note 31576 added to ref.session
| From: | jvilla at isdesigndev dot com | Date: | Sat, 26 Apr 2003 19:10:26 +0000 |
| Subject: | note 31576 added to ref.session | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-47145@lists.php.net to get a copy of this message | ||
=======================================
Here is script I have been using to authenticate the session and the user
//after successful database authentication with username AND password match
//get the unique time that this user has logged in at
$time_started = md5(mktime());
//encrypt the username and password
$secure_session_user = md5($_POST['username'].$_POST['password']);
//get the current users username
$_SESSION['session_user'] = $_POST['username'];
//this session_key will be used to authenticate on every page / getIPADDR() is a function which just
return the ip address (I found here on php.net)
$_SESSION['session_key'] = $time_started.$secure_session_user.getIPADDR().session_id();
$_SESSION['current_session'] =
$_POST['username']."=".$_SESSION['session_key'];
//my own function which redirects the user
p_redirect("../account/profile_home.php");
//So now we have 3 SESSION vars which we will use for authentication
1. $_SESSION['current_session']
2. $_SESSION['session_key']
3. $_SESSION['session_user']
//On every page, we include a file called verify_session.php which has the following code
if ($_SESSION['current_session'] !=
$_SESSION['session_user']."=".$_SESSION['session_key'])
header("location:../login/index.php?auth_msg=".urlencode("Your session has expired,
please login again"));
if ($logout == "logout")
{
$_SESSION['current_session'] = rand(100,9000000);
$_SESSION['curr_sess_iden'] = rand(100,9000000);
$_SESSION['session_user'] = "Oscar the Grouch";
$_SESSION['session_key'] = rand(100,9000000);
header("location:../login/index.php?auth_msg=".urlencode("You have been logged
out"));
}
//and in our navigation, we have a logout link as simple as
<a href="<? $_SERVER['PHP_SELF'] ?>?logout=logout">Logout</a>
Hope it helps someone....
--
http://www.php.net/manual/en/ref.session.php
http://master.php.net/manage/user-notes.php?action=edit+31576
http://master.php.net/manage/user-notes.php?action=delete+31576
http://master.php.net/manage/user-notes.php?action=reject+31576