الفريق العربي للبرمجةأرشيف المنتديات · 2000 – 2023
نسخة أرشيفية للقراءة فقط — التسجيل والمشاركة مغلقان، والمحتوى محفوظ كما كان.

مشكلة في تذكر الـ login

بدأه Sameh11 في 12 يناير 2011 · 3 رد · 445 مشاهدة · في منتدى تطوير المواقع بـ PHP
مشاركة: واتساب X فيسبوك تيليجرام
#1 صاحب الموضوع

السلام عليكم ..

عندي صفحة دخول المستخدم

عندما ادخل اسم المستخدم ينتقل مباشرة لصفحة تعديل البيانات

ولكن الملاحظ انة عند تسجيل اسم دخول احمد ينتقل لتعديل بيانات عضو اخر وهو العضو الاول في الداتا بيس

كتبت هذا الكود في صفحة تعديل البيانات

session_start();

لكنة لم يجدي نفعا

هذا كود صفحة الدخول

<?php require_once('Connections/GoldenCityTravel.php'); ?>
<?php
if (!function_exists("GetSQLValueString")) {
function GetSQLValueString($theValue, $theType, $theDefinedValue = "", $theNotDefinedValue = "") 
{
  if (PHP_VERSION < 6) {
    $theValue = get_magic_quotes_gpc() ? stripslashes($theValue) : $theValue;
  }

  $theValue = function_exists("mysql_real_escape_string") ? mysql_real_escape_string($theValue) : mysql_escape_string($theValue);

  switch ($theType) {
    case "text":
      $theValue = ($theValue != "") ? "'" . $theValue . "'" : "NULL";
      break;    
    case "long":
    case "int":
      $theValue = ($theValue != "") ? intval($theValue) : "NULL";
      break;
    case "double":
      $theValue = ($theValue != "") ? doubleval($theValue) : "NULL";
      break;
    case "date":
      $theValue = ($theValue != "") ? "'" . $theValue . "'" : "NULL";
      break;
    case "defined":
      $theValue = ($theValue != "") ? $theDefinedValue : $theNotDefinedValue;
      break;
  }
  return $theValue;
}
}

$editFormAction = $_SERVER['PHP_SELF'];
if (isset($_SERVER['QUERY_STRING'])) {
  $editFormAction .= "?" . htmlentities($_SERVER['QUERY_STRING']);
}

if ((isset($_POST["MM_insert"])) && ($_POST["MM_insert"] == "form1")) {
  $insertSQL = sprintf("INSERT INTO tbl_customer (email_address, password) VALUES (%s, %s)",
                       GetSQLValueString($_POST['email_address'], "text"),
                       GetSQLValueString($_POST['password'], "text"));

  mysql_select_db($database_GoldenCityTravel, $GoldenCityTravel);
  $Result1 = mysql_query($insertSQL, $GoldenCityTravel) or die(mysql_error());

  $insertGoTo = "update.php";
  if (isset($_SERVER['QUERY_STRING'])) {
    $insertGoTo .= (strpos($insertGoTo, '?')) ? "&" : "?";
    $insertGoTo .= $_SERVER['QUERY_STRING'];
  }
  header(sprintf("Location: %s", $insertGoTo));
}

mysql_select_db($database_GoldenCityTravel, $GoldenCityTravel);
$query_Recordset1 = "SELECT * FROM tbl_customer";
$Recordset1 = mysql_query($query_Recordset1, $GoldenCityTravel) or die(mysql_error());
$row_Recordset1 = mysql_fetch_assoc($Recordset1);
$totalRows_Recordset1 = mysql_num_rows($Recordset1);
?>
<?php
// *** Validate request to login to this site.
if (!isset($_SESSION)) {
  session_start();
}

$loginFormAction = $_SERVER['PHP_SELF'];
if (isset($_GET['accesscheck'])) {
  $_SESSION['PrevUrl'] = $_GET['accesscheck'];
}

if (isset($_POST['email_address'])) {
  $loginUsername=$_POST['email_address'];
  $password=$_POST['password'];
  $MM_fldUserAuthorization = "";
  $MM_redirectLoginSuccess = "update.php";
  $MM_redirectLoginFailed = "index.php";
  $MM_redirecttoReferrer = true;
  mysql_select_db($database_GoldenCityTravel, $GoldenCityTravel);

