note 31576 added to ref.session

From: Date: Sat, 26 Apr 2003 19:10:26 +0000
Subject: note 31576 added to ref.session
Groups: php.notes 
Request: Send a blank email to php-notes+get-47145@lists.php.net to get a copy of this message
======================================= Here is script I have been using to authenticate the session and the user //after successful database authentication with username AND password match //get the unique time that this user has logged in at $time_started = md5(mktime()); //encrypt the username and password $secure_session_user = md5($_POST['username'].$_POST['password']); //get the current users username $_SESSION['session_user'] = $_POST['username']; //this session_key will be used to authenticate on every page / getIPADDR() is a function which just return the ip address (I found here on php.net) $_SESSION['session_key'] = $time_started.$secure_session_user.getIPADDR().session_id(); $_SESSION['current_session'] = $_POST['username']."=".$_SESSION['session_key']; //my own function which redirects the user p_redirect("../account/profile_home.php"); //So now we have 3 SESSION vars which we will use for authentication 1. $_SESSION['current_session'] 2. $_SESSION['session_key'] 3. $_SESSION['session_user'] //On every page, we include a file called verify_session.php which has the following code if ($_SESSION['current_session'] != $_SESSION['session_user']."=".$_SESSION['session_key']) header("location:../login/index.php?auth_msg=".urlencode("Your session has expired, please login again")); if ($logout == "logout") { $_SESSION['current_session'] = rand(100,9000000); $_SESSION['curr_sess_iden'] = rand(100,9000000); $_SESSION['session_user'] = "Oscar the Grouch"; $_SESSION['session_key'] = rand(100,9000000); header("location:../login/index.php?auth_msg=".urlencode("You have been logged out")); } //and in our navigation, we have a logout link as simple as <a href="<? $_SERVER['PHP_SELF'] ?>?logout=logout">Logout</a> Hope it helps someone.... -- http://www.php.net/manual/en/ref.session.php http://master.php.net/manage/user-notes.php?action=edit+31576 http://master.php.net/manage/user-notes.php?action=delete+31576 http://master.php.net/manage/user-notes.php?action=reject+31576

« previous php.notes (#47145) next »