else//如果登陆 { Label1.Text =Session["UserName"].ToString();//显示用户名 } }
|
|
提交订单部分
private void Button1_Click(object sender, System.EventArgs e) { SqlConnection myConn=DBCONN.CreateCon(); myConn.Open(); string uname =Session["UserName"].ToString(); string ucompanyname = Request.Form["companyname"].ToString(); string utruename = Request.Form["truename"].ToString(); string ushenfen = Request.Form["shenfen"].ToString(); string utel = Request.Form["tel"].ToString(); string uproducts = Request.Form["products"].ToString(); string utotle = Request.Form["totle"].ToString(); string uprice = Request.Form["price"].ToString();
string SqlStr="insert into user01 (companyname,truename,shenfen,tel,products,totle,price) values " +"('"+ucompanyname+"','"+utruename+"','"+ushenfen+"','"+utel+"','"+uproducts+"','"+utotle+"','"+uprice+"')"; SqlCommand SqlCmd=new SqlCommand(SqlStr,myConn); SqlCmd.ExecuteNonQuery(); Response.Write("<script>alert('你的资料已提交,点击将到首页.谢谢!');location.href='Index.aspx'</script>"); myConn.Close();
}
|