prepare("SELECT * FROM users WHERE username = ?"); $stmt->execute([$_POST['username']]); $user = $stmt->fetch(); if ($user && password_verify($_POST['password'], $user['password'])) { $_SESSION['user_id'] = $user['id']; $_SESSION['username'] = $user['username']; $_SESSION['is_admin'] = $user['is_admin']; header("Location: admin.php"); exit; } else { $error_message = 'Invalid username or password.'; } } catch (PDOException $e) { $error_message = 'Database error: ' . $e->getMessage(); } } else { $error_message = 'Please fill in both fields.'; } } ?>