RE: [PHP-DB] username/password db query
| From: | Jason Wong | Date: | Mon, 01 Oct 2001 08:17:07 +0000 |
| Subject: | RE: [PHP-DB] username/password db query | ||
| References: | 1 | Groups: | php.db |
| Request: | Send a blank email to php-db+get-12861@lists.php.net to get a copy of this message | ||
>-----Original Message-----
>From: Ross Dmochowski [mailto:rossdmochowski@hotmail.com]
>Sent: 01 October 2001 08:04
>To: php-db@lists.php.net
>Subject: [PHP-DB] username/password db query
>
>
>Hi. i'm new to PHP, and i can't seem to find out what i'm doing wrong
>with the following code:
>
>client posts username/password via SSL to this file, login.php,
>where i want to check the username/password combo against what is listed
>in the db
>if the entries are blank, it goes to a page that sends email and syslog
>alerts about a failed login attempt.
>if the entry is bad, it also goes to this badlogin.php
>while if it matches, they get cookies set and go to the goodlogin.php
>
><?php
>$username = $HTTP_POST_VARS['username'];
>$password = $HTTP_POST_VARS['password'];
>if ($username == "" or $password == "") {
>header ("Location:
>http://www.some.com/secure/badlogin.php");
>} else {
>$db = pg_connect("dbname=some_com user=some_com");
>$query = "SELECT * FROM userinfo";
>$result = pg_exec($db, $query);
>$numrows = pg_numrows($result);
>};
>do {
> $myrow = pg_fetch_row ($result,$row);
> if ($username==$myrow[0] && $password==$myrow[2]) {
> mt_srand((double)microtime()*1000000);
> $random_cookiename = mt_rand();
> $random_cookievalue = mt_rand();
> setcookie ($random_cookiename, $random_cookievalue, time()+900);
> setcookie (ClientAddress, $REMOTE_ADDR, time()+900);
> pg_close($db);
> header ("Location:
> https://www.some.com/secure/goodlogin.php");
> }
> $row++;
> } while($row < $numrows);
>pg_close($db);
>header ("Location:
>http://www.some.com/secure/badlogin.php");
>?>
>
>the specified user has db rights.
>if i put
>echo $myrow[0];
>in the loop (and remove the redirect to the badlogin.php file , it will
>print out all the users in the db (the first column)
>but my comparison operation is not successfully telling when the entered
>data properly matches the db entry (is it a datatype problem? the username
>is kept in the postgresql db as type char)
>
>any constructive help would be very appreciated.
Why not let the DB do the work?
$query = "SELECT * FROM userinfo WHERE username_field='$username' AND
password_field='$password'";
$result = pg_exec($db, $query);
if (pg_numrows($result)) {
DO_SET_COOKIE_STUFF; }
else {
DO_WRONG_USERNAME_PASSWORD_STUFF;
}
hth
--
Jason Wong
Gremlins Associates
www.gremlins.com.hk
Tel: +852-2573-5033
Fax: +852-2573-5851