如何在PHP中单击“注销”按钮后禁用浏览器后退按钮功能

时间:2016-05-27 03:12:59

标签: javascript php jquery html session

我在使用浏览器后退按钮时遇到问题。 当用户按下注销时,它必须销毁会话和cookie。我写了以下代码:

的index.php

<!DOCTYPE html>
<html lang="en">
<head>
    <script type="text/javascript">
        function disablebackbutton(){
            window.history.forward();
        }
        disablebackbutton();
    </script>
</head>
<body>
<form name="loginform" method="post" action="<?php echo __PROJECT_LINK__; ?>/php/login_exec.php">
                <div class="modal-body">
                    <div class="form-horizontal">
                        <div class="form-group">
                            <label class="control-label">
                                <?php
                                if( isset($_SESSION['ERRMsg_ARR']) && is_array($_SESSION['ERRMsg_ARR']) && count($_SESSION['ERRMsg_ARR']) >0 ) {
                                    echo '<ul class="err">';
                                    foreach($_SESSION['ERRMsg_ARR'] as $msg) {
                                        echo '<span class="label label-warning" style="margin-left: 5px;">',$msg,'</span>';
                                    }
                                    echo '</ul>';
                                    unset($_SESSION['ERRMsg_ARR']);
                                }
                                ?>
                            </label>
                        </div>
                        <div class="subnav subnav-fixed nav navbar" style="margin-top: 10px; margin-right: 10px; margin-left: 10px;">
                            <ul class="nav nav-pills">
                                <li style="margin-top: 10px;">
                                    <span class="label label-default" style="margin-left: 22px;">Username</span>
                                    <input type="text" id="inputUserName" name="username" placeholder="Username" style="margin-left: 5px;">
                                </li>
                                <li style="margin-top: 10px;">
                                    <span class="label label-default" style="margin-left: 22px;">Password</span>
                                    <input type="password" id="inputPassword" name="password" placeholder="Password" style="margin-left: 5px;">
                                </li>
                                <li style="margin-top: 10px; margin-bottom: 10px;">
                                </li>
                            </ul>
                        </div>
                    </div>
                </div>
                <div class="modal-footer">
                    <!--?php $this->btnLogLogin->Render();?-->
                    <button type="button" class="btn btn-default" data-dismiss="modal">Close</button>
                    <button type="submit" class="btn btn-primary">Sign In</button>
                </div>
            </form>
</body>
</html>

login_exec.php

<?php
    //Start session
    if (session_status() == PHP_SESSION_NONE) {
        session_start();
    }
    //Include database connection details
    require_once('connection.php');

    //Array to store validation errors
    $errmsg_arr = array();

    //Validation error flag
    $errflag = false;

    //Function to sanitize values received from the form. Prevents SQL injection
    function clean($str) {
    $str = @trim($str);
    if(get_magic_quotes_gpc()) {
    $str = stripslashes($str);
    }
    return mysql_real_escape_string($str);
    }
     if(isset($_POST['username']))
     {
    //Sanitize the POST values
    $username = ($_POST['username']);
    $password = ($_POST['password']);

    //Input Validations
    if($username == '') {
    $errmsg_arr[] = 'Username missing';
    $errflag = true;
    }
    if($password == '') {
    $errmsg_arr[] = 'Password missing';
    $errflag = true;
    }

    //If there are input validations, redirect back to the login form
    if($errflag==true) {
    $_SESSION['ERRMsg_ARR'] = $errmsg_arr;
    session_write_close();
    header("location:../index.php");
    exit();
    }

    //Create query
    $qry="SELECT * FROM admin WHERE user_name='$username' AND password='$password'";
    $result=mysql_query($qry);

