Re: [PHP3] MySQL returns data-set even if where clause doesn't match ???

From: Date: Fri, 30 Jun 2000 20:43:13 +0000
Subject: Re: [PHP3] MySQL returns data-set even if where clause doesn't match ???
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-4135@lists.php.net to get a copy of this message
In article <001001bfdad4$414499c0$5164a8c0@stf>, jan@4freedom.de ("Jan Mussler") wrote: > $result =3D mysql_query("SELECT acountID,a_pass FROM acounts WHERE = > (a_firmennummer =3D $firmenid) AND (a_name like '$username');"); If $firmenid is blank, this SQL is invalid, and you are getting into the clause way below where you set $pw = ''. *THEN* it should check the MD5 and the non-blank $pw, and return 0... Not sure why that isn't working, but focus your attention there, or just return 0 if the $result is 0... > =20 > if($result) > { > if($row =3D mysql_fetch_row($result)) { > $pw =3D $row[1]; > $id =3D $row[0]; > } > else { > return 0; // I think the script should stop here if the $firmid isn't = > found in any cell, becaue it returns an emtpy set. > } > } > else { > $pw =3D ""; > } > =20 > if(!strcmp(md5($userpw),$pw) && $pw !=3D "") { > return $id; > } > else { > return 0; > } > } -- Richard Lynch | If this was worth $$$ to you, buy a CD US Customer Support Director | from one of the artists listed here: Zend Technologies USA | http://www.L-I-E.com/artists.htm http://www.zend.com | (this has nothing to do with Zend, duh!)

« previous php.general (#4135) next »