note 31955 deleted from function.setcookie by alindeman
| From: | alindeman@php.net | Date: | Sat, 10 May 2003 01:40:50 +0000 |
| Subject: | note 31955 deleted from function.setcookie by alindeman | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-47807@lists.php.net to get a copy of this message | ||
I'm trying to delete cookies from the browser. I have the cookies being created when you log
into the web site. They store the login information. When you click the log out button, it deletes
the cookies. The problem: I have the cookie checking being done in the site header, if the cookie
exists and checks against the user information in the database correctly, then you are logged in,
otherwise you are logged out. Since the check is being done in the header, if you log out and go to
a sub-directory, the cookie does not appear to be deleted unless you refresh the page. Is there a
way around this?
Login.php
<?
$UserName=$HTTP_POST_VARS["UserName"];
$Password=$HTTP_POST_VARS["Password"];
$QueryLogin = "select UserID From tbl_Users where UserName='$UserName' and
Password='$Password'";
$RecordsetLogin = mysql_query($QueryLogin, $dbh);
$SQLRecordsetLogin = mysql_fetch_array($RecordsetLogin);
$RedirectPageTrue="/indexa.php?Complete=true";
$RedirectPageFalse="/indexa.php?Complete=false";
if ($SQLRecordsetLogin[UserID]=="") {
Header("Location: $RedirectPageFalse");
}else{
$UserID=$SQLRecordsetLogin[UserID];
setcookie ("UserName", $UserName,time()+60*60*24*365,"/");
setcookie ("Password", $Password,time()+60*60*24*365,"/");
setcookie ("UserID", $UserID,time()+60*60*24*365,"/");
Header("Location: $RedirectPageTrue");
}
?>
Header check, in header.php
<?
if ($HTTP_COOKIE_VARS["UserID"]=="") {
$LoggedIn="false";
}else{
$UserID=$HTTP_COOKIE_VARS["UserID"];
$UserName=$HTTP_COOKIE_VARS["UserName"];
$Password=$HTTP_COOKIE_VARS["Password"];
$QueryUserInfo = "select * From tbl_Users where UserName='$UserName' and
Password='$Password' and UserID='$UserID'";
$RecordsetUserInfo = mysql_query($QueryUserInfo, $dbh);
$SQLRecordsetUserInfo = mysql_fetch_array($RecordsetUserInfo);
if ($SQLRecordsetUserInfo[UserID]=="") {
$LoggedIn="false";
}else{
$SQLUserID=$SQLRecordsetUserInfo[UserID];
$LoggedIn="true";
}}
?>
logout.php
<?
$RedirectPageTrue="/indexa.php?Complete=true";
setcookie ('Password', ' ', (time () - 2592000), '/', '',
0);
setcookie ('UserName', ' ', (time () - 2592000), '/', '',
0);
setcookie ('UserID', ' ', (time () - 2592000), '/', '', 0);
Header("Location: $RedirectPageTrue");
?>
Any answers to this question are greatly helpful.