RE: [PHP] header() ???

From: Date: Wed, 13 Sep 0000 23:48:29 +0000
Subject: RE: [PHP] header() ???
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-16724@lists.php.net to get a copy of this message
Sonia, Almost. Depending upon your programming style, they may ultimately be functionally the same, but with the following differences: Using the header redirect the user will see the URL login.php in the address bar, and any variables passed to or set in your calling script will be flushed (unless specifically passed in the header). In your include() exit() example, the user will see the URL of whatever page is including the file (not login.php) and your login.php script will inherit any variables passed to the script or set prior to the include() statement. Also, I like to check the referrer on the page that processes the login, using include() it would not see login.php and fail. Again, that particular page is a generic script I can use across many sites - once a user is validated (or not) I use header() to redirect them dynamically to where they belong - one user may go to user_main.php, while another belongs on supervisor_main.php, etc. Another neat trick to deal with users that bookmark secured pages is to pass a variable to login.php: if (!isset($PHPSESSID)) { header("Location: login.php?redirect=$PHP_SELF"); } Then after you validate them, you can automagically send them to the page they requested. 8-) The long and short is go ahead and do what you're most comfortable with. I use a ton of includes, many of them conditional, but as a rule when security is even remotely involved, I opt for header() redirect. Have fun! J!M > Jim, > > Thanks a lot for your detailed explanation. > > Is this equivalent to your example: > > if (!isset($PHPSESSID)) { > include "login.php"; > exit(); > } > > In this way, the browser will display the login page and will not continue > process the rest of current page. > > ---Sonia > > -----Original Message----- > From: J!M [mailto:jim@dynamisys-llc.com] > Sent: Wednesday, September 13, 2000 3:33 PM > To: Sonia Tsui; 'php-general@lists.php.net' > Subject: RE: [PHP] header() ??? > > > Sonia, > > I'll jump in with my $.02... > > Say you're checking session_id's or cookies on sensitive pages - > > if (!isset($PHPSESSID)) { > header("Location: login.php"); > } > > *** Queries, sensitive code, etc here. *** > > The header redirect aborts the processing of the current script and > loads up login.php if there is no $PHPSESSID set. Now your user > is sent to the appropriate page to log in to the system. You see, if you > were to simply include("login.php") in the same code block, the page would > continue to process, displaying your login form above the sensitive code > you are trying to protect with the Location: redirect. > > I use multiple checks on many pages, although a user may have > permission to access a script, and they pass the session check, I > only want the script to run if it is passed the proper data that a > query is based upon: > > if (!isset($id)) { > header("Location: products.php"); > } > > This block, used at the top of a product_detail.php page will prevent the > script from executing if the $id variable is not passed, instead > automagically directing the user to the place where they can select an > item. > > I also use headers to redirect the output of several generic scripts I use > across many pages. One case is deleting an item from a database table - I > pass several variables to the script, one being the url I wish to redirect > the user back to, the others involving the query the page will run. I then > dynamically set the header: > > header("Location: $redirect_page?message=$message"); > > This allows me to pass the user to where they best belong, and > provide a meaningful message when they get there. > > I hope this clears up any confusion you still have. > > Have fun- Headers are your friend ;-) > J!M > > In short, headers are your friend ;-) they allow you to protect code by > sending the user somewhere else if they don't pass > Jason, > > I see. So > even if the content of the other page resides on the same server > of the > current page, is it still better to use header()? > > thanks > ---Sonia > > > -----Original Message----- > From: Jason Murray > [mailto:Jason.Murray@melbourneit.com.au] > Sent: Wednesday, September 13, > 2000 10:50 PM > To: 'Sonia Tsui' > Cc: 'php-general@lists.php.net' > > > Subject: RE: [PHP] header() ??? > > > > I checked the book "Professional > PHP Programming" and > > refer to how they use header(): > > > > if > (!authenticateUser($cookie_user, $cookie_passwd)) { > > > header("Location:http://$HTTP_HOST/$DOCROOT/default.htm"¾ôÔŠF[ > Zqû‡©); > > exit(); > > > } > > > > what difference does that make if I do this instead: > > if > (...) { > > include > "http://$HTTP_HOST/$DCROOT/default.htm"); > > > exit(); > > } > > > > I guess my question is really this: header is used > here to > > redirect user to other pages, but is it equivalent of doing > this > > using include in this case? > > If you include it, you are > presenting the contents of the other page as > the current page. > > If > you redirect to it, you are sending the browser to a different page. > > > IMHO you should never include() from http:// anyway, since the > remote > > server may be down or timed out. > > Jason > > -- > PHP General Mailing > List (http://www.php.net/) > To unsubscribe, e-mail: > php-general-unsubscribe@lists.php.net > For additional commands, e-mail: > php-general-help@lists.php.net > To contact the list administrators, > e-mail: php-list-admin@lists.php.net > > > >

« previous php.general (#16724) next »