<script language="vb" runat="server">
sub page_load(sender as object,e as eventargs)
dim conn as sqlconnection
dim cmd as sqlcommand
dim rd as sqldatareader
dim sql as string
dim i as integer
conn = New SQLConnection(ConfigurationSettings.AppSettings("sqlconn"))
conn.Open()
sql = "select * from userinfo where " & "name='" & User.Identity.Name & "'" & " and grade='3' or " & "name='" & User.Identity.Name & "'" & " and grade='2' "
cmd=new sqlcommand(sql,conn)
rd=cmd.executereader()
if Rd.Read() then
nameview.text=User.Identity.Name
else
response.Redirect("../pass.aspx")
end if
end sub
sub exit1(sender as object,e as ImageClickEventArgs)
Response.Redirect("../pass.aspx")
end sub
sub sendmsg(sender as object,e as ImageClickEventArgs)
If Isvalid then
opendatabase()
response.Redirect("../pass.aspx")
end if
end sub
sub opendatabase()
dim conn as sqlconnection
dim adpt as SqldataAdapter
dim cmd as sqlcommand
dim sql as string
dim upname=User.Identity.Name
Conn = New SQLConnection(ConfigurationSettings.AppSettings("sqlconn"))
Conn.Open()
sql="insert into message (msg,upname) values(@msg,@upname)"
cmd=new sqlcommand(sql,conn)