Jeg sidder pt. og koder på en lille privat hjemmeside, hvor jeg dog har en del administrative funktioner.
Jeg havde ikke mod på selv at ligge ud med at kode et login system, så jeg fandt et script på en hjemmeside til fri afbenyttelse. Systemet virkede forholdsvis fint, men det er dog efter at jeg har implenteret diverse PHP funktioner begyndt at drille voldsomt.
Mit login-script ser således ud:
<?
/**
* Checks to see if the user has submitted his
* username and password through the login form,
* if so, checks authenticity in database and
* creates session.
*/
if(isset($_POST['sublogin'])){
/* Check that all fields were typed in */
if(!$_POST['user'] || !$_POST['pass']){
$fejl='Du udfyldte ikke et nødvendigt felt. ';
echo "<meta http-equiv=\\"Refresh\\" url=$HTTP_SERVER_VARS[PHP_SELF]\\">";
return;
}
/* Spruce up username, check length */
$_POST['user'] = trim($_POST['user']);
if(strlen($_POST['user']) > 30){
$fejl2='Brugernavnet overskrider 30 tegn. ';
echo "<meta http-equiv=\\"Refresh\\" url=$HTTP_SERVER_VARS[PHP_SELF]\\">";
return;
}
/* Checks that username is in database and password is correct */
$md5pass = md5($_POST['pass']);
$result = confirmUser($_POST['user'], $md5pass);
/* Check error codes */
if($result == 1){
$fejl3='Brugeren eksisterer ikke. ';
echo "<meta http-equiv=\\"Refresh\\" url=$HTTP_SERVER_VARS[PHP_SELF]\\">";
return;
}
else if($result == 2){
$fejl4='Forkert kodeord. ';
echo "<meta http-equiv=\\"Refresh\\" url=$HTTP_SERVER_VARS[PHP_SELF]\\">";
return;
}
/* Username and password correct, register session variables */
$_POST['user'] = stripslashes($_POST['user']);
$_SESSION['username'] = $_POST['user'];
$_SESSION['password'] = $md5pass;
/**
* This is the cool part: the user has requested that we remember that
* he's logged in, so we set two cookies. One to hold his username,
* and one to hold his md5 encrypted password. We set them both to
* expire in 100 days. Now, next time he comes to our site, we will
* log him in automatically.
*/
if(isset($_POST['remember'])){
setcookie("cookname", $_SESSION['username'], time()+60*60*24*100, "/");
setcookie("cookpass", $_SESSION['password'], time()+60*60*24*100, "/");
}
/* Quick self-redirect to avoid resending data on refresh */
echo "<meta http-equiv=\\"Refresh\\" content=\\"0;url=$HTTP_SERVER_VARS[PHP_SELF]\\">";
return;
}
/* Sets the value of the logged_in variable, which can be used in your code */
$logged_in = checkLogin();
?>
<?
/**
* Checks whether or not the given username is in the
* database, if so it checks if the given password is
* the same password in the database for that user.
* If the user doesn't exist or if the passwords don't
* match up, it returns an error code (1 or 2).
* On success it returns 0.
*/
function confirmUser($username, $password){
global $conn;
/* Add slashes if necessary (for query) */
if(!get_magic_quotes_gpc()) {
$username = addslashes($username);
}
/* Verify that user is in database */
$q = "select password from users where username = '$username'";
$result = mysql_query($q,$conn);
if(!$result || (mysql_numrows($result) < 1)){
return 1; //Indicates username failure
}
/* Retrieve password from result, strip slashes */
$dbarray = mysql_fetch_array($result);
$dbarray['password'] = stripslashes($dbarray['password']);
$password = stripslashes($password);
/* Validate that password is correct */
if($password == $dbarray['password']){
return 0; //Success! Username and password confirmed
}
else{
return 2; //Indicates password failure
}
}
/**
* checkLogin - Checks if the user has already previously
* logged in, and a session with the user has already been
* established. Also checks to see if user has been remembered.
* If so, the database is queried to make sure of the user's
* authenticity. Returns true if the user has logged in.
*/
function checkLogin(){
/* Check if user has been remembered */
if(isset($_COOKIE['cookname']) && isset($_COOKIE['cookpass'])){
$_SESSION['username'] = $_COOKIE['cookname'];
$_SESSION['password'] = $_COOKIE['cookpass'];
}
/* Username and password have been set */
if(isset($_SESSION['username']) && isset($_SESSION['password'])){
/* Confirm that username and password are valid */
if(confirmUser($_SESSION['username'], $_SESSION['password']) != 0){
/* Variables are incorrect, user not logged in */
unset($_SESSION['username']);
unset($_SESSION['password']);
return false;
}
return true;
}
/* User not logged in */
else{
return false;
}
}
/**
* Determines whether or not to display the login
* form or to show the user that he is logged in
* based on if the session variables are set.
*/
function displayLogin(){
global $logged_in;
if($logged_in){
echo "<span style='font-size:10px;font-family:verdana;line-height:30px;color:#1A1A1A;'>Velkommen <b>$_SESSION[username]</b><a href='logout.php'>Log ud</a></span>";
}
else{
?>
<form action="" method="post" align="center">
<input type="text" name="user" maxlength="20" align="center" value="Username" class="input" style="width:95px;">
<input type="password" name="pass" maxlength="20" align="center" value="111" class="input" style="width:95px;">
<input type="submit" name="sublogin" value="Login" align="center" class="input" style='width:80px;'>
<input type="checkbox" name="remember">
<span style='font-size:10px;' class='news'>Husk</span></form>
<?
}
}
?>
Med en helt alm. funktion, som TSW's Afstemningsboks får jeg fejlen:
Warning: Cannot modify header information - headers already sent by (output started at c:\\XXX\\login.php:71) in c:\\XXX\\2\\pollfunctions.php on line 40Jeg har en anelse om at det måske kunne skyldes at noget er sat forkert op i login.php filen? Jeg har ikke selv megen erfaring med sessions, så måske en af jer kan lure en fejl, eller andet jeg kan rette, for at undgå den trælse
Cannot modify header fejlPå forhånd tak.
[Redigeret d. 22/06-05 22:16:21 af Jonas]