Jump to content

[SOLVED] user, session , security


asmith

Recommended Posts

when a user log in :

before i show him his logged page

$_SESSION[user] = "aaa";

 

and at all of user pages :

 

if ($_SESSION[user] != "aaa") {header("location: login.php");exit;}

 

1.is this way enough secure ?

i mean i have put a "aaa" variable  , isn't that unsafe ?

2.beside how can i use a changable variable for defining users ?

Link to comment
https://forums.phpfreaks.com/topic/78910-solved-user-session-security/
Share on other sites

Usually easiest to use booleens.

 

If user logged in successfully....

 

<?php

  session_start();
  $_SESSION['user_logged_in'] = true;

?>

 

Then a simple login check...

 

<?php

  session_start();
  if (isset($_SESSION['user_logged_in'])) {
    // user is logged in.
  }

?>

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.