السلام عليكم ..
عندي صفحة دخول المستخدم
عندما ادخل اسم المستخدم ينتقل مباشرة لصفحة تعديل البيانات
ولكن الملاحظ انة عند تسجيل اسم دخول احمد ينتقل لتعديل بيانات عضو اخر وهو العضو الاول في الداتا بيس
كتبت هذا الكود في صفحة تعديل البيانات
session_start();
لكنة لم يجدي نفعا
هذا كود صفحة الدخول
<?php require_once('Connections/GoldenCityTravel.php'); ?>
<?php
if (!function_exists("GetSQLValueString")) {
function GetSQLValueString($theValue, $theType, $theDefinedValue = "", $theNotDefinedValue = "")
{
if (PHP_VERSION < 6) {
$theValue = get_magic_quotes_gpc() ? stripslashes($theValue) : $theValue;
}
$theValue = function_exists("mysql_real_escape_string") ? mysql_real_escape_string($theValue) : mysql_escape_string($theValue);
switch ($theType) {
case "text":
$theValue = ($theValue != "") ? "'" . $theValue . "'" : "NULL";
break;
case "long":
case "int":
$theValue = ($theValue != "") ? intval($theValue) : "NULL";
break;
case "double":
$theValue = ($theValue != "") ? doubleval($theValue) : "NULL";
break;
case "date":
$theValue = ($theValue != "") ? "'" . $theValue . "'" : "NULL";
break;
case "defined":
$theValue = ($theValue != "") ? $theDefinedValue : $theNotDefinedValue;
break;
}
return $theValue;
}
}
$editFormAction = $_SERVER['PHP_SELF'];
if (isset($_SERVER['QUERY_STRING'])) {
$editFormAction .= "?" . htmlentities($_SERVER['QUERY_STRING']);
}
if ((isset($_POST["MM_insert"])) && ($_POST["MM_insert"] == "form1")) {
$insertSQL = sprintf("INSERT INTO tbl_customer (email_address, password) VALUES (%s, %s)",
GetSQLValueString($_POST['email_address'], "text"),
GetSQLValueString($_POST['password'], "text"));
mysql_select_db($database_GoldenCityTravel, $GoldenCityTravel);
$Result1 = mysql_query($insertSQL, $GoldenCityTravel) or die(mysql_error());
$insertGoTo = "update.php";
if (isset($_SERVER['QUERY_STRING'])) {
$insertGoTo .= (strpos($insertGoTo, '?')) ? "&" : "?";
$insertGoTo .= $_SERVER['QUERY_STRING'];
}
header(sprintf("Location: %s", $insertGoTo));
}
mysql_select_db($database_GoldenCityTravel, $GoldenCityTravel);
$query_Recordset1 = "SELECT * FROM tbl_customer";
$Recordset1 = mysql_query($query_Recordset1, $GoldenCityTravel) or die(mysql_error());
$row_Recordset1 = mysql_fetch_assoc($Recordset1);
$totalRows_Recordset1 = mysql_num_rows($Recordset1);
?>
<?php
// *** Validate request to login to this site.
if (!isset($_SESSION)) {
session_start();
}
$loginFormAction = $_SERVER['PHP_SELF'];
if (isset($_GET['accesscheck'])) {
$_SESSION['PrevUrl'] = $_GET['accesscheck'];
}
if (isset($_POST['email_address'])) {
$loginUsername=$_POST['email_address'];
$password=$_POST['password'];
$MM_fldUserAuthorization = "";
$MM_redirectLoginSuccess = "update.php";
$MM_redirectLoginFailed = "index.php";
$MM_redirecttoReferrer = true;
mysql_select_db($database_GoldenCityTravel, $GoldenCityTravel);
$LoginRS__query=sprintf("SELECT email_address, password FROM tbl_customer WHERE email_address=%s AND password=%s",
GetSQLValueString($loginUsername, "text"), GetSQLValueString($password, "text"));
$LoginRS = mysql_query($LoginRS__query, $GoldenCityTravel) or die(mysql_error());
$loginFoundUser = mysql_num_rows($LoginRS);
if ($loginFoundUser) {
$loginStrGroup = "";
if (PHP_VERSION >= 5.1) {session_regenerate_id(true);} else {session_regenerate_id();}
//declare two session variables and assign them
$_SESSION['MM_Username'] = $loginUsername;
$_SESSION['MM_UserGroup'] = $loginStrGroup;
if (isset($_SESSION['PrevUrl']) && true) {
$MM_redirectLoginSuccess = $_SESSION['PrevUrl'];
}
header("Location: " . $MM_redirectLoginSuccess );
}
else {
