[php] simple login - need a pro to optimize

Joined
Aug 8, 2004
Messages
3,892
Reaction score
20
Needlesly complex and even possibly unsecure since you don't check any of your variables. Especially if you plan on using this in combination with a database later on you're leaving yourself pretty much wide open to SQL injects.

Also, instead of <?php echo $current_page; ?> you can simply write <?=$current_page?> (though to be honoust I discourage the use of PHP in HTML alltogether)

Furthermore you check certain pages several times: when for instance you include form.generator.php you already checked in index.php for userlevel. Superflious. Better is to simply disallow direct acces to form.generator.php (by means of a .htacces file for instance) and redirect all requests to your index.php.

Also, you don't close your HTML tags. Not nice. Not to mention the lack of doctype specification - there goes your W3C compliancy.

Lastly, if you want to check for certain values in an array like you do with username in array, simply is if(in_array("needle", "haystack") {**.

Anyway, nice attempt but there is still a lot to improve :)
 
FragFrog said:
Needlesly complex and even possibly unsecure since you don't check any of your variables. Especially if you plan on using this in combination with a database later on you're leaving yourself pretty much wide open to SQL injects.

Also, instead of <?php echo $current_page; ?> you can simply write <?=$current_page?> (though to be honoust I discourage the use of PHP in HTML alltogether)

Furthermore you check certain pages several times: when for instance you include form.generator.php you already checked in index.php for userlevel. Superflious. Better is to simply disallow direct acces to form.generator.php (by means of a .htacces file for instance) and redirect all requests to your index.php.

Also, you don't close your HTML tags. Not nice. Not to mention the lack of doctype specification - there goes your W3C compliancy.

Lastly, if you want to check for certain values in an array like you do with username in array, simply is if(in_array("needle", "haystack") {**.

Anyway, nice attempt but there is still a lot to improve :)
what's the detailed/full
if(in_array("needle", "haystack") {**
syntax?
 
Well, every line of the script I am posting here is written by me. Finally, I had done something bigger than simple form submitting.

So here's a login script, which has user array which is checked every time the page is executed. The username/pwd is compared with a cookie and if cookie with data meets, the page is being displayed. If the usr/pwd is not correct you will see the login screen.

Now, the cookie expires in 20 seconds (I just needed this not to wait long till it expires but later it will be longer). And the username/pwd are raw atm. - I will change this by myself.

So what I am asking is to drop an eye on source and give suggestions to me, what should be corrected, wrong, etc., since I am really a beginner. Don't know if you like my method of page refreshing with HEADER, but this seems to be very useful to this kind of scripts, because you may not hit back button and refresh button wouln't give double submit form. BUT, it seems that firefox wouln't operate such script at all.

The db wouln't be big, so I am not planning to add mysql/sqlite for now. I am not ready for trying this since queries look so hard to understand for me..

Any suggestions, comments and corrections are welcome.

TY
 

Attachments

Nicely done, but I discourage the use of die() because if someone were to implement this in their site, it would stop the rest of the script, even the html portion, from excecuting.

[N]asser` ~ Out
 
my idea of a login script.

is just a simple php include that is opened by all the files in ur website
lets say login.php

was is inside it:

1. function to check if user/pass cookie or session is found
if found: will decrypt cookies and authenticate
if authenticated: trigger website to show logined
if not: remain dormant
2. function to access login POSTs
if POST: accept and authenticate
if authenticated: encrypt and save as cookie or session
once saved: #1 will then handle the rest.
3. function to logout

that simple.. doesnt have to be very complicated.
u can add many things like preg checks for unknown characters.... etc etc
 
Back