Classic ASP login flow with Sessions and MSSQL

This tutorial keeps the original Classic ASP/MSSQL login flow—collect credentials, find the user, verify the password, then create Session state—but updates the security guidance.

Legacy warning: the historical version of this tutorial compared a plaintext password inside a concatenated SQL statement. Do not implement authentication that way. Use a parameterized query and a modern password-hashing verifier.

Display the login form

If IsEmpty(Session("userid")) Then %>
<form method="post" action="loginck.asp">
  <input type="text" name="userid" autocomplete="username">
  <input type="password" name="password" autocomplete="current-password">
  <button type="submit">Log in</button>
</form>
<% Else
  Response.Write "You are already signed in."
End If

Read the POST values explicitly

Dim userid, password
userid = Trim(Request.Form("userid"))
password = Request.Form("password")

Use Request.Form for POSTed credentials rather than the combined Request() collection.

Validate the user ID format

Dim RExp : Set RExp = New RegExp
RExp.Pattern = "^[A-Za-z0-9._-]{3,50}$"
If Not RExp.Test(userid) Then
  Response.Write "Invalid user ID format."
  Response.End
End If

Validation controls the allowed user-ID format; it is not the SQL-injection defense. Parameter binding handles data values safely in SQL.

Look up the account with an ADO parameter

Set cmd = Server.CreateObject("ADODB.Command")
Set cmd.ActiveConnection = conn
cmd.CommandText = "SELECT userid, password_hash FROM member WHERE userid = ?"
cmd.CommandType = 1 ' adCmdText
cmd.Parameters.Append cmd.CreateParameter("@userid", 200, 1, 50, userid)
Set rs = cmd.Execute

ADO's Command and CreateParameter() APIs let the provider receive the user ID as data instead of concatenating it into the SQL text.

Verify the password, then create the Session

' After retrieving the user, verify the submitted password with
' a vetted Argon2id/bcrypt/PBKDF2 password-hashing component.
If Not rs.EOF Then
  ' passwordOk = PasswordVerifier.Verify(password, rs("password_hash"))
  If passwordOk Then
    Session("userid") = rs("userid")
    Response.Redirect "mem/index.asp"
  End If
End If

Classic ASP/VBScript does not provide a modern built-in password-hashing API comparable to current frameworks. Use a vetted component/service that supports a password-specific algorithm such as Argon2id, bcrypt or PBKDF2. Do not substitute MD5, SHA-1 or a single fast SHA-256 hash.

Return a generic login failure message so the response does not reveal whether the user ID or password was incorrect. Use HTTPS for all authentication traffic.


ASP Home






✖
We use cookies to improve your browsing experience. . Learn more
HTML MySQL PHP JavaScript ASP Photoshop Articles Contact us
© 2000-2026 plus2net.com All rights reserved worldwide Privacy Policy Disclaimer