Re: newbie: q on sessions, passwords and loading pages
| From: | Joel Ricker | Date: | Fri, 28 Sep 2001 05:14:11 +0000 |
| Subject: | Re: newbie: q on sessions, passwords and loading pages | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-69119@lists.php.net to get a copy of this message | ||
From: "Jean-Christian Imbeault" <jean_christian@hotmail.com>
: I want to make a login page, and if the login is correct have the main
page
: come up. But the problem I have is, after validating the login how can I
: make PHP open up a new page?
A couple of ways to do this, plus others I'm sure that I'm not covering.
One way to do this would be to send a redirection header after a successful
login, ie, instead of a standard header, you send the status code that says
move to this page instead which would be your other pages or scripts. I
can't remember off the top of my head what the exact codes are and I haven't
played with this route yet. You'll need to learn a little about the
headers() function plus valid HTTP headers.
The other, easier way would be to create the script you'll be sending the
person to after they have logged in successfully. In another file called
say, login.inc, create your usrename and password code. If it doesn't
validate ok, show the prompt again and exit().
Now this file would go at the top of the page you want to show when they
login, using the include("login.inc") command.
The flow would work like this,
Let say the file you want people to login in to see is called
mysecretfile.php.
When php parses mysecretfile.php, it will hit the include('login.inc')
portion. It then fetches that file and plugs that in just as if you had
put the contents of login.inc into mysecretfile.php yourself. If it checks
out, the code flow continues on that point, displaying the rest of the files
contents but if not, like I said it hits the exit() portion and stops right
there.
This is just a basic overview, there is a lot I've left out that you'll find
out as you play with this, especially for starters, storing the login.inc
file outside of the web root to prevent people from seeing that at all.
There is also this link I found at Zend that has some stuff on logins.
Haven't read it yet but I'm sure there will be some things to answer your
questions.
http://www.zend.com/zend/tut/authentication.php
Hope this helps,
Joel