prepare("SELECT password FROM users WHERE username = ?"); $stmt->bind_param("s", $username); $stmt->execute(); $stmt->bind_result($password_db); $stmt->fetch(); $stmt->close(); if ($password_db === $password) { // Plaintext for now, can hash later $_SESSION['authenticated'] = true; $_SESSION['username'] = $username; header("Location: pin.php"); exit(); } else { $error = "Invalid username or password."; } } else { $error = "Please fill in both fields."; } } ?>