Hieronder hetgene wat ik gedaan had:
function checklogin($dbconnect) {
if(isset($_SESSION['username']) && isset($_SESSION['password'])) {
$sql = mysql_query("SELECT username, password FROM users WHERE username = '".htmlspecialchars(mysql_real_escape_string($_SESSION['username']))."' AND password = '".htmlspecialchars(mysql_real_escape_string($_SESSION['password']))."' LIMIT 1", $dbconnect) or die("Database error: ".mysql_error()."");
if(mysql_num_rows($sql) == 1) {
echo "<a href=edit.php>Edit/Delete Item</a><br/>";
echo "<a href=add.php>Add Item</a><br/><br/>";
}
else {
return FALSE;
}
}
else {
header("Location: login.php");
}
}