Re: authentication for lack of a better subject
| From: | Matthew Gallant | Date: | Tue, 18 Jul 2000 10:59:18 +0000 |
| Subject: | Re: authentication for lack of a better subject | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-7053@lists.php.net to get a copy of this message | ||
I store an access level in the user database and look it up when the user
logs in. Then you can block out whole pages of your site like this:
$theuser = $SESSION["userid"];
$result = mysql_query("SELECT * from Users WHERE userid = '$theuser'");
$row = mysql_fetch_array($result);
if ($row["accesslevel"] < 2) {
header("Location: http://www.blahblah.com/ /*or
wherever you want them
to go*/");
die;
}
or you can use a similar if/else to alter what the script outputs.
"eric" <edahnke@istreetlabs.com> wrote in message
news:3973D7D1.2A52BD30@istreetlabs.com...
>
> hi
>
> Suppose buyers and sellers have sensitive information on their
> respective pages throughout a site. How does one keep a buyer or seller
> from typing a "guessed" url and seeing perhaps others pertainent data.
> Not that data itself would be returned , queries wouldn't work etc.
> Rather how do you lock them out of the page period. Session failure or
> something.
>
> I'm running apache, php4 and have sessions enabled through the site,
> mysql, etc. Can you do some type of authentication combining these
> programs? How do you guys skin this cat?
>
>
> cheers.
>
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
>