note 28639 added to ref.session
| From: | rafacouto at yahoo dot com | Date: | Sun, 19 Jan 2003 03:33:30 +0000 |
| Subject: | note 28639 added to ref.session | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-42374@lists.php.net to get a copy of this message | ||
This is an useful and transparent PHP include using PHP session module (session_start and
session_register functions). Add "<?php include('sesion.inc.php'); >" in
PHP scripts where you need user authentication. It uses MySQL access to check username and password
(configurable). When user is right (valid user/password or session ok), it runs your normal PHP
script.
.....8<..........8<..........8<..........8<.....
<?php
/* sesion.inc.php
*
* You must include this file (sesion.inc.php) from
* PHP scripts with user autentication:
*
* <?php include('sesion.inc.php'); >
*
* At top of file, without previous white spaces.
* Review configuration and design you own
* form_login() function (view below).
*/
//////////////////////////////////////////////////////////////////////
// Configuration
//////////////////////////////////////////////////////////////////////
// DB access control
$bd_servidor = 'localhost'; // DB server
$bd_esquema = 'xiria'; // DB name
$bd_usuario = 'root'; // DB user
$bd_clave = ''; // DB password
// table structure
$usuarios_tabla = 'usuarios'; // tablename
$usuarios_campo_alias = 'usuario'; // user field
$usuarios_campo_clave = 'clave'; // password field
//////////////////////////////////////////////////////////////////////
// Main program
//////////////////////////////////////////////////////////////////////
// suponemos lo peor
$valido = false;
// comprobamos usuario con sesión ya abierta
session_start();
session_register('sesion_usuario');
session_register('sesion_control');
if ($sesion_control) $valido = (md5(usuario_clave($sesion_usuario)) == $sesion_control);
// comprobamos la identificación por login
if (!$valido && $_POST[clave]) {
if ($valido = (usuario_clave(trim($_POST[usuario])) == $_POST[clave])) {
$sesion_control = md5($_POST[clave]);
$sesion_usuario = trim($_POST[usuario]);
}
}
if ($valido) return; else form_login();
exit;
// consulta a MySQL por la clave de un usuario
function usuario_clave ($usuario) {
global $usuarios_tabla, $usuarios_campo_clave, $usuarios_campo_alias;
global $bd_servidor, $bd_usuario, $bd_clave, $bd_esquema;
mysql_pconnect($bd_servidor, $bd_usuario, $bd_clave);
mysql_select_db($bd_esquema);
$res = mysql_query("SELECT $usuarios_campo_clave FROM $usuarios_tabla WHERE
$usuarios_campo_alias = '$usuario'");
if ($res) list($ret) = mysql_fetch_row($res);
else die(mysql_error());
return $ret;
}
// mostrar pantalla de login
function form_login() {
echo '
<html>
<head><title>Identificar usuario</title></head>
<body>
<form action="?" method="post" name="login">
<table border="0" align="center" cellpadding="4"
cellspacing="4">
<tr>
<td><div align="right">Usuario:</div></td>
<td><input name="usuario" type="text"></td>
</tr>
<tr>
<td><div align="right">Clave:</div></td>
<td><input name="clave" type="password"></td>
</tr>
<tr>
<td colspan="2">
<div align="center"><input name="entrar"
type="submit" value="Entrar"></div>
</td>
</tr>
</table>
</form>
</body>
</html>
';
}
?>
.....8<..........8<..........8<..........8<.....
--
http://www.php.net/manual/en/ref.session.php
http://master.php.net/manage/user-notes.php?action=edit+28639
http://master.php.net/manage/user-notes.php?action=delete+28639
http://master.php.net/manage/user-notes.php?action=reject+28639