Skip to page content or skip to Accesskey List.
Search evolt.org
evolt.org login: or register

Work

Main Page Content

PHP Login System with Admin Features

Rated 4.59 (Ratings: 33) (Add your rating)

Log in to add a comment
(2473 comments so far)

Want more?

 
Picture of jpmaster77

JP

Member info | Full bio

User since: January 10, 2004

Last login: September 12, 2008

Articles written: 2

Introduction

I wrote the popular evolt.org tutorial PHP Login Script with Remember Me Feature mainly as an introduction to user sessions and cookies in PHP. Since it was created as a learning tool, many advanced features were left out of the script. By popular demand, I have written and am presenting here a complete Login System, with all the features that were left out of the first script, that can be easily integrated into any website.

Notes

This article is intended primarily for intermediate to advanced users of PHP, as it is not exactly a tutorial, but a description of the implementation of an advanced Login System. Beginners who are looking to learn about user session and cookies in PHP are advised to read the above mentioned tutorial before reading this article.

Features

Here are some of the features in this Login System that weren't included in the initial tutorial:

  • Better Security - Passwords are not stored in cookies, randomly generated ids take their place.
  • Member Levels - Now users can be differentiated by what level they are (user, admin, etc.)
  • Admin Center - As an admin, you have full control over registered users. You can view user info, upgrade/demote user levels, delete users, delete inactive users, and ban users.
  • Visitor Tracking - You can now tell how many guests and users are actively viewing your site, and who those users are. You also know how many total members your site has.
  • Account Info - Users can now view their own information, and edit it as well. They can also see the information of other users.
  • Form Helper - No more ugly error pages! Now users are redirected to the form they filled out and the errors that have occurred are displayed.
  • Forgot Password - Users who forget their password can have a new one generated for them and sent to their email address.
  • Email - Now emails can be sent to newly registered users.
  • Miscellaneous - Much better code design, smooth page transitions, and MORE!

Database

All the tables needed for the Login System are written in the file dbtables.sql. You can look at the file and create each table manually or you can just run the file with mysql and it will create all the necessary tables automatically.

dbtables.sql

#
#  dbtables.sql
#
#  Simplifies the task of creating all the database tables
#  used by the login system.
#
#  Can be run from command prompt by typing:
#
#  mysql -u yourusername -D yourdatabasename < dbtables.sql
#
#  That's with dbtables.sql in the mysql bin directory, but
#  you can just include the path to dbtables.sql and that's
#  fine too.
#
#  Written by: Jpmaster77 a.k.a. The Grandmaster of C++ (GMC)
#  Last Updated: August 13, 2004
#

#
#  Table structure for users table
#
DROP TABLE IF EXISTS users;

CREATE TABLE users (
 username varchar(30) primary key,
 password varchar(32),
 userid varchar(32),
 userlevel tinyint(1) unsigned not null,
 email varchar(50),
 timestamp int(11) unsigned not null
);


#
#  Table structure for active users table
#
DROP TABLE IF EXISTS active_users;

CREATE TABLE active_users (
 username varchar(30) primary key,
 timestamp int(11) unsigned not null
);


#
#  Table structure for active guests table
#
DROP TABLE IF EXISTS active_guests;

CREATE TABLE active_guests (
 ip varchar(15) primary key,
 timestamp int(11) unsigned not null
);


#
#  Table structure for banned users table
#
DROP TABLE IF EXISTS banned_users;

CREATE TABLE banned_users (
 username varchar(30) primary key,
 timestamp int(11) unsigned not null
);

Code Design

I will be presenting the Login System by showing only the important files, describing what they do and how they interact with each other. By reading this you should get a good idea of how the Login System works and understand how to integrate it into your website. It is important to note before you start that the code relies on classes and the key variables of this Login System are class objects.

constants.php

This file will contain all the constants and important information used by the login system. Here you specify stuff like your database username and password, the admin account name (which will be able to create other admins), visitor timeouts, email options, etc.

