login page php wouldnt redirect

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • leesyaa
    New Member
    • Jan 2014
    • 20

    #1

    login page php wouldnt redirect

    hi, im trying to make a login page that call the user from two different table (admin & user). it doesnt have any error but it somehow doesnt link to the required page.


    login.php
    Code:
    if(isset($_POST['submit']))
    	{	
    		include 'connection.php';
    		
    		$username = trim(addslashes($_POST['username']));
    		$password = trim(addslashes($_POST['password']));
    		
    		if ($username != '' && $password != '') 
    		{
    			
    			$sql = "SELECT * FROM admin
    						WHERE admin_username = '$username' AND admin_password = '$password'";
    			$result = mysql_query($sql) or die('Query failed. ' . mysql_error());
    			$row = mysql_fetch_array($result, MYSQL_ASSOC);
    			
    			if (mysql_num_rows($result) == 1) 
    			{
    				$_SESSION['admin_name']=$row['admin_name'];
    				$_SESSION['admin_addr']=$row['admin_addr'];
    				$_SESSION['admin_position']=$row['admin_position'];	
    				$_SESSION['admin_ic']=$row['admin_ic'];
    									
    				if(isset($_SESSION['admin_username']) && $_SESSION['admin_username'] === TRUE )
    				{
    					print "<script>";
    					print "window.alert('Welcome Admin'); self.location='admin.php';"; 
    					print "</script>";						
    				}
    				else
    				{
    				echo "<script languange = 'Javascript'>
    				alert('please check again!!');
    				location.href = 'login.php';</script>";
    				}																	
    			}
    		}
    	} 
    						
    		
    		if(isset($_POST['submit']))
    		{	
    			include 'connection.php';
    		
    			$username = trim(addslashes($_POST['username']));
    			$password = trim(addslashes($_POST['password']));
    		
    			if ($username != '' && $password != '') 
    			{
    			
    				$sql = "SELECT * FROM staff
    							WHERE staff_username = '$username' AND staff_password = '$password'";
    				$result = mysql_query($sql) or die('Query failed. ' . mysql_error());
    				$row = mysql_fetch_array($result, MYSQL_ASSOC);
    			
    				if (mysql_num_rows($result) == 1) 
    				{
    					$_SESSION['staff_name']=$row['staff_name'];
    					$_SESSION['staff_addr']=$row['staff_addr'];
    					$_SESSION['staff_position']=$row['staff_position'];	
    					$_SESSION['staff_ic']=$row['staff_ic'];
    									
    					if ($_SESSION['staff_username']=='staff_username')
    					{
    						print "<script>";
    						print "window.alert('Welcome user'); self.location='user.php';"; 
    						print "</script>";						
    					}
    					else
    					{
    					echo "<script languange = 'Javascript'>
    					alert('Please check again!!');
    					location.href = 'login.php';</script>";			
    					}
    				}
    			}			
    		}
    						
    
    ?>

    the outcome will always be "please check again!" eventhough the username and password is correct.

    why? :(
  • Exequiel
    Contributor
    • Jul 2012
    • 288

    #2
    It did not work because the $_SESSION['staff_username '] is empty, you did not set a value for that session.
    put this code first
    Code:
    $_SESSION['staff_username']='staff_username';
    before your
    Code:
     if ($_SESSION['staff_username']=='staff_username')
    and also for admin.
    try it.

    Comment

    • leesyaa
      New Member
      • Jan 2014
      • 20

      #3
      thanks! it work well :D

      but now it doesnt respond to the

      Code:
      <?php 
      session_start();
      if(!isset($_SESSION['admin_username'])) {
      	header("Location: error.php");
      	}
      
      ?>
      that i set to secure the page.

      the user could still open the admin page :(

      Comment

      • Exequiel
        Contributor
        • Jul 2012
        • 288

        #4
        Try this code, in this logic we need to check if the session is empty or not, if the session is not empty redirect for admin/staff page, if the session is empty redirect to login page.

        Code:
        <?php
        session_start();
        ob_start();
        include 'coonnectionToDB.php';//your connection to your database
        
        if(!empty($_SESSION['admin_username']))
        {
         header("Location: adminpage.php");
        }
        else if(!empty($_SESSION['staff_username']))
        {
         header("Location: staffpage.php");
        }
        else
        {
         header("Location: login.php");
        }
        ?>

        Comment

        • Rabbit
          Recognized Expert MVP
          • Jan 2007
          • 12517

          #5
          You never check to see if they are an admin before showing the admin page. You merely set a variable do it's always true.

          Comment

          • Exequiel
            Contributor
            • Jul 2012
            • 288

            #6
            leesyaa's database design is not ok for me, she can make only 1 table for an account for admin and staff and determine what user type the user is.

            Comment

            Working...