<!--#include file="conn.asp"-->
<%
if session("username")<>"admin" then
response.write "<script>alert('您不是系統管理員,沒有此許可權!');history.back()</script>"
session("passed")=false
else
%>
<html>
<head>
<title>使用者修改</title>
</head>
<body>
<%
dim uid
uid=request.querystring("userid")
sql="select * from users where id=" & uid
'定義recordset對象
set rs=server.createobject("adodb.recordset")
rs.open sql,conn,1,3
if rs.eof then
response.write ("<h2>不存在此使用者名稱!</h2>")
else
%>
<form method="post" action="usersave.asp" name=myform onsubmit="return chkfield()">
<p align="center">使用者基本資料</p>
<br><br><br>
<center>
<table border="0" width="371" id="table1">
<tr>
<td bgcolor="#c0c0c0" width="97" align="center">
<font size="2">用 戶 名:</font>
</td>
<td width="260">
<%=rs("username")%>
<input type=hidden name=userid value=<%=rs("id")%>>
</td>
</tr>
<tr>
<td bgcolor="#c0c0c0" width="97" align="center">
<font size="2">使用者姓名:</font>
</td>
<td width="260">
<input type=text name=ename size=20 value="<%=rs("ename")%>">
</td>
</tr>
<tr>
<td bgcolor="#c0c0c0" width="97" align="center">
<font size="2">電子郵箱:</font>
</td>
<td width="260">
<input type=text name=email size=20 value="<%=rs("email")%>">
</td>
</tr>
</table>
</center>
<p align="center">
<input type="submit" value="提交" name="b1">
<input type="reset" value="重設" name="b2">
</p>
</form>
<%end if%>
</body>
</html>
<%
end if
%>
處理檔案
<!--#include file= "chkpwd.asp"-->
<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=gb2312">
<title>使用者管理</title>
</head>
<body>
<%
userid = request.querystring("userid")
oripwd = request.form("oripwd")
pwd = request.form("pwd")
'判斷是否存在此使用者
set rs = server.createobject("adodb.recordset")
'sql = "select * from users where id = '"&userid&"'"
'rs.open sql,conn,1,1
rs.open "select * from users where id="&userid,conn,1,3
if rs.eof then
response.write("<hr><center>不存在此使用者名稱!</h2><br><br><br>")
response.write("<input type = button name = close onclick = window.close() value = 關閉>")
elseif (rs("userpwd")<>md5(oripwd)) then
response.write("<hr><center>密碼錯誤!</h2><br><br><br>")
response.write("<input type = button name = close onclick = window.close() value = 關閉>")
else
sql = "update users set userpwd= '"&md5(trim(pwd))&"' where id = "&userid
set rs = server.createobject("adodb.recordset")
rs.open sql,conn,1,3
response.write("<hr><center>更改密碼成功!</h2><br><br><br>")
response.write("<input type = button name = close onclick = window.close() value = 關閉>")
end if
%>
</body>
</html>