Dim user As String = e .Form .Controls ( "UserName"). Text
Dim pwd As String = e .Form .Controls ( "PassWord"). Text
Dim dr As DataRow = DataTables ("员工信息" ). Find( "员工姓名 = '" & user & "'") '分开查询,防注入登录
If dr IsNot Nothing Then
pwd = MD5Encrypt ( pwd)
If user = dr ("员工姓名" ) Then
If dr ("员工状态" ) = "在职" Then
If pwd = dr ("员工密码" ) Then
_UserName = dr ("员工姓名" )
_UserLoginName = user
_UserGroup = dr ("公司职位" )
e .Form .Close ()
Else
MessageBox .Show ("输入的账号或密码错误,请重试!" , "提示")
End If
Else
MessageBox .Show ("输入的账号或密码错误,请重试!" , "提示")
End If
Else
MessageBox .Show ("输入的账号或密码错误,请重试!" , "提示")
End If
End If