var oXH = new ActiveXObject("Microsoft.XMLHTTP")
var sURL = "loginhttp.asp"
var sHeader = ""

function urlencode(sStr)
{
	var surlenc = ""
	var stemp = ""
	var stemp1 = ""
	
	stemp = sStr.replace(/\%/g,"%25");
	stemp1 = stemp.replace(/\&/g,"%26");
	surlenc = stemp1.replace(/\ /g,"%20");
	
	return (surlenc);
}

function bdy_onload()
{
	oXH.open("POST", sURL, false);
	oXH.setRequestHeader("Content-Type", "application/x-www-form-urlencoded");
	sHeader = urlencode("ssql=select nID, sDeptName from [Department] order by nID") + "&stype=select";
	oXH.send(sHeader);
	
	spandept.innerHTML = "<select id='seldept' name='seldept' style='font-family:mefont;font-size:11pt;width:200' onchange='seldept_onchange();'>" + oXH.responseText + "</select>";
	
//	seldept_onchange();
	setprevlogin();

	txtpwd.focus();
}

function seldept_onchange()
{
	oXH.open("POST", sURL, false);
	oXH.setRequestHeader("Content-Type", "application/x-www-form-urlencoded");
	sHeader = urlencode("ssql=select PID, sName from [login] where nDept=" + seldept(seldept.selectedIndex).value) + "&stype=select";

	oXH.send(sHeader);

	spanuser.innerHTML = "<select id='seluser' name='seluser' style='font-family:tahoma;font-size:9pt;width:200'>" + oXH.responseText + "</select>";
}

function checkenterkey()
{
	if (window.event.keyCode == 13)
	{
		login_validate();
	}
}

function login_validate()
{
	if (seluser.length == 0){ return false; }

	oXH.open("POST", sURL, false);
	oXH.setRequestHeader("Content-Type", "application/x-www-form-urlencoded");
	sHeader = "uid=" + urlencode(seluser(seluser.selectedIndex).value) + "&pwd=" + urlencode(txtpwd.value) + "&stype=check";
	oXH.send(sHeader);

	if (oXH.responseText == "True")
	{
		oXH.open("POST", sURL, false);
		oXH.setRequestHeader("Content-Type", "application/x-www-form-urlencoded");
		sHeader = "dept=" + urlencode(seldept(seldept.selectedIndex).value) + "&uid=" + urlencode(seluser(seluser.selectedIndex).value) + "&stype=set";
		oXH.send(sHeader);
		
		frmlogin.deptid.value = seldept(seldept.selectedIndex).value;
		frmlogin.uid.value = seluser(seluser.selectedIndex).value;

		frmlogin.submit();
	}
	else
	{
		alert("Invalid Login!");
		txtpwd.value = "";
	}
}

