real_escape_string($_POST["email"])); $result = $mysqli->query($sql); $user = $result->fetch_assoc(); if ($user) { if ($_POST["password"]==$user["password_hash"]) { // if (password_verify($_POST["password"], $user["password_hash"])) { session_start(); session_regenerate_id(); $_SESSION["user_id"] = $user["id"]; header("Location: index.php"); exit; } } $is_invalid = true; } ?>