我遇到了2個文件的問題:login_config.php
和profile.php
。會話變量不起作用? (PHP)
- login_config.php由日誌系統,它設置$ _SESSION [「鑰匙」]真正的幾種驗證完成後的。
- profile.php是用戶在成功後重定向到的頁面。
我希望profile.php上的數據只能使用$ _SESSION ['key'] set(成功登錄時)訪問。
我的問題:我的代碼有什麼不正確?此外,爲什麼我在提交登錄時出現錯誤,只有在$ _SESSION ['key']爲false /未設置時纔會返回,與目標profile.php頁面相反?
CODE:(login_config.php)
<?php
// POST VARIABLES
$submit = $_POST['login_submit'];
$username = $_POST['login_username'];
$password = $_POST['login_password'];
$email = $_POST['login_email'];
require 'password_config.php';
if(isset($submit)){
require 'db/connect.php';
// PASSWORD VERIFYING
$pass_query = "SELECT password FROM users WHERE email='$email'";
$queried = mysql_query($pass_query);
while($row = mysql_fetch_array($queried)){
$user_pass = $row['password'];
$veri_password = password_verify($password, $user_pass);
}
if(!$veri_password === true){$errors[] = '-Account does not exist ';}
// CHECKING NUM ROWS
$sql = "SELECT id, username FROM users WHERE password='$user_pass' AND email='$email'";
$entered_user = mysql_query($sql);
$num_rows = mysql_num_rows($entered_user);
// ERRS ARRAY ESTABLISHED
$errors = array();
// FURTHER VERIFYING
if(empty($password) || empty($email))
{
$errors[] = 'Please do not leave fields empty';
}
elseif($num_rows != 1)
{
$errors[] = '-Account does not exist ';
}
elseif($num_rows == 1)
{
session_start();
$_SESSION['key'] === true;
while($row = mysql_fetch_array($entered_user)){
$_SESSION['id'] = $row['id'];
$_SESSION['email'] = $email;
$_SESSION['user'] = $row['username'];
$_SESSION['pass'] = $password;
header('Location: profile.php');
exit();
}
}
}
CODE:(profile.php)
<?php
session_start();
if($_SESSION['key'] !== true){
die ("please <a href='login.php'>log in</a> to view this page");
}
?>
<html>
<head>
<title>Profile</title>
<link href='css/main.css' rel='stylesheet' />
</head>
<body>
<div id='container'>
<?php require 'include/header.php'; ?>
<?= 'NJM ID # ==>'.$_SESSION['id'].'<br />'.'Username ==>'.$_SESSION['user'].'<br/>'.'Password ==>'.$_SESSION['pass'].'<br/>'.'<br />' ?>
<a href='logout.php'>Log out!</a>
<br />
-OR-
<br />
<p>Try our beta mode<a href='forum.php'> forum</a></p>
<?php require 'include/footer.php'; ?>
</div>
</body>
</html>
注:我知道我很容易受到SQL攻擊的代碼的當前狀態,我將在稍後解決這個問題,同時我也堅持不推薦使用MySQL。
此外,在此先感謝您的幫助-Eugene –
不能完全確定爲什麼這個問題已經下來了投票。仍然沒有收到解決方案。 –
你可以縮進你的代碼,並更具體地說明你得到的是哪個錯誤。註釋你的代碼以顯示邏輯失敗的位置,以及你期望看到/你實際看到的是什麼 –