  $LoginRS__query=sprintf("SELECT email_address, password FROM tbl_customer WHERE email_address=%s AND password=%s",
    GetSQLValueString($loginUsername, "text"), GetSQLValueString($password, "text")); 

  $LoginRS = mysql_query($LoginRS__query, $GoldenCityTravel) or die(mysql_error());
  $loginFoundUser = mysql_num_rows($LoginRS);
  if ($loginFoundUser) {
     $loginStrGroup = "";

	if (PHP_VERSION >= 5.1) {session_regenerate_id(true);} else {session_regenerate_id();}
    //declare two session variables and assign them
    $_SESSION['MM_Username'] = $loginUsername;
    $_SESSION['MM_UserGroup'] = $loginStrGroup;	      

    if (isset($_SESSION['PrevUrl']) && true) {
      $MM_redirectLoginSuccess = $_SESSION['PrevUrl'];	
    }
    header("Location: " . $MM_redirectLoginSuccess );
  }
  else {
    header("Location: ". $MM_redirectLoginFailed );
  }
}
?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>Untitled Document</title>
</head>

<body>
<form action="<?php echo $loginFormAction; ?>" method="POST" name="form1" id="form1">
  <table align="center">
    <tr valign="baseline">
      <td nowrap="nowrap" align="right">Email_address:</td>
      <td><input type="text" name="email_address" value="" size="32" /></td>
    </tr>
    <tr valign="baseline">
      <td nowrap="nowrap" align="right">Password:</td>
      <td><input type="text" name="password" value="" size="32" /></td>
    </tr>
    <tr valign="baseline">
      <td nowrap="nowrap" align="right"> </td>
      <td><input type="submit" value="Insert record" /></td>
    </tr>
  </table>
  <input type="hidden" name="MM_insert" value="form1" />
</form>
<p> </p>
</body>
</html>
<?php
mysql_free_result($Recordset1);
?>

وهذا كود صفحة تعديل البيانات

<?php require_once('Connections/GoldenCityTravel.php');
session_start(); 
 ?>

<?php
if (!function_exists("GetSQLValueString")) {
function GetSQLValueString($theValue, $theType, $theDefinedValue = "", $theNotDefinedValue = "") 
{
  $theValue = get_magic_quotes_gpc() ? stripslashes($theValue) : $theValue;

  $theValue = function_exists("mysql_real_escape_string") ? mysql_real_escape_string($theValue) : mysql_escape_string($theValue);

  switch ($theType) {
    case "text":
      $theValue = ($theValue != "") ? "'" . $theValue . "'" : "NULL";
      break;    
    case "long":
    case "int":
      $theValue = ($theValue != "") ? intval($theValue) : "NULL";
      break;
    case "double":
      $theValue = ($theValue != "") ? "'" . doubleval($theValue) . "'" : "NULL";
      break;
    case "date":
      $theValue = ($theValue != "") ? "'" . $theValue . "'" : "NULL";
      break;
    case "defined":
      $theValue = ($theValue != "") ? $theDefinedValue : $theNotDefinedValue;
      break;
  }
  return $theValue;
}
}






$editFormAction = $_SERVER['PHP_SELF'];
if (isset($_SERVER['QUERY_STRING'])) {
  $editFormAction .= "?" . htmlentities($_SERVER['QUERY_STRING']);
}
if ((isset($_POST["MM_insert"])) && ($_POST["MM_insert"] == "form1")) {
  $insertSQL = sprintf("INSERT INTO tbl_customer (customer_code, customer_first_name, customer_last_name, country, city, address, contact_number, gender, email_address, password) VALUES (%s, %s, %s, %s, %s, %s, %s, %s, %s, %s)",
                       GetSQLValueString($_POST['customer_code'], "int"),
                       GetSQLValueString($_POST['customer_first_name'], "text"),
                       GetSQLValueString($_POST['customer_last_name'], "text"),
                       GetSQLValueString($_POST['country'], "text"),
                       GetSQLValueString($_POST['city'], "text"),
                       GetSQLValueString($_POST['address'], "text"),
                       GetSQLValueString($_POST['contact_number'], "int"),
                       GetSQLValueString($_POST['gender'], "text"),
                       GetSQLValueString($_POST['email_address'], "text"),
                       GetSQLValueString($_POST['password'], "text"));

  mysql_select_db($database_GoldenCityTravel, $GoldenCityTravel);
  $Result1 = mysql_query($insertSQL, $GoldenCityTravel) or die(mysql_error());

