using System; using System.Collections; using System.Configuration; using System.Data; using System.Linq; using System.Web; using System.Web.Security; using System.Web.UI; using System.Web.UI.HtmlControls; using System.Web.UI.WebControls; using System.Web.UI.WebControls.WebParts; using System.Xml.Linq; public partial class Default2 : System.Web.UI.Page { protected void Page_Load(object sender, EventArgs e) { } protected void register_Click(object sender, EventArgs e) { SqlConnection MyConnection = new SqlConnection(ConfigurationManager.ConnectionStrings["EPCDBConn"].ToString()); string myInsert = "INSERT INTO Users (User_name,User_passowrd,Email) values (@User_Name,@User_Pass ,@User_Email)"; MyConnection.Open(); SqlCommand myCommand = new SqlCommand(myInsert, MyConnection); myCommand.Parameters.AddWithValue("@User_Name", txtUsername.Text); myCommand.Parameters.AddWithValue("@User_Pass", txtPassword.Text); myCommand.Parameters.AddWithValue("@User_Email", User_Email.Text); myCommand.ExecuteNonQuery(); MyConnection.Close(); } protected void btnLogin_Click(object sender, EventArgs e) { SqlConnection MyConnection = new SqlConnection(ConfigurationManager.ConnectionStrings["EPCDBConn"].ToString()); if (MyConnection.State == ConnectionState.Closed) MyConnection.Open(); SqlCommand myCommand = new SqlCommand(); myCommand.CommandText = "select * from Users where User_name = '" + txtUsername.Text + "' AND User_passowrd ='" + txtPassword.Text + "'"; myCommand.Connection = MyConnection; object result = myCommand.ExecuteScalar(); if (result == null) { Label3.Visible = true; Label3.Text = "يجب التسجيل"; Response.Redirect("register.aspx"); } else { Session("User_name") = txtUsername.Text; Response.Redirect("Home.aspx"); } if (MyConnection.State == ConnectionState.Open) { MyConnection.Close(); } } }