<?php
session_start();
$_SESSION['loggedin'] = "";
$username = "bugsbunny";
$password = "carrots";
if($_SESSION['loggedin'] == "" || !isset($_SESSION['loggedin'])) {

print '<form action="" method="POST">';
print 'username : <input type="text" name="username"><br/>
       password : <input type="password" name="password"><br/>';
print "<input type='submit' name='sb' id='sb' value='login'>";
print '</form>';
}elseif($_SESSION['loggedin'] != "" || isset($_SESSION['loggedin'])) {

if(isset($_POST['sb'])) {

if($_POST['username'] == "" || $_POST['password'] == "") {

print 'fill into fields';
}else{

if($_POST['username'] == "$username" and $_POST['password'] == "$password") {

print "you're logged in";
//put more protected content here
}
}
}
}
?>