  $insertGoTo = "cust_reg_success.php";
  if (isset($_SERVER['QUERY_STRING'])) {
    $insertGoTo .= (strpos($insertGoTo, '?')) ? "&" : "?";
    $insertGoTo .= $_SERVER['QUERY_STRING'];
  }
  header(sprintf("Location: %s", $insertGoTo));
}

if ((isset($_POST["MM_insert"])) && ($_POST["MM_insert"] == "form2")) {
  $insertSQL = sprintf("INSERT INTO tbl_customer (customer_first_name, customer_last_name, country, city, address, contact_number, gender, email_address, password) VALUES (%s, %s, %s, %s, %s, %s, %s, %s, %s)",
                       GetSQLValueString($_POST['customer_first_name'], "text"),
                       GetSQLValueString($_POST['customer_last_name'], "text"),
                       GetSQLValueString($_POST['country'], "text"),
                       GetSQLValueString($_POST['city'], "text"),
                       GetSQLValueString($_POST['address'], "text"),
                       GetSQLValueString($_POST['contact_number'], "int"),
                       GetSQLValueString($_POST['gender'], "text"),
                       GetSQLValueString($_POST['email_address'], "text"),
                       GetSQLValueString($_POST['password'], "text"));

  mysql_select_db($database_GoldenCityTravel, $GoldenCityTravel);
  $Result1 = mysql_query($insertSQL, $GoldenCityTravel) or die(mysql_error());

  $insertGoTo = "cust_reg_success.php";
  if (isset($_SERVER['QUERY_STRING'])) {
    $insertGoTo .= (strpos($insertGoTo, '?')) ? "&" : "?";
    $insertGoTo .= $_SERVER['QUERY_STRING'];
  }
  header(sprintf("Location: %s", $insertGoTo));
}

if ((isset($_POST["MM_update"])) && ($_POST["MM_update"] == "form3")) {
  $updateSQL = sprintf("UPDATE tbl_customer SET country=%s, city=%s, address=%s, contact_number=%s, email_address=%s, password=%s WHERE customer_code=%s",
                       GetSQLValueString($_POST['country'], "text"),
                       GetSQLValueString($_POST['city'], "text"),
                       GetSQLValueString($_POST['address'], "text"),
                       GetSQLValueString($_POST['contact_number'], "int"),
                       GetSQLValueString($_POST['email_address'], "text"),
                       GetSQLValueString($_POST['password'], "text"),
                       GetSQLValueString($_POST['customer_code'], "int"));

  mysql_select_db($database_GoldenCityTravel, $GoldenCityTravel);
  $Result1 = mysql_query($updateSQL, $GoldenCityTravel) or die(mysql_error());
}

mysql_select_db($database_GoldenCityTravel, $GoldenCityTravel);
$query_Reg = "SELECT * FROM tbl_customer";
$Reg = mysql_query($query_Reg, $GoldenCityTravel) or die(mysql_error());
$row_Reg = mysql_fetch_assoc($Reg);
$totalRows_Reg = mysql_num_rows($Reg);
?><!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>Registration Form</title>
</head>

<body>
<form action="<?php echo $editFormAction; ?>" method="post" name="form1" id="form1">
</form>

