Re: authentication for lack of a better subject

From: Date: Tue, 18 Jul 2000 10:59:18 +0000
Subject: Re: authentication for lack of a better subject
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-7053@lists.php.net to get a copy of this message
I store an access level in the user database and look it up when the user logs in. Then you can block out whole pages of your site like this: $theuser = $SESSION["userid"]; $result = mysql_query("SELECT * from Users WHERE userid = '$theuser'"); $row = mysql_fetch_array($result); if ($row["accesslevel"] < 2) { header("Location: http://www.blahblah.com/ /*or wherever you want them to go*/"); die; } or you can use a similar if/else to alter what the script outputs. "eric" <edahnke@istreetlabs.com> wrote in message news:3973D7D1.2A52BD30@istreetlabs.com... > > hi > > Suppose buyers and sellers have sensitive information on their > respective pages throughout a site. How does one keep a buyer or seller > from typing a "guessed" url and seeing perhaps others pertainent data. > Not that data itself would be returned , queries wouldn't work etc. > Rather how do you lock them out of the page period. Session failure or > something. > > I'm running apache, php4 and have sessions enabled through the site, > mysql, etc. Can you do some type of authentication combining these > programs? How do you guys skin this cat? > > > cheers. > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net >

« previous php.general (#7053) next »