    //Check whether the query was successful or not
    if($result) {
    if(mysql_num_rows($result)) {
        while($row = mysql_fetch_array($result))
        {
            if($row['User_Status']=="Active"){
                $expire=time()+60*60*24*30; //1month
                setcookie("User_id", $row['User_id'], $expire);
                $name = $row['full_name'];
                $parts = explode(" ", $name);
                $lastname = array_pop($parts);
                $firstname = implode(" ", $parts);
                $_SESSION['USER']  = $firstname;
                $_SESSION['UID']  = $row['User_id'];
                $_SESSION['URights'] = $row['Rights'];
                header("location:../welcome.php");
            }
            else{
                $errmsg_arr[] = 'User Status is Block. Please contact your Administrator.';
                $errflag = true;
                if($errflag) {
                    $_SESSION['ERRMsg_ARR'] = $errmsg_arr;
                    session_write_close();
                    header("location: ../index.php");
                    exit();
                }
            }
        }
    }
    else {
    //Login failed
    $errmsg_arr[] = 'Username and Password not found';
    $errflag = true;
    if($errflag) {
    $_SESSION['ERRMsg_ARR'] = $errmsg_arr;
    session_write_close();
    header("location: ../index.php");
    exit();
    }
    }
    }else {
    die("Query failed");
    }
    }
    ?>

的welcome.php

<?php include 'qcubed.inc.php'; ?>
<?php
    $User_Name = $_SESSION['USER'];
    ?>
<html>

   <head>
      <title>Welcome</title>
   </head>
   <body>
      <h1>Welcome <?php echo $User_Name; ?></h1>
      <h2><a href = "<?php echo __PROJECT_LINK__; ?>/Info.php">Info</a></h2> 
      <h2><a href = "<?php echo __PROJECT_LINK__; ?>/php/logout.php">Sign Out</a></h2>
   </body>
 </html>

info.php的

    <?php include '../../qcubed.inc.php';?>
<!DOCTYPE html>
<html lang="en">
<head>
    <title><?php echo __PROJECT_TITLE__; ?> - Full Info</title>
    <script type="text/javascript">
            function disablebackbutton(){
                window.history.forward();
            }
            disablebackbutton();
        </script>
</head>
<?php
if(isset($_SESSION['UID']) && $_SESSION['UID'] != "")
{
//Task to do
        $User_Name = $_SESSION['USER'];
?>
<body>
         <h1>Info about <?php echo $User_Name; ?></h1> 
          <h2><a href = "<?php echo __PROJECT_LINK__; ?>/php/logout.php">Sign Out</a></h2>
       </body>
<?php
}
else{
    //redirect URL
    ?>
       <script>
            alert('You must Login first.');
            window.location.href='../../index.php';
        </script>";
   <?php

    exit();
}
?>

     </html>

logout.php

<?php
//session_write_close();
    session_start(); # NOTE THE SESSION START
    $expire=time()-60*60*24*30; //1month
    if(isset($_COOKIE['User_id'])):
        setcookie('User_id', '', $expire, '/');
    endif;
    unset($_SESSION['UID']);
    unset($_SESSION['USER']);
    unset($_SESSION['URights']);
    unset($_SESSION['UReg']);
    $_SESSION = array();
    foreach(array_keys($_SESSION) as $k) unset($_SESSION[$k]);
    session_unset();
    session_destroy();
    header("location: ../index.php");
    exit(); # NOTE THE EXIT
?>

从Info.php注销后,当我按下浏览器后退按钮时,它会在Info.php页面中显示我之前登录的用户页面和会话用户名, 但如果我在每个页面的head部分使用以下javascript,它也会在登录时禁用所有浏览器后退按钮。

<script type="text/javascript">
        function disablebackbutton(){
            window.history.forward();
        }
        disablebackbutton();
    </script>

我想在注销时才禁用浏览器后退按钮。 请帮帮我。

5 个答案:

答案 0 :(得分:0)

之前成了我的问题。在我的情况下,我没有禁用后退按钮。我做的是在用户注销时检查会话。如果没有检测到会话,请将用户重定向到登录页面或您想要重定向的页面..如果检测到的会话将其重定向到主页

答案 1 :(得分:0)

在login_exec.php中使用此代码

 if($errflag==true) {
        $_SESSION['ERRMsg_ARR'] = $errmsg_arr;
        session_write_close();
        header("location:../index.php");
        exit();
        }

        //Create query
        $qry="SELECT * FROM admin WHERE user_name='$username' AND password='$password'";
        $result=mysql_query($qry);

