note 62389 deleted from ref.session by didou
| From: | didou@php.net | Date: | Sun, 23 Apr 2006 22:56:09 +0000 |
| Subject: | note 62389 deleted from ref.session by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-109241@lists.php.net to get a copy of this message | ||
Note Submitter: tm2183 at yahoo dot com
----
Heres some quick code using sessions. i have my register globals set to off. hope this helps.
<?php
// name your input field as 'user' and 'pass'
// put this on top of every page you want to have password authentication
if (!empty($_POST['user'])) { $user = $_POST['user']; } else { $user =
""; }
if (!empty($_POST['pass'])) { $pass = md5(trim($_POST['pass'])); } else { $pass
= ""; }
if (!isset($_SESSION['user']) && !isset($_SESSION['pass']) ) {
$_SESSION['user'] = $user;
$_SESSION['pass'] = $pass;
}
else if(isset($_SESSION['user']) && isset($_SESSION['pass'])) {
if (!empty($_POST['user']) && !empty($_POST['pass'])) {
$_SESSION['user'] = $user;
$_SESSION['pass'] = $pass;
} else {
$user = $_SESSION['user'];
$pass = $_SESSION['pass'];
}
}
$sql_authen = "SELECT * FROM users WHERE username = '$user' AND password =
'$pass'";
$result = @mysql_query($sql_authen, $link);
$row_exist = mysql_num_rows($result);
if($row_exist <= 0) {
//password failed. put content if user fails authentication.
} else {
//if password and name matched put content here.
}
?>