Re: Re: Another sessions question
| From: | Scott Fletcher | Date: | Wed, 30 Apr 2003 15:38:45 +0000 |
| Subject: | Re: Re: Another sessions question | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-145793@lists.php.net to get a copy of this message | ||
For the status bar, I can use the '#" in the "<a href='#'
onclick='redirect()'>" and that prevent the displaying of the link path in
the status bar. But, with the file path instead of the '#', there is one
workaround to it which is by using javascript. Like this,
"window.status='';" but the problem is two thing, one, some browsers don't
support this or javascript not turned on. The 2nd problem is if there
problem with other javascript codes not related to this then this would be
broken (broken javascript). It's not a perfect world here. I agree that it
is bad to see the display of the link info in the "< a href='whatever'>"
on
the status bar. There is no other workaround I know of. But if the data is
assigned to the $_SESSION before getting to the next webpage then you won't
have to worry about the variable strings after the file name in the link
because you won't be needing to include it and it would already be included
in the session. For me, it is impossible to make this 100% variable free in
the link because I use the Animate Menu which require the variable in the
link. Like "test1.php?status=view" or "test1.php?status=update", etc...
If you want to hide the sesison id from showing up in the link, then you can
use the trans id. That way, it won't show up in the 'a href' links. You
can find more information about it on PHP.net. I do hear that people
sometime have problem with it so I didn't try it. I stick to using hte
session id in the links so I can have the security script to check for it
and match it.
As for registration and updating of the user profile.... The only thing
everyone need to know is to use session_start() at the very top of the
script before any of the session variable is being used. It work pretty
well for me but I do have one problem which is because of the bug in
Internet Explorer itself. That is when I have more than 1 Internet Explorer
browser running, different machiens, different people, then the session id
get mixed up or corrupted. When that happen, the end user become a
different person to the website. So, I had to use the database to keep
track of the session and use security check to kick out the user if the
session id don't match and the user would have to log in to use it. True
enough, I have a couple of customers calling me about the problem with being
kicked off of the website, so I explained to them about the problem with
Internet Explorer bugs and that Microsoft is slow to fix it, in most cases,
it never get fixed and that I was forced to use the security feature becuase
the website is a credit bureau.
FletchSOD....
P.S. Your other option could be like instead of the variable, $error or
$error[], whatever you're using. Use something like an id number of some
sort, like '$status=1;'. Then have the $_SESSION to use the id number to
grab the error message. Like assigning the error message to
$_SESSION['error'] and create a id number and assign it to
$_SESSION['code_id'] then on the next webpage, use something like $data =
$_SESSION['code_id'] then somehow use it with error in $_SESSION... My
understanding is that $_SESSION is a form of array when you have more than
one variables assigned to it. But dual array, to my knowledge, there is no
feature like this...
"C.R." <odcs@rogers.com> wrote in message
news:001601c30ff1$d9ad3cd0$6401a8c0@p1...
> The login part is not my real concern, as I am now using plain variables
for
> the error messages, but the registration and updating of the user profile
is
> still a problem. Also. When sending a variable through the url
> (http://www.server.com?error=Biteme) is there a way to hide this so it
> doesn't show up in the status bar - this looks really cheesy to have all
the
> error messages appear when the user is being redirected to another page.
> This is one other reason I liked sessions. I don't notice this on other
> sites I have looked at that have forms, so they must be doing this
> differently as well.
>
> TIA
>
>
> ----- Original Message -----
> From: "Scott Fletcher" <scott@abcoa.com>
> To: <php-general@lists.php.net>
> Sent: Wednesday, April 30, 2003 10:13 AM
> Subject: [PHP] Re: Another sessions question
>
>
> > There is other method of error checking for the login feature only.
What
> I
> > do is I don't create a session, instead what I do is to display the html
> > login form. When the user submit it, the webpage reload by itself upon
> > submit by using $PHP_SELF in the action attribute. This is when I
receive
> > the user id and password then I run the database query to see if there
is
> a
> > match or not. Well, I'm using database because of lot of information on
> hte
> > website require the use of the database, so since I have it, so I use it
> > anyway. If there is no match then I use the header() to move the
webpage
> > back to the login page with a failed message. If there is a match, then
I
> > create a session before using hte header() to direct the user to a
> different
> > webpage. This amke it possible for me to put most of the database info
> into
> > the session before going to the next webpage...
> >
> > As for the error session, I'll leave that open to interpretation.
> >
> > FletchSOD
> >
> > "C.R." <odcs@rogers.com> wrote in message
> > news:000801c30f9d$c4f50560$6401a8c0@p1...
> > > I have a login, registration, update, and a form if you forget your
> > > password. I am using sessions to control the login and error messages.
> So
> > > this is my problem
> > >
> > > When a user enters the login page a session is started, if the user
> enters
> > > the wrong login info they will get an error message which is set in a
> > > session variable called $error['whatever'] (this will change depending
> on
> > > the error). If the user then decides he should register first, and
goes
> to
> > > the register page - he gets a message on the page that simply says
> > 'Array'.
> > > This is because the session is still active and $error['whatever'] is
> > still
> > > set, although I've cleared the array with - $error = array(); On each
> > page
> > > I have something like if($error) { echo $error['whatever']; }. I have
> used
> > > done it this way to make things more uniform and understandable, but I
> may
> > > also have shot myself in the foot - is there a way to get around this
> > > without having to change the session variables for each of these
pages.
> > >
> > > I hope I have explained this properly, or for that matter used
sessions
> > > properly - I am still trying to learn about sessions and problems like
> > this
> > > keep popping up.
> > >
> > > TIA
> > >
> > >
> >
> >
> >
> > --
> > PHP General Mailing List (http://www.php.net/)
> > To unsubscribe, visit: http://www.php.net/unsub.php
> >
> >
>
>