<?php
session_start();
$servername = "localhost";
$username = "root";
$password = "";
$dbname = "my_db";
$conn = new mysqli($servername, $username, $password, $dbname);
if ($_SERVER["REQUEST_METHOD"] == "POST") {
$user = $_POST['username'];
$pass = $_POST['password'];
$sql = "SELECT id, password_hash FROM users WHERE username = '$user'";
$result = $conn->query($sql);
if ($result->num_rows > 0) {
$row = $result->fetch_assoc();
if (password_verify($pass, $row['password_hash'])) {
$_SESSION["loggedin"] = true;
$_SESSION["userid"] = $row["id"];
$_SESSION["username"] = $user;
echo "Welcome, you are logged in!";
} else {
echo "Incorrect password.";
}
} else {
echo "User does not exist.";
}
}
?>