Re: mysql_trouble (check fast!)

From: Date: Tue, 08 May 2001 22:51:58 +0000
Subject: Re: mysql_trouble (check fast!)
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-51996@lists.php.net to get a copy of this message
Hi Fredrik, Always check whether or not the required variables are there BEFORE querying the database..... And make sure that the negatives are dealt with first. That's my opinion. I'd probably also check whether the original username / password is in the database before proceeding. Probably more work on the db's part than needed, but still. Gotta make sure everything's correct: <? if (!is_set($new_password)) { echo "You haven't assigned a new password. Please go back."; } else { $sql_check = "SELECT id FROM users WHERE username = '$username' AND password = '$password'"; $result_check = @mysql_query($sql_check, $connection) or die ("some graceful error"); if (mysql_num_rows($result_check) == 0) { echo "The username and original password you entered did not match anything in the database. Please go back and try again."; } else { $sql_update = "UPDATE users SET password = '$new_password' WHERE username = '$username'"; $result_update = @mysql_query($sql_update, $connection) or die("Another graceful error."); echo "Your new password has been saved."; } } ?> James. ""FredrikAT"" <ftakle@online.no> wrote in message news:9d9jll$fic$1@toye.p.sourceforge.net... > $na_pw is the active password... > ..if pw is blank or wrong i want to output a error message... > ...iknow that I could do if (empty($na_pw) and $na_pw <> $pw), but then I > would have to send another query to MySQL.. > > I thought that q_updateresult would say (when i echo) 0 when password is > bad, but it echos 1. > > Any tips? > > CODE: > $q_updatequery = "UPDATE brukerinfo SET navn=\"$ny_navn\", tlf=\"$ny_tlf\", > pw=PASSWORD('$ny_pw') WHERE brukerID=\"$id\" and > pw=PASSWORD('$na_pw')\n"; > > $q_updateresult = mysql_db_query ($db, $q_updatequery); > > --------------------------------- > Fredrik A. Takle > fredrik@takle.net > > > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net >

« previous php.general (#51996) next »