RE: [PHP-DB] username/password db query

From: Date: Mon, 01 Oct 2001 08:17:07 +0000
Subject: RE: [PHP-DB] username/password db query
References: 1  Groups: php.db 
Request: Send a blank email to php-db+get-12861@lists.php.net to get a copy of this message
>-----Original Message----- >From: Ross Dmochowski [mailto:rossdmochowski@hotmail.com] >Sent: 01 October 2001 08:04 >To: php-db@lists.php.net >Subject: [PHP-DB] username/password db query > > >Hi. i'm new to PHP, and i can't seem to find out what i'm doing wrong >with the following code: > >client posts username/password via SSL to this file, login.php, >where i want to check the username/password combo against what is listed >in the db >if the entries are blank, it goes to a page that sends email and syslog >alerts about a failed login attempt. >if the entry is bad, it also goes to this badlogin.php >while if it matches, they get cookies set and go to the goodlogin.php > ><?php >$username = $HTTP_POST_VARS['username']; >$password = $HTTP_POST_VARS['password']; >if ($username == "" or $password == "") { >header ("Location: >http://www.some.com/secure/badlogin.php"); >} else { >$db = pg_connect("dbname=some_com user=some_com"); >$query = "SELECT * FROM userinfo"; >$result = pg_exec($db, $query); >$numrows = pg_numrows($result); >}; >do { > $myrow = pg_fetch_row ($result,$row); > if ($username==$myrow[0] && $password==$myrow[2]) { > mt_srand((double)microtime()*1000000); > $random_cookiename = mt_rand(); > $random_cookievalue = mt_rand(); > setcookie ($random_cookiename, $random_cookievalue, time()+900); > setcookie (ClientAddress, $REMOTE_ADDR, time()+900); > pg_close($db); > header ("Location: > https://www.some.com/secure/goodlogin.php"); > } > $row++; > } while($row < $numrows); >pg_close($db); >header ("Location: >http://www.some.com/secure/badlogin.php"); >?> > >the specified user has db rights. >if i put >echo $myrow[0]; >in the loop (and remove the redirect to the badlogin.php file , it will >print out all the users in the db (the first column) >but my comparison operation is not successfully telling when the entered >data properly matches the db entry (is it a datatype problem? the username >is kept in the postgresql db as type char) > >any constructive help would be very appreciated. Why not let the DB do the work? $query = "SELECT * FROM userinfo WHERE username_field='$username' AND password_field='$password'"; $result = pg_exec($db, $query); if (pg_numrows($result)) { DO_SET_COOKIE_STUFF; } else { DO_WRONG_USERNAME_PASSWORD_STUFF; } hth -- Jason Wong Gremlins Associates www.gremlins.com.hk Tel: +852-2573-5033 Fax: +852-2573-5851

« previous php.db (#12861) next »