%Response.CacheControl = "Private"
response.expires=0
set rsparam=conn.execute("select * from param")
sUserName=trdb(left(request("username"),10))
sPass=request("spass")
sPass=trPass(sPass)
sErrText=""
sql="SELECT username,passwd,user_level,saved FROM user WHERE username='"&sUserName&"'"
set rs=conn.Execute(sql)
if rs.bof or rs.eof then
sErrText="
执行错误:用户名尚未注册!"
elseif rs("saved") or rs("user_level")=rsparam("superlevel") then
sErrText="
执行错误:用户名为保留帐号,不能自杀!"
else
if rs("passwd")=sPass then
conn.Execute("DELETE FROM user WHERE username='"&sUserName&"'")
sErrText="操作成功:你成功地删除了用户"&sUserName&"!"
else
sErrText="
执行错误:你输入了错误的密码!"
end if
end if
call echoerr(sErrText,"default.asp")%>
<%rsparam.close
set rsparam=nothing
conn.close
set conn=nothing%>