<?
/**
 * Constants.php
 *
 * This file is intended to group all constants to
 * make it easier for the site administrator to tweak
 * the login script.
 *
 * Written by: Jpmaster77 a.k.a. The Grandmaster of C++ (GMC)
 * Last Updated: August 19, 2004
 */
 
/**
 * Database Constants - these constants are required
 * in order for there to be a successful connection
 * to the MySQL database. Make sure the information is
 * correct.
 */
define("DB_SERVER", "localhost");
define("DB_USER", "your_name");
define("DB_PASS", "your_pass");
define("DB_NAME", "your_dbname");

/**
 * Database Table Constants - these constants
 * hold the names of all the database tables used
 * in the script.
 */
define("TBL_USERS", "users");
define("TBL_ACTIVE_USERS",  "active_users");
define("TBL_ACTIVE_GUESTS", "active_guests");
define("TBL_BANNED_USERS",  "banned_users");

/**
 * Special Names and Level Constants - the admin
 * page will only be accessible to the user with
 * the admin name and also to those users at the
 * admin user level. Feel free to change the names
 * and level constants as you see fit, you may
 * also add additional level specifications.
 * Levels must be digits between 0-9.
 */
define("ADMIN_NAME", "admin");
define("GUEST_NAME", "Guest");
define("ADMIN_LEVEL", 9);
define("USER_LEVEL",  1);
define("GUEST_LEVEL", 0);

/**
 * This boolean constant controls whether or
 * not the script keeps track of active users
 * and active guests who are visiting the site.
 */
define("TRACK_VISITORS", true);

/**
 * Timeout Constants - these constants refer to
 * the maximum amount of time (in minutes) after
 * their last page fresh that a user and guest
 * are still considered active visitors.
 */
define("USER_TIMEOUT", 10);
define("GUEST_TIMEOUT", 5);

/**
 * Cookie Constants - these are the parameters
 * to the setcookie function call, change them
 * if necessary to fit your website. If you need
 * help, visit www.php.net for more info.
 * <http://www.php.net/manual/en/function.setcookie.php>
 */
define("COOKIE_EXPIRE", 60*60*24*100);  //100 days by default
define("COOKIE_PATH", "/");  //Available in whole domain

/**
 * Email Constants - these specify what goes in
 * the from field in the emails that the script
 * sends to users, and whether to send a
 * welcome email to newly registered users.
 */
define("EMAIL_FROM_NAME", "YourName");
define("EMAIL_FROM_ADDR", "youremail@address.com");
define("EMAIL_WELCOME", false);

/**
 * This constant forces all users to have
 * lowercase usernames, capital letters are
 * converted automatically.
 */
define("ALL_LOWERCASE", false);
?>

database.php

This file contains all the functions that perform database operations, like adding new users to the database table, verifying username and password, retrieving user info, deleting users, etc. It also makes the initial connection to the MySQL database. The functions are members of the Database class, which means they can only be called through a variable of that class. At the end of the file, the $database variable is defined, which is the class object that gets used throughout the Login System.

<?
/**
 * Database.php
 * 
 * The Database class is meant to simplify the task of accessing
 * information from the website's database.
 *
 * Written by: Jpmaster77 a.k.a. The Grandmaster of C++ (GMC)
 * Last Updated: August 17, 2004
 */
include("constants.php");
      
class MySQLDB
{
   var $connection;         //The MySQL database connection
   var $num_active_users;   //Number of active users viewing site
   var $num_active_guests;  //Number of active guests viewing site
   var $num_members;        //Number of signed-up users
   /* Note: call getNumMembers() to access $num_members! */

   /* Class constructor */
   function MySQLDB(){
      /* Make connection to database */
      $this->connection = mysql_connect(DB_SERVER, DB_USER, DB_PASS) or die(mysql_error());
      mysql_select_db(DB_NAME, $this->connection) or die(mysql_error());
      
      /**
       * Only query database to find out number of members
       * when getNumMembers() is called for the first time,
       * until then, default value set.
       */
      $this->num_members = -1;
      
      if(TRACK_VISITORS){
         /* Calculate number of users at site */
         $this->calcNumActiveUsers();
      
         /* Calculate number of guests at site */
         $this->calcNumActiveGuests();
      }
   }

