Forum Moderators: coopster
// let's call the database connection
// done
session_start();
$user_check = $_SESSION['login_user'];
$ses_query = mysql_query("SELECT member_name, member_ID, member_email FROM members WHERE member_name = '$user_check' ");
$row = mysql_fetch_array($ses_query);
$member_name = $row['member_name'];
$member_ID = $row['member_ID'];
$member_email = $row['member_email'];
if(!isset($member_name))
{
header("Location: http://www.website.com/login/login.php");
}
// they're safe
?>
<?php
// let's call the database connection
// done
session_start();
if($_SERVER["REQUEST_METHOD"] == "POST"){
// username and password sent from Form
$myusername = addslashes($_POST['username']);
$mypassword = addslashes($_POST['password']);
$query = "SELECT member_ID FROM members WHERE member_name = '$myusername' and member_pw = '$mypassword'";
$result = mysql_query($query);
$row = mysql_fetch_array($result);
$count = mysql_num_rows($result);
$member_ID = $row['member_ID'];
// If result matched $myusername and $mypassword, table row must be 1 row
if($count==1){
session_register("myusername");
$_SESSION['login_user'] = $myusername;
header("location: http://www.website.com/index.php");
} // end if
else{
$error = "Your Login Name or Password is invalid";
} // end else
} // end if
?>
// login form here
Isn't referer disabled for POST requests?
// let's call the database connection
// done
session_start();
$user_check = $_SESSION['login_user'];
$_SESSION['referer'] = $_SERVER['HTTP_REFERER'];
$ses_query = mysql_query("SELECT member_name, member_ID, member_email FROM members WHERE member_name = '$user_check' ");
$row = mysql_fetch_array($ses_query);
$member_name = $row['member_name'];
$member_ID = $row['member_ID'];
$member_email = $row['member_email'];
if(!isset($member_name))
{
header("Location: http://www.website.com/login/login.php");
}
// they're safe
?>
<?php
// let's call the database connection
// done
session_start();
if($_SERVER["REQUEST_METHOD"] == "POST"){
// username and password sent from Form
$myusername = addslashes($_POST['username']);
$mypassword = addslashes($_POST['password']);
$query = "SELECT member_ID FROM members WHERE member_name = '$myusername' and member_pw = '$mypassword'";
$result = mysql_query($query);
$row = mysql_fetch_array($result);
$count = mysql_num_rows($result);
$member_ID = $row['member_ID'];
// If result matched $myusername and $mypassword, table row must be 1 row
if($count==1){
session_register("myusername");
$_SESSION['login_user'] = $myusername;
header("location: " . $_SESSION['referer']);
} // end if
else{
$error = "Your Login Name or Password is invalid";
} // end else
} // end if
?>
// login form here
if($count==1){
session_register("myusername");
$_SESSION['login_user'] = $myusername;
$_SESSION['referer'] = $_SERVER['HTTP_REFERER'];
header("location: " . $_SESSION['referer']);
$document = $_SERVER['PHP_SELF'];
$host = $_SERVER['HTTP_HOST'];
$querystring = '?'.$_SERVER['QUERY_STRING'];
$fullpath = $host.$document.$querystring;
session_start();
$user_check = $_SESSION['login_user'];
$_SESSION['referer'] = $fullpath;
header("location: http://".$_SESSION['referer']);