        //Check whether the query was successful or not
        if($result) {
        if(mysql_num_rows($result)) {
            while($row = mysql_fetch_array($result))
            {
                if($row['User_Status']=="Active"){
                    $expire=time()+60*60*24*30; //1month
                    setcookie("User_id", $row['User_id'], $expire);
                    $name = $row['full_name'];
                    $parts = explode(" ", $name);
                    $lastname = array_pop($parts);
                    $firstname = implode(" ", $parts);
                    $_SESSION['USER']  = $firstname;
                    $_SESSION['UID']  = $row['User_id'];
                    $_SESSION['login']=true; //ADD THIS CODE IN login_exec.php
                    $_SESSION['URights'] = $row['Rights'];
                    header("location:../welcome.php");
                }
                else{
                    $errmsg_arr[] = 'User Status is Block. Please contact your Administrator.';
                    $errflag = true;
                    if($errflag) {
                        $_SESSION['ERRMsg_ARR'] = $errmsg_arr;
                        session_write_close();
                        header("location: ../index.php");
                        exit();
                    }
                }
            }
        }

现在添加info.php的代码顶部

    session_start();
    $user=$_SESSION['USER'];
    if($_session['login']=true && $_session['user']= $user)
    {

    code of info.php 
    }
else
{

header(location:index.php);
}

<强> logout.php

<?php
    session_start();
    unset($_SESSION['USER']);
    session_destroy();
    header("Location:index.php");
?>

答案 2 :(得分:0)

而不是禁用后退按钮,您可以向每个页面添加代码以查看用户是否已记录。如果他们没有登录,请重定向到登录页面。

您可以创建一个基本类来为您处理此问题,并在每个页面上创建一个。

class sessionHandler
{

    function __construct($special = NULL)
    {

        session_set_cookie_params(60 * 60 * 24 * 365); // 1 year
        session_start();

        // if no user num (empty session) AND this isn't the login page
        if (!isset($_SESSION['userID']) && $special != 'LOGIN') {
            //send to login page
            header("location: login.php");
        }

        if ($special == 'LOGOUT') {
            // This is the logout page, clear the session and
            // send the user to the afterLogout page

            session_destroy();   // clear session files on server
            $_SESSION = Array(); // clear session variable for this session
            unset($_SESSION);

            // send to login page
            header("location: login.php");
        }

        if ($special == 'LOGIN') {
            // This is the login page, see if user is already logged in
            // if so, just send them to the afterLogin page
            // if not, validate their credentials, and store the USERID
            // in the $_SESSION var

            if ($this->getUserPermissions($_SESSION['userID'])) {
                 // send to any page you want
                 header("location: dashboard.php");
            }

        }

    }
}

现在,在您的所有网页上,将$session = new sessionHandler();放在顶部(在编写任何其他内容之前。

对于您要放置的登录和注销页面: $session = new sessionHandler('LOGIN'); $session = new sessionHandler('LOGOUT');

不准备好复制和粘贴,但希望能指出正确的方向。 : - )

答案 3 :(得分:0)

只需在用户只能登录时可以访问的所有页面添加条件:

[{"ProjectID":15,"ProjectName":" Securities"},{"ProjectID":16,"ProjectName":"PAS "}]

答案 4 :(得分:0)

最后我解决了我的问题..... :-) 我在

中使用以下代码

<强> logout.php

<html>
<head>
    <script type = "text/javascript" >
    window.history.forward();
    function preventBack() { window.history.forward(1); }
    setTimeout("preventBack()", 0);
    window.onunload = function () { null };
</script>

</head>
<body onload="preventBack();" onpageshow="if (event.persisted) preventBack();" onunload="">
Please Wait..
<?php

session_start(); # NOTE THE SESSION START
$expire=time()-60*60*24*30; //1month
if(isset($_COOKIE['User_id'])){
    setcookie('User_id', '', $expire);
}
unset($_SESSION['UID']);
unset($_SESSION['USER']);
unset($_SESSION['URights']);
unset($_SESSION['UReg']);
$_SESSION = array();
foreach(array_keys($_SESSION) as $k) unset($_SESSION[$k]);
session_unset();
session_destroy();

header("Refresh: 2;url=../index.php");
?>
</body>
</html>

现在它在退出后避免我使用浏览器后退按钮并销毁会话。 谢谢大家的宝贵支持......