<?php
session_start();
include 'db.php';
if($_SERVER['REQUEST_METHOD'] === 'POST'){
  $username = $_POST['username'];
  $password = $_POST['password'];
  $stmt = $conn->prepare("SELECT password, avatar, access FROM users WHERE username = ?");
  $stmt->bind_param("s", $username);
  $stmt->execute();
  $stmt->bind_result($hashed, $avatar, $access);
  if($stmt->fetch()){
    if(password_verify($password, $hashed)){
      $_SESSION['username'] = $username;
      $_SESSION['avatar'] = basename($avatar);
      $_SESSION['access'] = $access;
      header("Location: index.php");
      exit();
    } else { $_SESSION['error'] = "Неверный пароль."; header("Location: index.php"); exit(); }
  } else { $_SESSION['error'] = "Пользователь не найден."; header("Location: index.php"); exit(); }
  $stmt->close();
}
?>
