<%
end if
%>
<%
Dim action
Dim username,password
action=lcase(trim(request("action")))
username=request.Form("username")
password=md5(request.Form("password"))
select case action:
case "chklogin"
Call chklogin()
case "login"
Call login()
case "lostpwd"
Call lostpwd()
case "findpwd"
Call findpwd()
case "editinfo":
Call EditInfo()
case "editorder":
Call EditOrder()
case "saveinfo":
Call SaveInfo()
case "reg":
Call Reg()
case "searchorder":
Call SearchOrder()
case "help":
Call help()
case "order":
Call order()
case else:
Call login()
end select
Sub chklogin()
set cmd=server.createobject("adodb.command")
cmd.ActiveConnection=conn
cmd.CommandText="UserLogin"
cmd.CommandType=adCmdStoredProc
cmd.parameters.Append cmd.CreateParameter("@username",advarchar,adParamInput,20,username)
cmd.parameters.Append cmd.CreateParameter("@password",advarchar,adParamInput,30,password)
set rs=server.CreateObject("adodb.recordset")
rs.open cmd,,1,1
if rs.eof then
'call JsErr("用户名或密码不正确","javascript:window.opener=null;window.close()")
call JsErr("用户名或密码不正确","")
else
response.cookies("cs")("username")=username
response.cookies("cs")("name")=rs("name")
response.cookies("cs")("userid")=rs("id")
response.cookies("cs")("password")=request.Form("password")
session("username")=username
session("name")=rs("name")
session("uid")=rs("ID")
session("password")=request.Form("password")
set cmd=nothing
'response.Write(request("returnurl"))
' response.End()
groupid=trim(request("groupid"))
lineid=trim(request("lineid"))
'response.write trim(request("action"))
'response.end
if Request("returnurl")<>"" then
response.Redirect "order.asp?action=info&groupid="&groupid&"&lineid="&lineid
else
response.Redirect("tese.asp")
end if
end if
end sub
Sub order()
conn.execute "update order_list set state=4 where orderid='"&trim(request("orderid"))&"'"
response.redirect"tese?action=searchorder"
end sub
sub Findpwd()
Dim mEmail,Npwd,mUsername
mEmail=trim(request.form("Email"))
if mEmail="" then
Call JsErr("您的Email不能为空!","")
end if
if isvalidEmail(mEmail)=false then
Call JsErr("您的Email格式不正确!","")
end if
Sql="select Email,username,password from member where Email='"&mEmail&"'"
set rs=server.createobject("adodb.recordset")
rs.open sql,conn,1,3
if not rs.eof then
Call StrRandomize(CStr(Now) & CStr(Rnd))
Npwd=GeneratePassword(6)
rs("password")=md5(Npwd)
mUsername=rs("username")
rs.update
end if
UPASSWORD=Npwd
'Call SendSystemEmail("findpwd",mUsername)
Call JsErr(request.cookies("Errmsg"),"")
end sub
%>