<form action="<?php echo $editFormAction; ?>" method="post" name="form3" id="form3">
  <table align="center">
    <tr valign="baseline">
      <td width="104" align="right" nowrap="nowrap">Country:</td>
      <td width="240"><input type="text" name="country" value="<?php echo htmlentities($row_Reg['country'], ENT_COMPAT, 'utf-8'); ?>" size="25" /></td>
    </tr>
    <tr valign="baseline">
      <td nowrap="nowrap" align="right">City:</td>
      <td><input type="text" name="city" value="<?php echo htmlentities($row_Reg['city'], ENT_COMPAT, 'utf-8'); ?>" size="25" /></td>
    </tr>
    <tr valign="baseline">
      <td nowrap="nowrap" align="right">Address:</td>
      <td><input type="text" name="address" value="<?php echo htmlentities($row_Reg['address'], ENT_COMPAT, 'utf-8'); ?>" size="30" /></td>
    </tr>
    <tr valign="baseline">
      <td nowrap="nowrap" align="right">Contact_number:</td>
      <td><input type="text" name="contact_number" value="<?php echo htmlentities($row_Reg['contact_number'], ENT_COMPAT, 'utf-8'); ?>" size="20" /></td>
    </tr>
    <tr valign="baseline">
      <td nowrap="nowrap" align="right">Email_address:</td>
      <td><input type="text" name="email_address" value="<?php echo htmlentities($row_Reg['email_address'], ENT_COMPAT, 'utf-8'); ?>" size="40" /></td>
    </tr>
    <tr valign="baseline">
      <td nowrap="nowrap" align="right">Password:</td>
      <td><input name="password" type="password" value="<?php echo htmlentities($row_Reg['password'], ENT_COMPAT, 'utf-8'); ?>" size="6" maxlength="40" /></td>
    </tr>
    <tr valign="baseline">
      <td nowrap="nowrap" align="right"> </td>
      <td><input type="submit" value="Update record" /></td>
    </tr>
  </table>
  <input type="hidden" name="MM_update" value="form3" />
  <input type="hidden" name="customer_code" value="<?php echo $row_Reg['customer_code']; ?>" />
</form>
<p> </p>
<p> </p>
</body>
</html>
<?php
mysql_free_result($Reg);
?>

لا اعرف ما استخدم الكوكيز ام السيشنز ؟

تم تعديل هذه المشاركة بواسطة Sameh11 في 12 يناير 2011 في 23:41

#2

الـ session أضمن.

بشكل عام، session_start() يجب أن تكون في بداية الملف.. قبل أي شئ آخر، حتى قبل require_once أو include

أعد التجربة من جديد فلم أطلع على الكود بشكل كامل.

Do as I say, not as I do

We are Anonymous. We are Legion. We don't forgive. We don't forget

#3

وعليكم السلام ورحمة الله

اضافة لما ذكر الاستاذ Xacker عن الـ session_start()

لقد نسيت أن تضيف شرط لتحديد المستخدم الذي تريد تعديله في صفحة التعديل فإذا نظرت إلى هذا السطر :

$query_Reg = "SELECT * FROM tbl_customer";

أنت تقوم باستدعاء جميع المستخدمين الموجودين في الجدول دفعة واحدة و تقوم بالطباعة لمرة واحدة فسيتم طباعة بيانات اول مستخدم في قاعدة البيانات في كل مرة

لكي تقوم باستدعاء المستخدم الذي قام بتسجيل الدخول فقط عليك اضافة شرط كهذا مثلاً :

$query_Reg = "SELECT * FROM tbl_customer where email_address='$_SESSION[MM_Username]'";

بتوفيق الله...

تم تعديل هذه المشاركة بواسطة MoHaMMaD Pro في 13 يناير 2011 في 00:58

Everything will be fine when we TALK LESS, DO MORE


#4

الحمدلله اشتغل شاكر لكم

استفسار ما معني MM_Username]

هل هذا يعني اني ساستخدم هذا الكود في جميع الصفحات ..

علي سبيل المثال لقد سجل اسم المستخدم الدخول وانتقل مباشرة للصفحة الرئيسية ومن الصفحة الرئيسية الي جميع الصفح المتوفرة لدية

هل هذا يعني ساكتب هذان الكودان في جميع الصفح؟

تم تعديل هذه المشاركة بواسطة Sameh11 في 13 يناير 2011 في 11:12

مواضيع مشابهة