dean7 Posted March 6, 2009 Share Posted March 6, 2009 Hi, thanks for veiwing this topic but i have a login and register page all up and working. Login.php <HTML> <HEAD> <TITLE>Login</TITLE> <style type="text/css"> <!-- @import url("default.css"); --> </style> </HEAD> <BODY> <? include("header.tpl"); ?> <? /** * Checks whether or not the given username is in the * database, if so it checks if the given password is * the same password in the database for that user. * If the user doesn't exist or if the passwords don't * match up, it returns an error code (1 or 2). * On success it returns 0. */ function confirmUser($username, $password){ global $conn; /* Add slashes if necessary (for query) */ if(!get_magic_quotes_gpc()) { $username = addslashes($username); } /* Verify that user is in database */ $q = "select password from users where username = '$username'"; $result = mysql_query($q,$conn); if(!$result || (mysql_numrows($result) < 1)){ return 1; //Indicates username failure } /* Retrieve password from result, strip slashes */ $dbarray = mysql_fetch_array($result); $dbarray['password'] = stripslashes($dbarray['password']); $password = stripslashes($password); /* Validate that password is correct */ if($password == $dbarray['password']){ return 0; //Success! Username and password confirmed } else{ return 2; //Indicates password failure } } /** * checkLogin - Checks if the user has already previously * logged in, and a session with the user has already been * established. Also checks to see if user has been remembered. * If so, the database is queried to make sure of the user's * authenticity. Returns true if the user has logged in. */ function checkLogin(){ /* Check if user has been remembered */ if(isset($_COOKIE['cookname']) && isset($_COOKIE['cookpass'])){ $_SESSION['username'] = $_COOKIE['cookname']; $_SESSION['password'] = $_COOKIE['cookpass']; } /* Username and password have been set */ if(isset($_SESSION['username']) && isset($_SESSION['password'])){ /* Confirm that username and password are valid */ if(confirmUser($_SESSION['username'], $_SESSION['password']) != 0){ /* Variables are incorrect, user not logged in */ unset($_SESSION['username']); unset($_SESSION['password']); return false; } return true; } /* User not logged in */ else{ return false; } } /** * Determines whether or not to display the login * form or to show the user that he is logged in * based on if the session variables are set. */ function displayLogin(){ global $logged_in; if($logged_in){ echo ' user logged in. <a href="logout.php">loggout</a>'; } else{ ?> <table border="0" cellpadding="0" cellspacing="0" style="border-collapse: collapse" bordercolor="#111111" width="100%" id="AutoNumber1" height="1"> <tr> <td width="100%" height="1"> <p><h1>Login</h1></td> </tr> <tr> <td width="526" height="1"> <form action="" method="post"> <table align="left" border="0" cellspacing="0" cellpadding="3" width="613"> <tr><td width="1">Username:</td><td width="668"> <input type="text" name="user" maxlength="30" size="20"></td></tr> <tr><td width="1">Password:</td><td width="668"> <input type="password" name="pass" maxlength="30" size="20"></td></tr> <tr><td colspan="2" align="left" width="607"> <input type="checkbox" name="remember" value="ON"> <font size="2">Remember me next time</td></tr> <tr><td align="right" width="125"> <p align="center"></td><td align="right" width="482"> <p align="center"> <input type="submit" name="sublogin" value="Login" style="float: left"></td></tr> <tr><td colspan="2" align="left" width="607"><a href="register.php">Register</a> || <a href=otherwebsite>Other Websites</a></td></tr> </table> </form></td> <td width="95" height="1"></td> </tr> <tr> <td width="100%" height="99"> </td> </tr> </table> <body> </body> <? } } /** * Checks to see if the user has submitted his * username and password through the login form, * if so, checks authenticity in database and * creates session. */ if(isset($_POST['sublogin'])){ /* Check that all fields were typed in */ if(!$_POST['user'] || !$_POST['pass']){ die('You didn\'t fill in a required field.'); } /* Spruce up username, check length */ $_POST['user'] = trim($_POST['user']); if(strlen($_POST['user']) > 30){ die("Sorry, the username is longer than 30 characters, please shorten it."); } /* Checks that username is in database and password is correct */ $md5pass = md5($_POST['pass']); $result = confirmUser($_POST['user'], $md5pass); /* Check error codes */ if($result == 1){ die('That username doesn\'t exist in our database.'); } else if($result == 2){ die('Incorrect password, please try again.'); } /* Username and password correct, register session variables */ $_POST['user'] = stripslashes($_POST['user']); $_SESSION['username'] = $_POST['user']; $_SESSION['password'] = $md5pass; /** * This is the cool part: the user has requested that we remember that * he's logged in, so we set two cookies. One to hold his username, * and one to hold his md5 encrypted password. We set them both to * expire in 100 days. Now, next time he comes to our site, we will * log him in automatically. */ if(isset($_POST['remember'])){ setcookie("cookname", $_SESSION['username'], time()+60*60*24*100, "/"); setcookie("cookpass", $_SESSION['password'], time()+60*60*24*100, "/"); } /* Quick self-redirect to avoid resending data on refresh */ echo "<meta http-equiv=\"Refresh\" content=\"0;url=$HTTP_SERVER_VARS[php_SELF]\">"; return; } /* Sets the value of the logged_in variable, which can be used in your code */ $logged_in = checkLogin(); ?> Thats the login page, but i carnt seem to make it so as a user login with correct information they get moved to a different page like main2.php for me, but isnt working.. please help Link to comment https://forums.phpfreaks.com/topic/148279-solved-help/ Share on other sites More sharing options...
alphanumetrix Posted March 6, 2009 Share Posted March 6, 2009 Not sure what you're trying to do with this: /* Quick self-redirect to avoid resending data on refresh */ echo "<meta http-equiv=\"Refresh\" content=\"0;url=$HTTP_SERVER_VARS[php_SELF]\">"; return; if you're trying to redirect someone using that, it probably won't work. However, this will: <?php header("Location: http://yourpage.com"); ?> Link to comment https://forums.phpfreaks.com/topic/148279-solved-help/#findComment-778440 Share on other sites More sharing options...
BMurtagh Posted March 6, 2009 Share Posted March 6, 2009 Hi, I would put begin to put your code for the next page after a successful login in: /* Validate that password is correct */ if($password == $dbarray['password']){ //proceed to perform website’s functionality – e.g. present information to the user } else{ return 2; //Indicates password failure } } I removed the return 0; line because the return() statement immediately ends execution of the current function, and returns its argument as the value of the function call. And even if there was code after the return 0; line, it would not be executed. The else statement is fine as is because it should catch anything that indicates a failed login. I would also move the cookies/previous login snippet to the beginning of the code because it would make more sense to check right off the bat if the user has already been logged in or not before doing the actual username & password check. Link to comment https://forums.phpfreaks.com/topic/148279-solved-help/#findComment-778443 Share on other sites More sharing options...
dean7 Posted March 6, 2009 Author Share Posted March 6, 2009 Didnt seem to work :S Ill explane it bit better incase you didnt understand, Once a user is logged it i want it to redirect them to a different page but if they dont log in with correct details they stay at the same page. Link to comment https://forums.phpfreaks.com/topic/148279-solved-help/#findComment-778501 Share on other sites More sharing options...
redarrow Posted March 6, 2009 Share Posted March 6, 2009 quick example. <?php session_start(); if ( ($_SESSION['username']) && ($_SESSION['password'])){ header("location: correct_page.php"); exit; }else{}; ?> Link to comment https://forums.phpfreaks.com/topic/148279-solved-help/#findComment-778510 Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.