// [ValidateAntiForgeryToken] public ActionResult Login(User objUser) { int id = u.login(objUser); if (id > 0) { Session["UserId"] = id; Session["UserName"] = objUser.UserName; return(RedirectToAction("Search", "Invoice")); } else if (id == -1) { ViewBag.InvalidMessage = "Invalid username or password"; } else { ViewBag.WrongMessage = "Wrong username or password"; } return(View(objUser)); }