Re: Sessions 2!!!

From: Date: Mon, 07 Oct 2002 21:39:49 +0000
Subject: Re: Sessions 2!!!
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-119142@lists.php.net to get a copy of this message
So the script below is pasted or is being included at the top of each page? A lot of if statements in there.. you might consider turning some of those into functions to organize your code a bit. Maybe you'll find a loophole or something. -Kevin ----- Original Message ----- From: "Steve Vernon" <steve@extremewattage.co.uk> To: <php-general@lists.php.net> Sent: Monday, October 07, 2002 2:53 PM Subject: [PHP] Sessions 2!!! Hiya, DOn't think I am getting anywhere!!! I have no turned register_globals off and recoding my website, but I cant work out how to do sessions. The following code dosen't keep sessions. Its logs on, but I dosent keep a session on another page. It should either get the post variables with the new username and passwords or validate the session variables and use them. Help! Thanks! session_start(); if(isset($_SESSION['ssun']) || isset($_POST['ssname'])) { //Check if the user name and password are stored in session variables, if not empty them. if(!isset($_SESSION['ssun'])) { echo "Session ssun not set"; $_SESSION['ssun'] = ""; } if(!isset($_SESSION['sspw'])) { echo "Session sspw not set"; $_SESSION['sspw'] = ""; } //Attempt to logon. Set the logon form variables to the session variables. if(isset($_POST['sspass'])) { $_SESSION['sspw'] =$_POST['sspass']; } if(isset($ssname)) { $_SESSION['ssun'] =$_POST['ssname']; } //Make sure no one breaks in, if in the param loggedin was set, unset it. if(isset($loggedin)) { unset($loggedin); } if(isset($_POST['ssname'])) { //Check if the session username and password are correct $result = mysql_query("SELECT userid FROM users WHERE userpassword=PASSWORD('".$_POST['sspass']."') AND userid='".$_POST['ssname']."'", $db_link); } else { //Check if the session username and password are correct $result = mysql_query("SELECT userid FROM users WHERE userpassword=PASSWORD('".$_SESSION['sspw']."') AND userid='".$_SESSION['ssun']."'", $db_link); } $norows = mysql_num_rows($result); if($norows==1) { $loggedin="yes"; } else { $loggedin="no"; } if(isset($logoff)) { if($logoff=="true") { $loggedin="no"; $_SESSION['ssun']=""; $_SESSION['sspw']=""; } } }

« previous php.general (#119142) next »