无法从MySQL(php)获取数据(重新编辑)

时间:2016-02-01 09:44:45

标签: php mysql

我已经意识到为什么我实际上无法访问用户数据(在我登录后)以旧方式查找用户名为$_SESSION['username'];(假设有一行作为'用户名' in MySQL数据库)

因为我有一个测试帐户" good25" (选择数字的原因是看字母数字输入是否正常..它只是我的检查..没关系)

问题: 假设,我在表格中有行作为'用户名'以及他的所有信息......例如密码','电子邮件',' joindate',' type' ...

在网上我发现了如何从Session中抢夺用户名 <?php session_start(); $_SESSION('username'); ?>

成功!!

我有想法检查会话是否实际注册或没有? 登录start.php后,我使用了这段代码 if(isset($_SESSION['username'])) { print_r($_SESSION['username']); }

结果是&#34; 1&#34; (当我使用此用户名登录时#34; good25&#34;) 有什么建议吗?

  

index.php(比方说,index.php只保存注册+登录表单+注册脚本..以登录形式,动作=&#39; condb.php&#39;)

<?php 
require 'condb.php';

if (isset($_POST['btn-signup']))
{
    //FetchInputs
    $usern = mysqli_real_escape_string($connection,$_POST['username']);
    $email = mysqli_real_escape_string($connection,$_POST['email']);
    $password = mysqli_real_escape_string($connection,$_POST['password']);
    $repassword = mysqli_real_escape_string($connection,$_POST['repassword']);

    $usern = trim($usern);
    $email = trim($email);
    $password = trim($password);
    $repassword = trim($repassword);

    //SearchUser
    $searchusr = "SELECT username FROM $user_table WHERE username='$usern'";
    $usersearched = mysqli_query($connection, $searchusr);
    $countuser = mysqli_num_rows($usersearched);
    //SearchEmail
    $searcheml = "SELECT email FROM $user_table WHERE email='$email'";
    $emlsearched = mysqli_query($connection, $searcheml);
    $counteml = mysqli_num_rows($emlsearched);

    //RegisteringUser
    if ($countuser == 0)
    {
        if ($counteml == 0)
        {
            $ctime = time();
            $cday = date("Y-m-d",$ctime);
            $aCode = uniqid();
            $adduser = "INSERT INTO $user_table(username, email, password, realname, activationcode, verified, joindate, type, points) VALUES ('$usern','$email','$password','$name','$aCode','n','$cday','Free',$signPoints)";
            if (mysqli_query($connection, $adduser))
            {
                ?><script>alert('You have been registered');</script><?php
            }
            else {
                ?><script>alert('Couldnt Register, please contact Admin<br><?mysqli_error($connection);?>');</script><?php
            }
        } else {
            ?><script>alert('Email already exists!');</script><?php
        }
    } else {
        ?><script>alert('Username already exists!');</script><?php
    }
}
?>
  

condb.php

    $connection = mysqli_connect($db_server, $db_user, $db_pass);
mysqli_select_db($connection, $db_name);
if(!$connection) {
    die ("Connection Failed: " . mysqli_connect_error);
}

if (isset($_POST['btn-login']))
{
    $uname = mysqli_real_escape_string($connection,$_POST['uname']);
    $upass = mysqli_real_escape_string($connection,$_POST['upass']);

    //FindUser
    $finduser = "SELECT * FROM $user_table WHERE username='$uname' AND password='$upass'";
    $findinguser = mysqli_query($connection,$finduser);

    $founduser = mysqli_num_rows($findinguser);
    //ConfirmPassword
    if ($founduser > 0)
    {
        session_start();
        $_SESSION['username'] = $username;
        $_SESSION['username'] = true;
        if ($findinguser != false)
        {
            while ($fetchD = mysqli_fetch_array($findinguser, MYSQLI_ASSOC))
            {
                $fetchD['username'] = $usernn;
                $fetchD['email'] = $email;
                $fetchD['userid'] = $uid;
                $fetchD['realname'] = $rlnm;
                $fetchD['points'] = $pts;
                $fetchD['type'] = $membertype ;
            }
            header("Location: start.php");
        } else {
            echo mysqli_error();
        }
    } else {
        header("Location: index.php");
        ?><script>alert('Wrong details, please fill in correct password and email');</script><?php
    }
}

