
public string Login(string userName, string password) {

string customerID;

// params to stored proc

Database data = new Database();

SqlParameter[] prams = {

data.MakeInParam("@username", SqlDbType.VarChar, 25, password),

data.MakeInParam("@password", SqlDbType.VarChar, 25, userName),

data.MakeOutParam("@CustomerID", SqlDbType.VarChar, 25)


// create data object and params

data.RunProc("upAccountLogin", prams); // run the stored procedure

customerID = (string) prams[2].Value; // get the output param value

// if the customer id is an empty string, then the login failed

if (customerID == string.Empty)

return null;


return customerID;



