<?php

    $Name = strtolower($_POST['Name']);
    $Pass = $_POST['Pass'];
  
  $NotFound = True;

  $sql = "SELECT * FROM user"; // WHERE Name = '$Name' AND Pass = '$Pass'
  $ID = $db->SQLCommand($sql);
  while($Line = mysql_fetch_array($ID)) {
    if (strtolower($Line['Name']) == $Name) {
      if ($Line['Pass'] == $Pass) {
        $_SESSION['ID'] = $Line['ID'];
        $IDuser = $_SESSION['ID'];
        $_SESSION['User'] = $Line['Name'];
        $_SESSION['Pass'] = $Pass;

        $IP = $_SERVER['REMOTE_ADDR'];    
        $sql = "UPDATE user SET LastIP = '$IP', LastJoin = now() WHERE ID = '$IDuser'"; // WHERE Name = '$Name' AND Pass = '$Pass'
        $db->SQLCommand($sql);


        $NotFound = False;
        $LogText = '<b>Přihlášení se povedlo</b><br /><br />'; 
      } else {
        $LogText = '<b>Špatné heslo!</b><br /><br />';       
      }

  //TODO:  online

    }   
  }
  if ($NotFound)
    $LogText = '<b>Uživatel nebyl nalezen</b><br /><br />';
  
  WriteLog($LogText,'1');
?>
