Re: [PHP3] MySQL returns data-set even if where clause doesn't match ???
| From: | (Richard Lynch) | Date: | Fri, 30 Jun 2000 20:43:13 +0000 |
| Subject: | Re: [PHP3] MySQL returns data-set even if where clause doesn't match ??? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-4135@lists.php.net to get a copy of this message | ||
In article <001001bfdad4$414499c0$5164a8c0@stf>, jan@4freedom.de ("Jan
Mussler") wrote:
> $result =3D mysql_query("SELECT acountID,a_pass FROM acounts WHERE =
> (a_firmennummer =3D $firmenid) AND (a_name like '$username');");
If $firmenid is blank, this SQL is invalid, and you are getting into the
clause way below where you set $pw = ''.
*THEN* it should check the MD5 and the non-blank $pw, and return 0...
Not sure why that isn't working, but focus your attention there, or just
return 0 if the $result is 0...
> =20
> if($result)
> {
> if($row =3D mysql_fetch_row($result)) {
> $pw =3D $row[1];
> $id =3D $row[0];
> }
> else {
> return 0; // I think the script should stop here if the $firmid isn't =
> found in any cell, becaue it returns an emtpy set.
> }
> }
> else {
> $pw =3D "";
> }
> =20
> if(!strcmp(md5($userpw),$pw) && $pw !=3D "") {
> return $id;
> }
> else {
> return 0;
> }
> }
--
Richard Lynch | If this was worth $$$ to you, buy a CD
US Customer Support Director | from one of the artists listed here:
Zend Technologies USA | http://www.L-I-E.com/artists.htm
http://www.zend.com | (this has nothing to do with Zend,
duh!)