   /**
    * confirmUserPass - Checks whether or not the given
    * username is in the database, if so it checks if the
    * given password is the same password in the database
    * for that user. If the user doesn't exist or if the
    * passwords don't match up, it returns an error code
    * (1 or 2). On success it returns 0.
    */
   function confirmUserPass($username, $password){
      /* Add slashes if necessary (for query) */
      if(!get_magic_quotes_gpc()) {
	      $username = addslashes($username);
      }

      /* Verify that user is in database */
      $q = "SELECT password FROM ".TBL_USERS." WHERE username = '$username'";
      $result = mysql_query($q, $this->connection);
      if(!$result || (mysql_numrows($result) < 1)){
         return 1; //Indicates username failure
      }

      /* Retrieve password from result, strip slashes */
      $dbarray = mysql_fetch_array($result);
      $dbarray['password'] = stripslashes($dbarray['password']);
      $password = stripslashes($password);

      /* Validate that password is correct */
      if($password == $dbarray['password']){
         return 0; //Success! Username and password confirmed
      }
      else{
         return 2; //Indicates password failure
      }
   }
   
   /**
    * confirmUserID - Checks whether or not the given
    * username is in the database, if so it checks if the
    * given userid is the same userid in the database
    * for that user. If the user doesn't exist or if the
    * userids don't match up, it returns an error code
    * (1 or 2). On success it returns 0.
    */
   function confirmUserID($username, $userid){
      /* Add slashes if necessary (for query) */
      if(!get_magic_quotes_gpc()) {
	      $username = addslashes($username);
      }

      /* Verify that user is in database */
      $q = "SELECT userid FROM ".TBL_USERS." WHERE username = '$username'";
      $result = mysql_query($q, $this->connection);
      if(!$result || (mysql_numrows($result) < 1)){
         return 1; //Indicates username failure
      }

      /* Retrieve userid from result, strip slashes */
      $dbarray = mysql_fetch_array($result);
      $dbarray['userid'] = stripslashes($dbarray['userid']);
      $userid = stripslashes($userid);

      /* Validate that userid is correct */
      if($userid == $dbarray['userid']){
         return 0; //Success! Username and userid confirmed
      }
      else{
         return 2; //Indicates userid invalid
      }
   }
   
   /**
    * usernameTaken - Returns true if the username has
    * been taken by another user, false otherwise.
    */
   function usernameTaken($username){
      if(!get_magic_quotes_gpc()){
         $username = addslashes($username);
      }
      $q = "SELECT username FROM ".TBL_USERS." WHERE username = '$username'";
      $result = mysql_query($q, $this->connection);
      return (mysql_numrows($result) > 0);
   }
   
   /**
    * usernameBanned - Returns true if the username has
    * been banned by the administrator.
    */
   function usernameBanned($username){
      if(!get_magic_quotes_gpc()){
         $username = addslashes($username);
      }
      $q = "SELECT username FROM ".TBL_BANNED_USERS." WHERE username = '$username'";
      $result = mysql_query($q, $this->connection);
      return (mysql_numrows($result) > 0);
   }
   
   /**
    * addNewUser - Inserts the given (username, password, email)
    * info into the database. Appropriate user level is set.
    * Returns true on success, false otherwise.
    */
   function addNewUser($username, $password, $email){
      $time = time();
      /* If admin sign up, give admin user level */
      if(strcasecmp($username, ADMIN_NAME) == 0){
         $ulevel = ADMIN_LEVEL;
      }else{
         $ulevel = USER_LEVEL;
      }
      $q = "INSERT INTO ".TBL_USERS." VALUES ('$username', '$password', '0', $ulevel, '$email', $time)";
      return mysql_query($q, $this->connection);
   }
   
   /**
    * updateUserField - Updates a field, specified by the field
    * parameter, in the user's row of the database.
    */
   function updateUserField($username, $field, $value){
      $q = "UPDATE ".TBL_USERS." SET ".$field." = '$value' WHERE username = '$username'";
      return mysql_query($q, $this->connection);
   }
   
