Re: Restricted site area access
| From: | Michael & Michele Dean | Date: | Thu, 01 Jun 2000 12:43:45 +0000 |
| Subject: | Re: Restricted site area access | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-787@lists.php.net to get a copy of this message | ||
Tom Carter wrote:
> My question really is a fundamental PHP/MySQL one. My first thought was to
> store all the usernames and passwords in a (MySQL) table with a field for
> userlevel. Point of concern with this was how safe would it be?
> Also, assuming these users all logged in from the same point in the site,
> how would one/how easy is it to keep track of which one of the 5 levels
> (public, UL 1-4) the user is at and make the page display accordingly (or
> not as the case may be). My first two immediate ideas was some use of
> cookies, or passing some variable between pages (session ID)
>
Hi, Tom!
We use this very mechanism in our Open Source project Double Choco Latte.
You
can snag the source (CVS would be preferred) from
http://sourceforge.net/project/?group_id=1424
Take a look at login.php3 and for examples on the use of dynamically
generating pages
based on access level, look at htmlWorkorders.php3, htmlCommon.php3,
listmenu.php3,
or just grep for "SEC" on the whole group. We change business rules and
presentation
both based on security level.
Hope that helps!
Mike