  1. Have this:

    $page = $_SERVER['PHP_SELF'];
    $_SESSION['page_check'] = $page;

    on login.php


    and on the process page, have something like this:

    if($_SESSION['page_check'] == "login.php") {
       // Proceed
    else {
       // Fail - Display an error message

  2. Let's say you wanted to log a user out after 10 minutes. Create a new function named whatever you want, and a new column in the table named something like last_activity and set the type to timestamp. In the function, use strtotime to check when the user was last active, and if that was more than 10 minutes ago, unset the session for that user. Put the function in a file, and include/require that for every secure page.