   /**
    * getUserInfo - Returns the result array from a mysql
    * query asking for all information stored regarding
    * the given username. If query fails, NULL is returned.
    */
   function getUserInfo($username){
      $q = "SELECT * FROM ".TBL_USERS." WHERE username = '$username'";
      $result = mysql_query($q, $this->connection);
      /* Error occurred, return given name by default */
      if(!$result || (mysql_numrows($result) < 1)){
         return NULL;
      }
      /* Return result array */
      $dbarray = mysql_fetch_array($result);
      return $dbarray;
   }
   
   /**
    * getNumMembers - Returns the number of signed-up users
    * of the website, banned members not included. The first
    * time the function is called on page load, the database
    * is queried, on subsequent calls, the stored result
    * is returned. This is to improve efficiency, effectively
    * not querying the database when no call is made.
    */
   function getNumMembers(){
      if($this->num_members < 0){
         $q = "SELECT * FROM ".TBL_USERS;
         $result = mysql_query($q, $this->connection);
         $this->num_members = mysql_numrows($result);
      }
      return $this->num_members;
   }
   
   /**
    * calcNumActiveUsers - Finds out how many active users
    * are viewing site and sets class variable accordingly.
    */
   function calcNumActiveUsers(){
      /* Calculate number of users at site */
      $q = "SELECT * FROM ".TBL_ACTIVE_USERS;
      $result = mysql_query($q, $this->connection);
      $this->num_active_users = mysql_numrows($result);
   }
   
   /**
    * calcNumActiveGuests - Finds out how many active guests
    * are viewing site and sets class variable accordingly.
    */
   function calcNumActiveGuests(){
      /* Calculate number of guests at site */
      $q = "SELECT * FROM ".TBL_ACTIVE_GUESTS;
      $result = mysql_query($q, $this->connection);
      $this->num_active_guests = mysql_numrows($result);
   }
   
   /**
    * addActiveUser - Updates username's last active timestamp
    * in the database, and also adds him to the table of
    * active users, or updates timestamp if already there.
    */
   function addActiveUser($username, $time){
      $q = "UPDATE ".TBL_USERS." SET timestamp = '$time' WHERE username = '$username'";
      mysql_query($q, $this->connection);
      
      if(!TRACK_VISITORS) return;
      $q = "REPLACE INTO ".TBL_ACTIVE_USERS." VALUES ('$username', '$time')";
      mysql_query($q, $this->connection);
      $this->calcNumActiveUsers();
   }
   
   /* addActiveGuest - Adds guest to active guests table */
   function addActiveGuest($ip, $time){
      if(!TRACK_VISITORS) return;
      $q = "REPLACE INTO ".TBL_ACTIVE_GUESTS." VALUES ('$ip', '$time')";
      mysql_query($q, $this->connection);
      $this->calcNumActiveGuests();
   }
   
   /* These functions are self explanatory, no need for comments */
   
   /* removeActiveUser */
   function removeActiveUser($username){
      if(!TRACK_VISITORS) return;
      $q = "DELETE FROM ".TBL_ACTIVE_USERS." WHERE username = '$username'";
      mysql_query($q, $this->connection);
      $this->calcNumActiveUsers();
   }
   
   /* removeActiveGuest */
   function removeActiveGuest($ip){
      if(!TRACK_VISITORS) return;
      $q = "DELETE FROM ".TBL_ACTIVE_GUESTS." WHERE ip = '$ip'";
      mysql_query($q, $this->connection);
      $this->calcNumActiveGuests();
   }
   
   /* removeInactiveUsers */
   function removeInactiveUsers(){
      if(!TRACK_VISITORS) return;
      $timeout = time()-USER_TIMEOUT*60;
      $q = "DELETE FROM ".TBL_ACTIVE_USERS." WHERE timestamp < $timeout";
      mysql_query($q, $this->connection);
      $this->calcNumActiveUsers();
   }

   /* removeInactiveGuests */
   function removeInactiveGuests(){
      if(!TRACK_VISITORS) return;
      $timeout = time()-GUEST_TIMEOUT*60;
      $q = "DELETE FROM ".TBL_ACTIVE_GUESTS." WHERE timestamp < $timeout";
      mysql_query($q, $this->connection);
      $this->calcNumActiveGuests();
   }
   