header("Location: ". $MM_redirectLoginFailed );
}
}
?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>Untitled Document</title>
</head>
<body>
<form action="<?php echo $loginFormAction; ?>" method="POST" name="form1" id="form1">
<table align="center">
<tr valign="baseline">
<td nowrap="nowrap" align="right">Email_address:</td>
<td><input type="text" name="email_address" value="" size="32" /></td>
</tr>
<tr valign="baseline">
<td nowrap="nowrap" align="right">Password:</td>
<td><input type="text" name="password" value="" size="32" /></td>
</tr>
<tr valign="baseline">
<td nowrap="nowrap" align="right"> </td>
<td><input type="submit" value="Insert record" /></td>
</tr>
</table>
<input type="hidden" name="MM_insert" value="form1" />
</form>
<p> </p>
</body>
</html>
<?php
mysql_free_result($Recordset1);
?>وهذا كود صفحة تعديل البيانات
<?php require_once('Connections/GoldenCityTravel.php');
session_start();
?>
<?php
if (!function_exists("GetSQLValueString")) {
function GetSQLValueString($theValue, $theType, $theDefinedValue = "", $theNotDefinedValue = "")
{
$theValue = get_magic_quotes_gpc() ? stripslashes($theValue) : $theValue;
$theValue = function_exists("mysql_real_escape_string") ? mysql_real_escape_string($theValue) : mysql_escape_string($theValue);
switch ($theType) {
case "text":
$theValue = ($theValue != "") ? "'" . $theValue . "'" : "NULL";
break;
case "long":
case "int":
$theValue = ($theValue != "") ? intval($theValue) : "NULL";
break;
case "double":
$theValue = ($theValue != "") ? "'" . doubleval($theValue) . "'" : "NULL";
break;
case "date":
$theValue = ($theValue != "") ? "'" . $theValue . "'" : "NULL";
break;
case "defined":
$theValue = ($theValue != "") ? $theDefinedValue : $theNotDefinedValue;
break;
}
return $theValue;
}
}
$editFormAction = $_SERVER['PHP_SELF'];
if (isset($_SERVER['QUERY_STRING'])) {
$editFormAction .= "?" . htmlentities($_SERVER['QUERY_STRING']);
}
if ((isset($_POST["MM_insert"])) && ($_POST["MM_insert"] == "form1")) {
$insertSQL = sprintf("INSERT INTO tbl_customer (customer_code, customer_first_name, customer_last_name, country, city, address, contact_number, gender, email_address, password) VALUES (%s, %s, %s, %s, %s, %s, %s, %s, %s, %s)",
GetSQLValueString($_POST['customer_code'], "int"),
GetSQLValueString($_POST['customer_first_name'], "text"),
GetSQLValueString($_POST['customer_last_name'], "text"),
GetSQLValueString($_POST['country'], "text"),
GetSQLValueString($_POST['city'], "text"),
GetSQLValueString($_POST['address'], "text"),
GetSQLValueString($_POST['contact_number'], "int"),
GetSQLValueString($_POST['gender'], "text"),
GetSQLValueString($_POST['email_address'], "text"),
GetSQLValueString($_POST['password'], "text"));
mysql_select_db($database_GoldenCityTravel, $GoldenCityTravel);
$Result1 = mysql_query($insertSQL, $GoldenCityTravel) or die(mysql_error());
$insertGoTo = "cust_reg_success.php";
if (isset($_SERVER['QUERY_STRING'])) {
$insertGoTo .= (strpos($insertGoTo, '?')) ? "&" : "?";
$insertGoTo .= $_SERVER['QUERY_STRING'];
}
header(sprintf("Location: %s", $insertGoTo));
}
if ((isset($_POST["MM_insert"])) && ($_POST["MM_insert"] == "form2")) {
$insertSQL = sprintf("INSERT INTO tbl_customer (customer_first_name, customer_last_name, country, city, address, contact_number, gender, email_address, password) VALUES (%s, %s, %s, %s, %s, %s, %s, %s, %s)",
GetSQLValueString($_POST['customer_first_name'], "text"),
GetSQLValueString($_POST['customer_last_name'], "text"),
GetSQLValueString($_POST['country'], "text"),
GetSQLValueString($_POST['city'], "text"),
GetSQLValueString($_POST['address'], "text"),
