session 在此admin_login.jsp 初始化的
<%@ page contentType="text/html;charset=Big5"%>
<%@ page import="java.sql.*,java.io.*,java.lang.*,java.util.*,java.net.*"%>
<jsp:useBean id="weblib" class="weblib.WebLib" scope="session"></jsp:useBean>
<jsp:useBean id="staff" class="staff.Staff" scope="page"></jsp:useBean>
<%
response.setHeader("Cache-Control", "no-cache"

;
response.setHeader("Pragma", "no-cache"

;
response.addDateHeader("Expires", 0);
String stfuname = weblib.checkNull(request.getParameter("stfuname"

);
String passwd = weblib.checkNull(request.getParameter("passwd"

);
String error_msg = weblib.checkNull(request.getParameter("error_msg"

);
stfuname = stfuname.toUpperCase();
if(error_msg.equals("DoNotLogin"

) {
error_msg = "請重新登入!";
}
if(!stfuname.equals(""

&& !passwd.equals(""

) {
if(staff.open_connection()) {
String stf_id = staff.checkPass(stfuname,passwd);
if(!stf_id.equals(""

) {
if(staff.checkPrivi(stf_id,"1"

) {
session.setAttribute("stf_id",stf_id);
response.sendRedirect("item_category.jsp?pass_stf_id="+stf_id);
}
else {
error_msg = "沒有權限!";
}
}
else {
error_msg = "密碼不正確!";
}
}
else {
error_msg = "連接數據庫失敗!";
}
}
%>