   /**
    * query - Performs the given query on the database and
    * returns the result, which may be false, true or a
    * resource identifier.
    */
   function query($query){
      return mysql_query($query, $this->connection);
   }
};

/* Create database connection */
$database = new MySQLDB;

?>

session.php

This file is the heart and soul of the Login System. It contains the code to login, logout and register users. It also holds all the information about the user that is viewing the site. All the variables and functions are part of the Session class, and the $session class object variable is created so you can access those variables and functions. You will be using this class object whenever you want to get information about the visitor of your site, like whether or not they are logged in. How to use this object, and others as well, is apparent when looking through the example pages which are given (main.php, userinfo.php, etc.).

<?
/**
 * Session.php
 * 
 * The Session class is meant to simplify the task of keeping
 * track of logged in users and also guests.
 *
 * Written by: Jpmaster77 a.k.a. The Grandmaster of C++ (GMC)
 * Last Updated: August 19, 2004
 */
include("database.php");
include("mailer.php");
include("form.php");

class Session
{
   var $username;     //Username given on sign-up
   var $userid;       //Random value generated on current login
   var $userlevel;    //The level to which the user pertains
   var $time;         //Time user was last active (page loaded)
   var $logged_in;    //True if user is logged in, false otherwise
   var $userinfo = array();  //The array holding all user info
   var $url;          //The page url current being viewed
   var $referrer;     //Last recorded site page viewed
   /**
    * Note: referrer should really only be considered the actual
    * page referrer in process.php, any other time it may be
    * inaccurate.
    */

   /* Class constructor */
   function Session(){
      $this->time = time();
      $this->startSession();
   }

   /**
    * startSession - Performs all the actions necessary to 
    * initialize this session object. Tries to determine if the
    * the user has logged in already, and sets the variables 
    * accordingly. Also takes advantage of this page load to
    * update the active visitors tables.
    */
   function startSession(){
      global $database;  //The database connection
      session_start();   //Tell PHP to start the session

      /* Determine if user is logged in */
      $this->logged_in = $this->checkLogin();

      /**
       * Set guest value to users not logged in, and update
       * active guests table accordingly.
       */
      if(!$this->logged_in){
         $this->username = $_SESSION['username'] = GUEST_NAME;
         $this->userlevel = GUEST_LEVEL;
         $database->addActiveGuest($_SERVER['REMOTE_ADDR'], $this->time);
      }
      /* Update users last active timestamp */
      else{
         $database->addActiveUser($this->username, $this->time);
      }
      
      /* Remove inactive visitors from database */
      $database->removeInactiveUsers();
      $database->removeInactiveGuests();
      
      /* Set referrer page */
      if(isset($_SESSION['url'])){
         $this->referrer = $_SESSION['url'];
      }else{
         $this->referrer = "/";
      }

      /* Set current url */
      $this->url = $_SESSION['url'] = $_SERVER['PHP_SELF'];
   }

   /**
    * checkLogin - Checks if the user has already previously
    * logged in, and a session with the user has already been
    * established. Also checks to see if user has been remembered.
    * If so, the database is queried to make sure of the user's 
    * authenticity. Returns true if the user has logged in.
    */
   function checkLogin(){
      global $database;  //The database connection
      /* Check if user has been remembered */
      if(isset($_COOKIE['cookname']) && isset($_COOKIE['cookid'])){
         $this->username = $_SESSION['username'] = $_COOKIE['cookname'];
         $this->userid   = $_SESSION['userid']   = $_COOKIE['cookid'];
      }

      /* Username and userid have been set and not guest */
      if(isset($_SESSION['username']) && isset($_SESSION['userid']) &&
         $_SESSION['username'] != GUEST_NAME){
         /* Confirm that username and userid are valid */
         if($database->confirmUserID($_SESSION['username'], $_SESSION['userid']) != 0){
            /* Variables are incorrect, user not logged in */
            unset($_SESSION['username']);
            unset($_SESSION['userid']);
            return false;
         }

