RE: [PHP] Authentication with Sessions

From: Date: Mon, 08 Jan 2001 04:15:04 +0000
Subject: RE: [PHP] Authentication with Sessions
Groups: php.general 
Request: Send a blank email to php-general+get-33176@lists.php.net to get a copy of this message
You will have something like login.php with an html form that asks the user for username and password. The form calls something like processlogin.php, which looks the account up in a database. If it finds it (that is, the username and password combination exists) it creates a session and stores a flag indicating the user has been authenticated. Otherwise, you redirect to the login page. Something like this: if ($row=mysql_fetch_array($query_result) { # The username-password combination has been # found in the database. session_start(); session_register("login"); $login=$query_result["login"]; session_register("flagAuthenticated"); $flagAuthenticated=TRUE; } else { #Bad username-password combination header("Location: http://domain.com/login.php"); exit; } Now, in every page with restricted access, you must make sure the following code executes before any output: session_start(); if (!$flagAuthenticated) { #redirect to login header("Location: http://domain.com/login.php"); exit; } IT'S THAT SIMPLE!!! Just make sure the session id is being propagated in every link and URL request. This is done automatically if enable-trans-sid was used to compile PHP (I think this option is set to TRUE by default so don't mind about it). Still, i strongly suggest you use cookies too. Cheers. >>-----Original Message----- >>From: Roy Wilson, Jr. [mailto:wilson00@mindspring.com] >>Sent: Sunday, 07 January, 2001 4:44 PM >>To: php-general@lists.php.net >>Subject: [PHP] Authentication with Sessions Hello, I'm a pseudo newbie in the PHP world, so bear with me. I'm looking for ideas or general assistance on where to begin with authentication w/sessions. I essentially don't want to store the session in a cookie, but rather keep it with the URL. I can setup the authentication part just fine, it's the session handling that I'm not quite sure about. Any assistance would be grand. Thanks, Roy Wilson, Jr. -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#33176) next »