using cookies
| From: | LDL Enterprise | Date: | Tue, 08 Aug 2000 17:17:52 +0000 |
| Subject: | using cookies | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-10741@lists.php.net to get a copy of this message | ||
What I need is to track that login with a cookie set to expire in an
hour so if the users goes to the resources page and does not have a valid
cookie then it would deny access. The problem I think I am having is for
some reason the setcookie fuction is not working. I cannot get it to write
any cookie at all. Or something else is tweaked. I am very new at this. This
is what I have so far.
login script
<?php
$db = mysql_connect("localhost", "$adminuser", "$adminpass");
mysql_select_db("$mydatabase",$db);
if( $submit ) {
$userquery = mysql_query("SELECT * from users where
username=$username");
$recordset = mysql_fetch_array($userquery);
$pass = $recordset["password"];
if(strcmp($password,$pass)) {
$expire = time( ) + 60 * 30/* minutes idle */;
mysql_query("INSERT INTO current_session (userid, id, expire)
values($username, $username, $expire )");
setcookie ("sessioncookie",$usernmame,$expire);
echo "Logging in $username! <META HTTP-EQUIV=Refresh
content=1;URL=resources.php>";
} else {
echo "Login failed<META HTTP-EQUIV=Refresh content=1;URL=login.php>";
} }
?>
this is the script to validate if they have logged in which should be
entered into any page that needs to be validated.
if(!$sessioncookie) {
echo "no login information. direct to login.php";
exit;
}
$conn = mysql_connect("localhost", "$adminuser",
"$adminpass");
$db = mysql_select_db( "$mydatabase", $conn );
$sessionquery = mysql_query( "SELECT * FROM current_session
WHERE
userid ='$sessioncookie'" );
if( !$sessionquery ) {
setcookie ("sessioncookie", a);
header( "Location: login.php?msg=Session expired" );
exit;
}
$recordset = mysql_fetch_array( $sessionquery );
if( $recordset[ 'expire' ] <= time( ) ) {
setcookie( "sessioncookie", a );
header( "Location: login.php?msg=Session expired" );
exit;
}
$expire = time + 60 * 30/* minutes idle */;
mysql_query( "UPDATE current_session SET expire=$expire WHERE
userid='$sessioncookie'" );
// ... and go ahead on loading the page ;-)
?>
Thanks for any advice you may lend.