【问题标题】:After logging out and pressing back button the same page is showing in PHP注销并按返回按钮后,PHP 中显示相同的页面
【发布时间】:2018-05-13 05:59:02
【问题描述】:

我正在使用带有会话的 php。注销后它会重定向到登录页面,但在按下返回按钮后它再次向我显示没有登录的页面。我怎么解决这个问题。提前致谢

index.php

<form style="padding-left: 50px; padding-right: 50px;" action="func.php" method="post">
  <label for="uname" style="color:white;"><b>Username</b></label>
  <input type="text" placeholder="Enter Username" name="uname" style="border-radius: 10px;" required>

  <label for="psw" style="color:white;"><b>Password</b></label>
  <input type="password" placeholder="Enter Password" name="psw" style="border-radius: 10px;" required>

  <button type="submit" name="login_submit" class="b1">Login</button>
</form>

func.php

<?php                                                        
session_start();  
$con=mysqli_connect("localhost","root","","forestdb"); 
if(isset($_POST['login_submit'])){                     
$username=$_POST['uname'];                           
$password=$_POST['psw'];                                       
$query="select * from login where username='$username' and password='$password';";                        
$result=mysqli_query($con,$query); 
if(mysqli_num_rows($result)==1)
{
    $_SESSION['username']=1;
    header("Location:create_journal.php");
}
else{
    echo "<script>alert('Enter Correct Details!!')</script>";
    echo "<script>window.open('index.php', '_self')</script>";
}
}
?>

create_journal.php

<li><a href="logout.php" style="color:white;"  onmouseover='this.style.color="#08367f"' onmouseout='this.style.color="white"'><span class="glyphicon glyphicon-log-out"></span> Logout</a></li>

注销.php

<?php                                                        
session_start();                                           
session_destroy();                              
header("Location:index.php");                                               
?>

【问题讨论】:

  • 密码应该永远以纯文本形式存储。他们应该总是被散列!
  • 您实际上并没有检查 会话。首先检查会话是否有效,然后显示页面,否则重定向。

标签: javascript php html ajax


【解决方案1】:

首先,您的代码很容易受到 SQL 注入的影响,请使用 prepared statements 并阅读 here 所说的内容。

其次,您似乎没有检查是否设置了$_SESSION['username'],这意味着,如果您知道要访问的url,则无需登录即可访问该页面,这反过来意味着您可以返回一页,您将看到完全相同的内容。

【讨论】:

    【解决方案2】:

    为此,您必须在代码中使用会话标签。

    您的会话必须以登录开始

    // start the session 
    session_start(); 
    

    您的会话会随着注销而销毁。

    // destroy the session 
    session_destroy(); 
    

    使用它可以解决您的问题。

    您可以通过以下方式更好地理解:https://www.w3schools.com/php/php_sessions.asp

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 2023-02-21
      • 2012-05-17
      • 2020-06-04
      • 2014-10-22
      • 2014-05-03
      • 2017-04-07
      • 2013-07-20
      相关资源
      最近更新 更多