def login
  @title = "Logowanie do RailsSpace"
  if request.post? and params[:user]
    @user = User.new(params[:user])
    user = User.find_by_screen_name_and_password(@user.screen_name,@user.password)
    if user
      session[:user_id] = user.id
      flash[:notice] = "Uytkownik #{user.screen_name} zalogowany!"
      redirect_to :action => "index"
    else
      # Nie pokazuj hasa w widoku
      @user.password = nil
      flash[:notice] = "Nieprawdiowa kombinacja uytkownika/hasa"
    end
  end
end

