Re: mysql_trouble (check fast!)
| From: | James, Yz | Date: | Tue, 08 May 2001 22:51:58 +0000 |
| Subject: | Re: mysql_trouble (check fast!) | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-51996@lists.php.net to get a copy of this message | ||
Hi Fredrik,
Always check whether or not the required variables are there BEFORE querying
the database..... And make sure that the negatives are dealt with first.
That's my opinion. I'd probably also check whether the original username /
password is in the database before proceeding. Probably more work on the
db's part than needed, but still. Gotta make sure everything's correct:
<?
if (!is_set($new_password)) {
echo "You haven't assigned a new password. Please go back.";
} else {
$sql_check = "SELECT id FROM users WHERE username = '$username' AND
password = '$password'";
$result_check = @mysql_query($sql_check, $connection)
or die ("some graceful error");
if (mysql_num_rows($result_check) == 0) {
echo "The username and original password you entered did not match
anything in the database. Please go back and try again.";
} else {
$sql_update = "UPDATE users SET
password = '$new_password'
WHERE username = '$username'";
$result_update = @mysql_query($sql_update, $connection)
or die("Another graceful error.");
echo "Your new password has been saved.";
}
}
?>
James.
""FredrikAT"" <ftakle@online.no> wrote in message
news:9d9jll$fic$1@toye.p.sourceforge.net...
> $na_pw is the active password...
> ..if pw is blank or wrong i want to output a error message...
> ...iknow that I could do if (empty($na_pw) and $na_pw <> $pw), but then I
> would have to send another query to MySQL..
>
> I thought that q_updateresult would say (when i echo) 0 when password is
> bad, but it echos 1.
>
> Any tips?
>
> CODE:
> $q_updatequery = "UPDATE brukerinfo SET navn=\"$ny_navn\",
tlf=\"$ny_tlf\",
> pw=PASSWORD('$ny_pw') WHERE brukerID=\"$id\" and
> pw=PASSWORD('$na_pw')\n";
>
> $q_updateresult = mysql_db_query ($db, $q_updatequery);
>
> ---------------------------------
> Fredrik A. Takle
> fredrik@takle.net
>
>
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>