note 38713 added to language.operators.bitwise

From: Date: Sun, 04 Jan 2004 15:04:13 +0000
Subject: note 38713 added to language.operators.bitwise
Groups: php.notes 
Request: Send a blank email to php-notes+get-62895@lists.php.net to get a copy of this message
So here's an interesting little thing that I do with bitwise operators, could potentially be useful to others. I have a roles based system which shows, among other things, menu entries based on a users role. The menu entries are stored in a mysql database as are the users and the roles. My users table looks like this: +----------+--------+ | Username | RoleID | +----------+--------+ | admin | 1 | | suser | 2 | | user | 4 | +----------+--------+ My roles table looks like this: +-------------------------------+--------+ | RoleName | RoleID | +-------------------------------+--------+ | System Administrator | 1 | | Super User | 2 | | User | 4 | +-------------------------------+--------+ My menus table looks like this: +-------------------+---------------------+---------+ | Menu_Title | MenuFile | Roles | +-------------------+---------------------+---------+ | Data | Data.php | 7 | | All Data | All_Data.php | 3 | | Shutdown | Shutdown.php | 1 | +-------------------+---------------------+---------+ Now, when the user logs in I run a select to see if they are valid: SELECT * FROM Users WHERE Username = '<USER>' AND Password = '<PW>' If no rows were returned I print an error message and redraw the login screen, otherwise I set some session variables: <?php $row = mysql_fetch_assoc($recordset); $_SESSION['Username'] = $row['Username']; $_SESSION['RoleID'] = $row['RoleID']; ?> In my MainMenu.php I check that a valid user is logged in and if so I generate the menu: <?php if( isset($_SESSION['Username']) && isset($_SESSION['RoleID']) ) { generateMenuEntries($_SESSION['RoleID']); } ?> <?php /********************************************/ /** Generates the menu */ /*******************************************/ function generateMenuEntries( $roleID ) { $menuQuery = sprintf("SELECT * FROM menus WHERE (Roles & %d) = %d", $roleID, $roleID); $menuRecordset = mysql_query($menuQuery, $myConn); while( $menu = mysql_fetch_assoc( $menuRecordset )) { echo ' <tr>'; echo ' <td width="3%">&nbsp;</td> '; echo ' <td width="97%"><a href="'; echo $menu['MenuFile']; echo '">'; echo $items['Menu_Title']; echo '</a></td>'; echo ' </tr>'; } } ?> So the important part of the query is the (Roles & $roleID) = $roleID, that does a bitwise AND function and since only one bit is set in our role the value returned will either be 0 or the $roleID. I know this isn't the most secure way to handle the user/session data but it's sufficient for my needs. I have to be careful when I add roles so that it's 2^whatever. I wish I knew how to change the auto_increment so that it was just a bit shift. I suppose I could use an auto-generated ID field and do a stored procedure that calculates the role as 2^ID. I'll have to look into it. Hope this helps someone. ---- Manual Page -- http://www.php.net/manual/en/language.operators.bitwise.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+38713 Delete -- http://master.php.net/manage/user-notes.php?action=delete+38713&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+38713&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#62895) next »