prepare("SELECT * FROM `users` WHERE `username` = ?"); $stmt->execute([$username]); $user = $stmt->fetch(); if ($user && password_verify($password, $user['password_hash'])) { // Password is correct, start session $_SESSION['user_id'] = $user['id']; $_SESSION['username'] = $user['username']; $_SESSION['role'] = $user['role']; header("Location: dashboard.php"); exit; } else { $error_message = 'Invalid username or password.'; } } catch (PDOException $e) { $error_message = 'Database error. Please try again later.'; // In a real production environment, you would log this error. // error_log($e->getMessage()); } } } ?>
Please sign in to continue