我有一個PHP腳本,允許用戶註冊條目到數據庫。條目是自動增加的。我發現,用戶#A可以通過將url從edit.php?id = 2更改爲id = 1來從用戶#B獲得條目。防止用戶編輯其他條目
我當然希望防止。所以我的想法是:如果mysql條目中的用戶ID字段與我的php腳本中的$ _SESSION ['user_id']匹配,則允許編輯。
<?php $bruker = $_SESSION['user_id']; ?>
<?php }
// if the 'id' variable is set in the URL, we know that we need to edit a record
if (isset($_GET['id']))
// if the form's submit button is clicked, we need to process the form
if (isset($_POST['submit']))
// make sure the 'id' in the URL is valid
if (is_numeric($_POST['id']))
// get variables from the URL/form
$id = $_POST['id'];
$elv = htmlentities($_POST['elv'], ENT_QUOTES);
$vald = htmlentities($_POST['vald'], ENT_QUOTES);
$art = htmlentities($_POST['art'], ENT_QUOTES);
$dato = htmlentities($_POST['dato'], ENT_QUOTES);
$vekt = (int)$_POST['vekt'];
$lengde = (int)$_POST['lengde'];
$flue = htmlentities($_POST['flue'], ENT_QUOTES);
$gjenutsatt = (int)$_POST['gjenutsatt'];
$kjonn = (int)$_POST['kjonn'];
$bilde = htmlentities($_POST['bilde'], ENT_QUOTES);
$user = $_SESSION['user_id'];
// check that required fields are not empty
if ($elv == '' || $vald == '' || $art == '' || $dato == '' || $vekt == '' || $kjonn == '')
// if they are empty, show an error message and display the form
$error = 'Du må fylle ut de påkrevde feltene!';
renderForm($elv, $vald, $art, $dato, $vekt, $lengde, $flue, $gjenutsatt, $kjonn, $bilde, $user, $error, $id);
// if everything is fine, update the record in the database
if ($stmt = $mysqli->prepare("UPDATE fisk SET elv = ?, vald = ?, art = ?, dato = ?, vekt = ?, lengde = ?, flue = ?, gjenutsatt = ?, kjonn= ?, bilde = ?, user = ?
WHERE id=?"))
$stmt->bind_param("ssssiisiisii", $elv, $vald, $art, $dato, $vekt, $lengde, $flue, $gjenutsatt, $kjonn, $bilde, $user, $id);
// show an error message if the query has an error
echo "ERROR: could not prepare SQL statement.";
// redirect the user once the form is updated
header("Location: /");
// if the 'id' variable is not valid, show an error message
echo "Error!";
// if the form hasn't been submitted yet, get the info from the database and show the form
'選擇數據,你需要從thetable其中的recordId = $ foo和用戶ID = $ currentuser'。如果它不是合適的用戶,他們可以破解他們想要的url,他們將永遠不會獲得任何記錄數據進行編輯。 –
另外,當您嘗試編輯數據以防止普通人混淆輸入時,您應該避免使用GET字段 – MiltoxBeyond