GetSQLValueString($_POST['contact_number'], "int"),
GetSQLValueString($_POST['gender'], "text"),
GetSQLValueString($_POST['email_address'], "text"),
GetSQLValueString($_POST['password'], "text"));
mysql_select_db($database_GoldenCityTravel, $GoldenCityTravel);
$Result1 = mysql_query($insertSQL, $GoldenCityTravel) or die(mysql_error());
$insertGoTo = "cust_reg_success.php";
if (isset($_SERVER['QUERY_STRING'])) {
$insertGoTo .= (strpos($insertGoTo, '?')) ? "&" : "?";
$insertGoTo .= $_SERVER['QUERY_STRING'];
}
header(sprintf("Location: %s", $insertGoTo));
}
if ((isset($_POST["MM_update"])) && ($_POST["MM_update"] == "form3")) {
$updateSQL = sprintf("UPDATE tbl_customer SET country=%s, city=%s, address=%s, contact_number=%s, email_address=%s, password=%s WHERE customer_code=%s",
GetSQLValueString($_POST['country'], "text"),
GetSQLValueString($_POST['city'], "text"),
GetSQLValueString($_POST['address'], "text"),
GetSQLValueString($_POST['contact_number'], "int"),
GetSQLValueString($_POST['email_address'], "text"),
GetSQLValueString($_POST['password'], "text"),
GetSQLValueString($_POST['customer_code'], "int"));
mysql_select_db($database_GoldenCityTravel, $GoldenCityTravel);
$Result1 = mysql_query($updateSQL, $GoldenCityTravel) or die(mysql_error());
}
mysql_select_db($database_GoldenCityTravel, $GoldenCityTravel);
$query_Reg = "SELECT * FROM tbl_customer";
$Reg = mysql_query($query_Reg, $GoldenCityTravel) or die(mysql_error());
$row_Reg = mysql_fetch_assoc($Reg);
$totalRows_Reg = mysql_num_rows($Reg);
?><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>Registration Form</title>
</head>
<body>
<form action="<?php echo $editFormAction; ?>" method="post" name="form1" id="form1">
</form>
<form action="<?php echo $editFormAction; ?>" method="post" name="form3" id="form3">
<table align="center">
<tr valign="baseline">
<td width="104" align="right" nowrap="nowrap">Country:</td>
<td width="240"><input type="text" name="country" value="<?php echo htmlentities($row_Reg['country'], ENT_COMPAT, 'utf-8'); ?>" size="25" /></td>
</tr>
<tr valign="baseline">
<td nowrap="nowrap" align="right">City:</td>
<td><input type="text" name="city" value="<?php echo htmlentities($row_Reg['city'], ENT_COMPAT, 'utf-8'); ?>" size="25" /></td>
</tr>
<tr valign="baseline">
<td nowrap="nowrap" align="right">Address:</td>
<td><input type="text" name="address" value="<?php echo htmlentities($row_Reg['address'], ENT_COMPAT, 'utf-8'); ?>" size="30" /></td>
</tr>
<tr valign="baseline">
<td nowrap="nowrap" align="right">Contact_number:</td>
<td><input type="text" name="contact_number" value="<?php echo htmlentities($row_Reg['contact_number'], ENT_COMPAT, 'utf-8'); ?>" size="20" /></td>
</tr>
<tr valign="baseline">
<td nowrap="nowrap" align="right">Email_address:</td>
<td><input type="text" name="email_address" value="<?php echo htmlentities($row_Reg['email_address'], ENT_COMPAT, 'utf-8'); ?>" size="40" /></td>
</tr>
<tr valign="baseline">
<td nowrap="nowrap" align="right">Password:</td>
<td><input name="password" type="password" value="<?php echo htmlentities($row_Reg['password'], ENT_COMPAT, 'utf-8'); ?>" size="6" maxlength="40" /></td>
</tr>
<tr valign="baseline">
<td nowrap="nowrap" align="right"> </td>
<td><input type="submit" value="Update record" /></td>
</tr>
</table>
<input type="hidden" name="MM_update" value="form3" />
<input type="hidden" name="customer_code" value="<?php echo $row_Reg['customer_code']; ?>" />
</form>
<p> </p>
<p> </p>
</body>
</html>
<?php
mysql_free_result($Reg);
?>لا اعرف ما استخدم الكوكيز ام السيشنز ؟