function wcreate_object()
{
        try{
                obj1=new XMLHttpRequest();
        }

        catch(e)
        {
                try{
                        obj1=new ActiveXObject("MSXML2.XMLHTTP");
                }
                catch(e)
                {
                        obj1=new ActiveXObject("Microsoft.XMLHTTP");
                }
        }
        return obj1;
}


function wdo_login(frm, lang){

    var err = "";
    if (frm){
       if (!frm.UserName.value)
           err += "\n User name";
       if (!frm.Password.value)
           err += "\n Password" ;

       //some error happened
       if (err){
             err = "Please fill in these fields :" + err ;
             alert(err);
             return;
       }

      var myuser = frm.UserName.value ;
      // prepare Xrequest for adding the comment...
      var reqX = wcreate_object();

      if(reqX==null)
              alert("Your browser doesn't support AJAX technology...");
      else{
              url="login.php";
              try{

               var passData = "UserName="+frm.UserName.value+
                               "&Password="+frm.Password.value;

               //url = url;
               document.getElementById("login_div").innerHTML='<img src="images/loader.gif" alt="Please Wait...">';

                 //reqX.setRequestHeader("Content-type", "application/x-www-form-urlencoded");
                 //reqX.setRequestHeader("Content-length", passData.length);
                 //reqX.setRequestHeader("Connection", "close");


              

                reqX.onreadystatechange = function() {
                        try {
                               if (reqX.readyState != 4)  { return; }
                               if (reqX.status != 200)  {   return;   }
                               var serverResponse = reqX.responseText;

                               if(reqX.responseText.indexOf("OK") > -1) {
                                  document.getElementById("login_div").innerHTML="<span class='feelds'>Welcome : "+myuser+"</span>";
                                 // document.getElementById("log_head").innerHTML="<span class='feelds'>"+myuser+" logged in</span>";
                                  //document.getElementById("log_body").innerHTML='<a class="create" href="index.php?page=account&ex=2&lang='+lang+'&dir=users">My account</a><br /><a class="create" href="index.php?page=account&ex=2&lang='+lang+'&dir=users">Logout</a>';

                                  setTimeout( function(){
                                        window.location.href='index.php?page=orders&ex=2&lang='+lang+'&dir=users';
                                         },2000);
                               }
                               else{
                                  setTimeout( function(){
                                       document.getElementById("login_div").innerHTML="<span class='feelds'>Error: Please check user name and password...</span>";
                                         },1000);
                                  setTimeout( function(){
                                       document.getElementById("login_div").innerHTML="";
                                         },4000);
                               }
                        }
                        catch(e)
                        {
                        }
                }
                reqX.open("GET",url+'?'+passData  ,true);
                reqX.send(null);
              }
              catch(e)
              {
                      alert("Error : an error occured while trying to login...\n"+e);
              }

      }

   }


}

