RE: [PHP] Authentication with Sessions
| From: | Diego Fulgueira | Date: | Mon, 08 Jan 2001 04:15:04 +0000 |
| Subject: | RE: [PHP] Authentication with Sessions | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-33176@lists.php.net to get a copy of this message | ||
You will have something like login.php with an html form that asks the user
for username and password. The form calls something like processlogin.php,
which looks the account up in a database. If it finds it (that is, the
username and password combination exists) it creates a session and stores a
flag indicating the user has been authenticated. Otherwise, you redirect to
the login page. Something like this:
if ($row=mysql_fetch_array($query_result) {
# The username-password combination has been
# found in the database.
session_start();
session_register("login");
$login=$query_result["login"];
session_register("flagAuthenticated"); $flagAuthenticated=TRUE;
} else {
#Bad username-password combination
header("Location: http://domain.com/login.php");
exit;
}
Now, in every page with restricted access, you must make sure the following
code executes before any output:
session_start();
if (!$flagAuthenticated) {
#redirect to login
header("Location: http://domain.com/login.php");
exit;
}
IT'S THAT SIMPLE!!!
Just make sure the session id is being propagated in every link and URL
request. This is done automatically if enable-trans-sid was used to compile
PHP (I think this option is set to TRUE by default so don't mind about it).
Still, i strongly suggest you use cookies too.
Cheers.
>>-----Original Message-----
>>From: Roy Wilson, Jr. [mailto:wilson00@mindspring.com]
>>Sent: Sunday, 07 January, 2001 4:44 PM
>>To: php-general@lists.php.net
>>Subject: [PHP] Authentication with Sessions
Hello,
I'm a pseudo newbie in the PHP world, so bear with me. I'm looking for
ideas or general assistance on where to begin with authentication
w/sessions.
I essentially don't want to store the session in a cookie, but rather keep
it with the URL.
I can setup the authentication part just fine, it's the session handling
that I'm not quite sure about. Any assistance would be grand.
Thanks,
Roy Wilson, Jr.
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net