我不是要你建立一个脚本..请帮助一下? (非常感谢你,因为我是一个自学者,你不必说出一切......只是一条线索对我来说已经足够了)

3 个答案:

答案 0 :(得分:0)

可能是您可以尝试此代码

<?php
    require_once 'require.inc.php';
    //session_start();

    if (isset($_POST['btn-login']))
    {
        $uname = mysqli_real_escape_string($_POST['uname']);
        $upass = mysqli_real_escape_string($_POST['upass']);

        $search = mysqli_query($connection, "SELECT username, userid, password from $user_table WHERE username='$uname' AND password='$upass'");
        $match = mysqli_fetch_assoc($search);
        if ($match == 1 and $match['password'] == md5($upass))
        {
            $_SESSION['username'] = $match['userid'];
        } else {
            ?>
            <script>alert('Password or E-mail is wrong. If you havent registered, Please Register');</script>
            <?php
        }
    }
    if (isset($_SESSION['username']) or isset($match['userid'])){
    header("Location:start.php");
    }
    if (isset($_POST['btn-signup']))
    {
        $name = mysqli_real_escape_string($_POST['name']);
        $usern = mysqli_real_escape_string($_POST['username']);
        $email = mysqli_real_escape_string($_POST['email']);
        $password = mysqli_real_escape_string($_POST['password']);
        $repassword = mysqli_real_escape_string($_POST['repassword']);

        $name = trim($name);
        $usern = trim($usern);
        $email = trim($email);
        $password = trim($password);
        $repassword = trim($repassword);

        $query = "SELECT email FROM $user_table WHERE email='$email'";
        $result = mysqli_query($connection, $query);
        $count = mysqli_num_rows($result);

        $querytwo = "SELECT username FROM $user_table WHERE username='$usern'";
        $resulttwo = mysqli_query($connection, $querytwo);
        $counttwo = mysqli_num_rows($resulttwo);


        if ($count == 0 AND $counttwo == 0) 
        {
            if ($password == $repassword) {
                if (mysqli_query($connection, "INSERT INTO $user_table(username, email, password, realname) VALUES ('$usern','$email','$password','$name')"))
                {
                    ?>
                    <script> alert ('Successfully registered'); </script>
                    <?php
                }
            }else {
                ?>
                <script> alert ('The Password you entered, doesnt match.. Please fill in the same password'); </script>
                <?php
            }
        }
        else {
            ?>
            <script> alert('Username or E-mail already exist'); </script>
            <?php
        }
    }
?>

这适用于 require.inc.php

<?php
    global $username;
    //require 'dconn.php';
    session_start();

    $_SESSION["username"] = $username;

    $connection = mysqli_connect("localhost","root","", "test") or die(mysqli_error());


    // Check Login
    if (isset($_SESSION['username']) and isset ($match['userid']))
    {
    $Selection = "SELECT * FROM $user_table WHERE username='$username'";
    $selectQuery = mysqli_query($connection, $Selection);

        if ($selectQuery != false)
        {
            while ($fetchD = mysqli_fetch_assoc($selectQuery))
            {
                $usernn = $fetchD['username'];
                $email = $fetchD['email'];
                $uid = $fetchD['userid'];
            }
        } else {
            echo mysqli_error();
        }

    }
?>

答案 1 :(得分:0)

@suggestion,在用户登录后创建会话,然后为每个页面启动会话授权并进行您创建的会话并使用该会话变量执行SQL查询。

for example :
$_SESSION['user_name']=$row['username'];
for each page:
session_start();
$user_name=$_SESSION['user_name'];
SQL query
mysqli_query($con,"SELECT * FROM users where column_name='$user_name'");

答案 2 :(得分:0)

我认为您需要在要执行mysql操作的所有文件中包含dconn.php文件。如果你只在require.inc.php中包含它,那么你就可以在所有其他文件中使用它了。