June 2, 200917 yr Hey guys and girls, I'm writing my log in script as we speaek but i've come to a hault at a mysql query, I'm going to have a multi level user log in system so there will be Admin (me) and a client section. One way i thought of doing it is two tables, and a php if statement saying if admin this table if client this table, but that would require me to update the php file and the database, where as if i make it all in one database i can make my script a lot smaller. mysql_connect("$host", "$username", "$password")or die("cannot connect"); mysql_select_db("$db_name")or die("cannot select DB" . mysqlerror()); $loginsql = "SELECT * FROM $tbl_name WHERE username='$username' and password='$password'" The above is my db connect and select the table etc, ive got to the but with the username and password selection but if i was to have a multi level how would i incorperate it? im going to use nubmers as 0 for admin and 1 for client. my database table will look like this ID / username / password / level (level beig admin or not.) or am i a step ahead of myself here? Thanks Ben
June 2, 200917 yr You could just continue with the login process as usual so your current SQL statement is fine. However, after logging in, your script should select from the database whether the user is an admin or a user. You could then store this value in a session before using it in your scripts for example: if($_SESSION['rights'] == 'admin') { //show admin stuff } else { //stick with the user stuff }
June 2, 200917 yr better way 1 table add 1 row called user_level and set it to a boolean if 1 ... then normal user if 2 .... then admin database REATE TABLE `login_users` ( `id` int(11) NOT NULL auto_increment, `user` text NOT NULL, `pass` text NOT NULL, `email` text NOT NULL, `ip` text NOT NULL, `regdate` int(11) NOT NULL default '0', `lastlogin` text NOT NULL, `membergroup` int(11) NOT NULL default '1', `allow_login` int(11) NOT NULL default '1', PRIMARY KEY (`id`) ) ENGINE=MyISAM DEFAULT CHARSET=latin1; login script would just check what the user permission 1 so if ($user_level == 1) { header("location:admin/index.php"); exit; } else { header("location:user_cp.php"); exit; } that would be done after you have made sure username + password match etc
June 2, 200917 yr Author Thanks for the advice all, ive finished writing my login script now, but im getting an error, Parse error: syntax error, unexpected T_VARIABLE in /home2/irn3rdc/public_html/logincheck.php on line 21 Code: mysql_connect("$host", "$username", "$password")or die("cannot connect"); //connect to mysql mysql_select_db("$db_name")or die("cannot select DB" . mysqlerror()); //select db $sql = "SELECT * FROM $tbl_name WHERE username='$username' and password='$password'" $result = mysql_query($sql); //counts how many colums in table $count = mysql_num_rows($result); if ($count == 4 ) { The count is there to see if the table as the right amount of colums there are 5 columns and correct me if im wrong but it start from 0 so it would therefore be 4? Many Thanks Ben
June 3, 200917 yr $sql = "SELECT * FROM $tbl_name WHERE username='$username' and password='$password'" is missing a semi-colon at the end $sql = "SELECT * FROM $tbl_name WHERE username='$username' and password='$password'"; Array indexes start from 0, but when it's returning the count of results it should give you the actual amount. mysql_num_rows gives the number of records returned, not the number of fields for each row. Therefore, the number that you should get from that statement could only possibly be 0 or 1 (depending if a user if that username and password exists), or I suppose you could get more if theres more than one user has the same username and password. When numbering your roles, make the admin 10, 100 or some other large number, don't use 0. This is just a minor security thing, where depending on how you were checking if the user is admin/user, it might report them as being an admin when they're not. Also, limit your query to return a maximum of 1 result. $sql = "SELECT * FROM $tbl_name WHERE username='$username' and password='$password' LIMIT 1";
