0

在这个站点的帮助下,我有一个现在可以工作的登录脚本。问题是我试图限制的页面没有限制访问,当我在没有登录的情况下进入该页面时,它仍然可以让我访问该页面。我对 PHP 很陌生,因此非常感谢您的帮助和评论。

该页面的代码是

<?php require_once('../Connections/PropSuite.php'); ?>
<?php

error_reporting(E_ALL & ~E_NOTICE);
ini_set('display_errors', TRUE);
ini_set('display_startup_errors', TRUE);

function isLoggedIn()
{
    if(isset($_SESSION['valid']) && $_SESSION['valid'])
        return true;
    return false;
}


session_start();
//if the user has not logged in
if(!isLoggedIn())
{
    header('Location: http://localhost/PropSuite/index.php');
    die();
}



?>

登录脚本的代码是。

<?php



function validateUser()
{

    session_regenerate_id (); //this is a security measure
    $_SESSION['valid'] = 1;
    $_SESSION['userid'] = $userid;
}


?>

<?php

ob_start(); // Start output buffering

error_reporting(E_ALL & ~E_NOTICE);
ini_set('display_errors', TRUE);
ini_set('display_startup_errors', TRUE);

session_start(); //must call session_start before using any $_SESSION variables
$username = isset($_POST['username'])?$_POST['username']:'';
     $password = isset($_POST['password'])?$_POST['password']:'';
//connect to the database here

$hostname_PropSuite = "localhost";
$database_PropSuite = "propsuite";
$username_PropSuite = "root";
$password_PropSuite = "root";
$PropSuite = mysql_pconnect($hostname_PropSuite, $username_PropSuite, $password_PropSuite) or trigger_error(mysql_error(),E_USER_ERROR); 
mysql_select_db($database_PropSuite, $PropSuite);

$username = mysql_real_escape_string($username);

$query = "SELECT password, salt FROM admin_users WHERE username = '$username';";

$result = mysql_query($query) or die(mysql_error());

if(mysql_num_rows($result) < 1) //no such user exists
{
    header('Location: http://localhost/PropSuite/index.php?login=fail');

    die();
}
$userData = mysql_fetch_array($result, MYSQL_ASSOC);
$hash = hash('sha256', $userData['salt'] . hash('sha256', $password) );
if($hash != $userData['password']) //incorrect password
{
    header('Location: http://localhost/PropSuite/index.php?login=fail');

    die();
}
else
{
   validateUser(); //sets the session data for this user
}
//redirect to another page or display "login success" message
header('Location: http://localhost/PropSuite/main');
die()




//redirect to another page or display "login success" message


?>

再次,提前感谢您的帮助和模组,如果我发布类似的问题,我深表歉意。

4

2 回答 2

0

嗯,这样对吗:

if(isset($_SESSION['valid']) && $_SESSION['valid'])
    return true;

没有括号丢失吗?

我会这样写:

if(!empty($_SESSION['valid']) && !empty($_SESSION['valid']) && $_SESSION['valid'] === true) {
        return true;
 }

也许这就是重点。如果这是错误的,您的登录将每次都是真实的。然后就可以看到内容了,即使没有Session!

希望能帮助到你!

于 2013-09-28T19:12:50.523 回答
-1

返回真,返回假

如果会话显示页面

else display 请登录后查看此页面或其他内容

于 2013-09-28T18:45:40.303 回答