當我按下返回按鈕離開我的頁面時。登錄頁面不應該出現。因爲我已經登錄了!當其他用戶已經登錄時,其他用戶如何登錄!它應該要求現有用戶註銷,然後允許其他用戶登錄!例如:當我們登錄Facebook時,並嘗試去登錄頁面。它不打開登錄頁面,而是打開我們的帳戶,因爲我們仍然登錄!另一個用戶可以在沒有現有用戶註銷的情況下登錄
帳戶頁面代碼:
<?php
require 'connection.php';
session_start();
?>
<?php
if(isset($_SESSION['id']))
{
$id=$_SESSION['id'];
?>
<!doctype html>
<html>
<head></head>
<body>
<div id="content">
logged in
</div>
</body>
</html>
<?php
}
else
{
header('location:login.php');
die();
}
?>
註冊碼:
<?php
require 'connection.php';
session_start();
?>
<?php
if(isset($_POST['REGISTER']))
{
$user=$_POST['user'];
$email=$_POST['email'];
$pass=$_POST['pass'];
$sql = "INSERT INTO users (username,email_id,password) VALUES ('$user','$email','$pass');";
$query = mysqli_query($conn, "SELECT * FROM users WHERE email_id='".$email."'");
if(mysqli_num_rows($query) > 0)
{
echo "OOPS! This email id is already registered.";
header ("refresh7; url=login.php");
}
else
{
if($conn->multi_query($sql) === TRUE)
{
echo 'Hello'.' '.$user.'!'.'<br>';
}}}
$conn->close();
header ("refresh:7; url=login.php");
?>
登錄頁面代碼:
<?php
require 'connection.php';
session_start();
?>
<html>
<head></head>
<body>
<div id="left">
<h2> <a href="login.php"> <center> LOGIN </center> </a> </h2>
<form action="" method="post">
<b> Email Id: </b> <input type="email" name="email" placeholder="[email protected]" required> <br> <br>
<b> Password: </b> <input type="password" name="pass" placeholder="****" required> <br> <br>
<input type="submit" value="LOGIN" name="LOGIN">
</form>
<?php
if(isset($_GET['error'])==true)
{
echo '<font color="red"> <p align="center"> username & password does not match! </p> </font>';
}
?>
</div>
<?php
if(isset($_POST['LOGIN']))
{
$email=$_POST['email'];
$pass=$_POST['pass'];
$sql = $conn->query("SELECT * FROM users WHERE email_id='$email' AND password='$pass'");
$row = $sql->fetch_array(MYSQLI_BOTH);
if($row>0)
{
$_SESSION['id'] = $row['id'];
header('location: account.php');
}
else
{
header('location:login.php?error=1');
}}
?>
</body>
</html>
您的代碼對SQL注入開放。使用參數化查詢。密碼也應該散列。 – chris85
每個頁面都必須啓動會話,並且每個頁面都必須檢查'$ _SESSION ['id']'以知道登錄是否已經執行 – RiggsFolly
@Confiqure請不要忘記在編輯時刪除不可編輯的代碼片段格式 – Will