June 3, 200917 yr Author $sql = "SELECT * FROM $tbl_name WHERE username='$username' and password='$password'" is missing a semi-colon at the end $sql = "SELECT * FROM $tbl_name WHERE username='$username' and password='$password'"; Array indexes start from 0, but when it's returning the count of results it should give you the actual amount. mysql_num_rows gives the number of records returned, not the number of fields for each row. Therefore, the number that you should get from that statement could only possibly be 0 or 1 (depending if a user if that username and password exists), or I suppose you could get more if theres more than one user has the same username and password. When numbering your roles, make the admin 10, 100 or some other large number, don't use 0. This is just a minor security thing, where depending on how you were checking if the user is admin/user, it might report them as being an admin when they're not. Also, limit your query to return a maximum of 1 result. $sql = "SELECT * FROM $tbl_name WHERE username='$username' and password='$password' LIMIT 1"; Thank's that sorted THAT error out now im onto another one lol, and syntax is a pain hehe and in my database i made the username field unique, have i done that right so i cant put the same username in twice? and thanks for the advice on the limit option
June 3, 200917 yr Author Right, got an actualy login problem, it now keeps saying that im putting in the wrong username and password. http://irn3rd.co.uk/index.php?view=login user: test pass: test try it for yourself doesnt work <?php if ($_POST['submit']){ //Connection Details $host="localhost"; // Host name $username="irn3rdc_forum"; // Mysql username $password="******"; // Mysql password $db_name="irn3rdc_login"; // Database name $tbl_name="user"; // Table name $login = $_POST['username'];//username $pass = $_POST['password'];//password mysql_connect("$host", "$username", "$password")or die("cannot connect"); //connect to mysql mysql_select_db("$db_name")or die("cannot select DB" . mysqlerror()); //select db $sql = "SELECT * FROM $tbl_name WHERE username='$login' and password='$pass'"; $result = mysql_query($sql); //counts how many colums in table //$count = mysql_num_rows($result); if($count==2){ // check login session_register("username"); session_register("password"); $expire=time()+60*60*24*30; setcookie("user", "$username",$expire); header("location:http://www.irn3rd.co.uk/index.php?view=login"); }else{ include"header.php"; echo "<div id=\"content\">"; echo "Wrong Username or Password"; include"footer.php"; } }else{ echo "<div id=\"content\">"; echo "You have come to this page inaccuratly"; } ?> Login code above <form action="logincheck.php" method="post" name="login"> Login:<br /> <input name="username" type="text" maxlength="11" /> <br /> Password:<br /> <input name="password" type="password" maxlength="11"/> <br /> <input name="submit" type="submit" value="Login"/> </form> Form code above Where am i going wrong? php table consists of id username and password atm, not got the admin level in there yet donig that next, i just want it logging in first.
June 3, 200917 yr if($count==2){ should be: if($count==1){ Sorry my explanation earlier wasn't that clear. mysql_num_rows counts how many records are retrieved from the database, not how many columns there are in the table. To understand rows and columns, try going into phpMyAdmin, and click Browse on your user table. The headings along the top are columns, whereas each entry in the table is a row. When you run an SQL query, you retrieve a set of rows, in this case 1 row (the record of the user that's trying to login), or no rows if the credentials are invalid. To make your script work, all you need to check is that 1 row was returned i.e. there was a record which has the username and password provided, hence my correction above. If you want to count the number of columns, you need to convert the result to an array using mysql_fetch_assoc(), which converts the row you retrieved into an array. In your case you'd get an array like this: array( 'id'=>1, 'username'=>'irn3rd', 'password'=>'password' ); As you can see, each element in the array corresponds to the columns in your database table. You can then use the count() function, which counts how many elements there are in an array, and this will give you the number of columns. Running the count function will give 3, not 2, because that's the number of elements there are. It doesn't start at zero.
June 3, 200917 yr Author Ive changed my if ($count==1){ but still doesnt seem to be "loggin" me in. I cant figure it out and really annoying me, cause im thinking it somethin simple, plus im tired so off to bed, read the posts in the morning. Ben
Create an account or sign in to comment