Re: Password Protection
| From: | Julie Meloni | Date: | Thu, 19 Jul 2001 02:08:48 +0000 |
| Subject: | Re: Password Protection | ||
| References: | 1 | Groups: | php.windows |
| Request: | Send a blank email to php-windows+get-8384@lists.php.net to get a copy of this message | ||
N> <?php
N> $code = mysql_query("SELECT password FROM newsauthors WHERE $name = author");
?>>
You're not extracting a result here, just executing the query
(assuming you have succesfully created the connection to the db at
some other point in your code).
Look up mysql_result() (and others in the family) in the PHP Manual.
N> <?php
N> if ($code = $password) {
When you do extract a result, and you're trying to compare it, you'll
want == and not = to do the comparison.
If you need more information, look under "Operators" in the PHP
Manual.
You might also want to think about not storing plaintext passwords in
your db, but instead hashing the passwords using the password()
function in MySQL, then comparing the hashed input password against
the hash stored in the table.
Mmm...hash.
- Julie
Julie Meloni
julie@thickbook.com
"PHP Essentials" & "PHP Fast & Easy"
--- www.thickbook.com ---