Re: Sessions 2!!!
| From: | Kevin Stone | Date: | Mon, 07 Oct 2002 21:39:49 +0000 |
| Subject: | Re: Sessions 2!!! | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-119142@lists.php.net to get a copy of this message | ||
So the script below is pasted or is being included at the top of each page?
A lot of if statements in there.. you might consider turning some of those
into functions to organize your code a bit. Maybe you'll find a loophole or
something.
-Kevin
----- Original Message -----
From: "Steve Vernon" <steve@extremewattage.co.uk>
To: <php-general@lists.php.net>
Sent: Monday, October 07, 2002 2:53 PM
Subject: [PHP] Sessions 2!!!
Hiya,
DOn't think I am getting anywhere!!!
I have no turned register_globals off and recoding my website, but I
cant work out how to do sessions.
The following code dosen't keep sessions. Its logs on, but I dosent keep
a session on another page. It should either get the post variables with the
new username and passwords or validate the session variables and use them.
Help!
Thanks!
session_start();
if(isset($_SESSION['ssun']) || isset($_POST['ssname']))
{
//Check if the user name and password are stored in session variables, if
not empty them.
if(!isset($_SESSION['ssun']))
{
echo "Session ssun not set";
$_SESSION['ssun'] = "";
}
if(!isset($_SESSION['sspw']))
{
echo "Session sspw not set";
$_SESSION['sspw'] = "";
}
//Attempt to logon. Set the logon form variables to the session variables.
if(isset($_POST['sspass']))
{
$_SESSION['sspw'] =$_POST['sspass'];
}
if(isset($ssname))
{
$_SESSION['ssun'] =$_POST['ssname'];
}
//Make sure no one breaks in, if in the param loggedin was set, unset it.
if(isset($loggedin))
{
unset($loggedin);
}
if(isset($_POST['ssname']))
{
//Check if the session username and password are correct
$result = mysql_query("SELECT userid FROM users WHERE
userpassword=PASSWORD('".$_POST['sspass']."') AND
userid='".$_POST['ssname']."'", $db_link);
}
else
{
//Check if the session username and password are correct
$result = mysql_query("SELECT userid FROM users WHERE
userpassword=PASSWORD('".$_SESSION['sspw']."') AND
userid='".$_SESSION['ssun']."'", $db_link);
}
$norows = mysql_num_rows($result);
if($norows==1)
{
$loggedin="yes";
}
else
{
$loggedin="no";
}
if(isset($logoff))
{
if($logoff=="true")
{
$loggedin="no";
$_SESSION['ssun']="";
$_SESSION['sspw']="";
}
}
}