         /* User is logged in, set class variables */
         $this->userinfo  = $database->getUserInfo($_SESSION['username']);
         $this->username  = $this->userinfo['username'];
         $this->userid    = $this->userinfo['userid'];
         $this->userlevel = $this->userinfo['userlevel'];
         return true;
      }
      /* User not logged in */
      else{
         return false;
      }
   }

   /**
    * login - The user has submitted his username and password
    * through the login form, this function checks the authenticity
    * of that information in the database and creates the session.
    * Effectively logging in the user if all goes well.
    */
   function login($subuser, $subpass, $subremember){
      global $database, $form;  //The database and form object

      /* Username error checking */
      $field = "user";  //Use field name for username
      if(!$subuser || strlen($subuser = trim($subuser)) == 0){
         $form->setError($field, "* Username not entered");
      }
      else{
         /* Check if username is not alphanumeric */
         if(!eregi("^([0-9a-z])*$", $subuser)){
            $form->setError($field, "* Username not alphanumeric");
         }
      }

      /* Password error checking */
      $field = "pass";  //Use field name for password
      if(!$subpass){
         $form->setError($field, "* Password not entered");
      }
      
      /* Return if form errors exist */
      if($form->num_errors > 0){
         return false;
      }

      /* Checks that username is in database and password is correct */
      $subuser = stripslashes($subuser);
      $result = $database->confirmUserPass($subuser, md5($subpass));

      /* Check error codes */
      if($result == 1){
         $field = "user";
         $form->setError($field, "* Username not found");
      }
      else if($result == 2){
         $field = "pass";
         $form->setError($field, "* Invalid password");
      }
      
      /* Return if form errors exist */
      if($form->num_errors > 0){
         return false;
      }

      /* Username and password correct, register session variables */
      $this->userinfo  = $database->getUserInfo($subuser);
      $this->username  = $_SESSION['username'] = $this->userinfo['username'];
      $this->userid    = $_SESSION['userid']   = $this->generateRandID();
      $this->userlevel = $this->userinfo['userlevel'];
      
      /* Insert userid into database and update active users table */
      $database->updateUserField($this->username, "userid", $this->userid);
      $database->addActiveUser($this->username, $this->time);
      $database->removeActiveGuest($_SERVER['REMOTE_ADDR']);

      /**
       * This is the cool part: the user has requested that we remember that
       * he's logged in, so we set two cookies. One to hold his username,
       * and one to hold his random value userid. It expires by the time
       * specified in constants.php. Now, next time he comes to our site, we will
       * log him in automatically, but only if he didn't log out before he left.
       */
      if($subremember){
         setcookie("cookname", $this->username, time()+COOKIE_EXPIRE, COOKIE_PATH);
         setcookie("cookid",   $this->userid,   time()+COOKIE_EXPIRE, COOKIE_PATH);
      }

      /* Login completed successfully */
      return true;
   }

   /**
    * logout - Gets called when the user wants to be logged out of the
    * website. It deletes any cookies that were stored on the users
    * computer as a result of him wanting to be remembered, and also
    * unsets session variables and demotes his user level to guest.
    */
   function logout(){
      global $database;  //The database connection
      /**
       * Delete cookies - the time must be in the past,
       * so just negate what you added when creating the
       * cookie.
       */
      if(isset($_COOKIE['cookname']) && isset($_COOKIE['cookid'])){
         setcookie("cookname", "", time()-COOKIE_EXPIRE, COOKIE_PATH);
         setcookie("cookid",   "", time()-COOKIE_EXPIRE, COOKIE_PATH);
      }

      /* Unset PHP session variables */
      unset($_SESSION['username']);
      unset($_SESSION['userid']);

      /* Reflect fact that user has logged out */
      $this->logged_in = false;
      
      /**
       * Remove from active users table and add to
       * active guests tables.
       */
      $database->removeActiveUser($this->username);
      $database->addActiveGuest($_SERVER['REMOTE_ADDR'], $this->time);
      
      /* Set user level to guest */
      $this->username  = GUEST_NAME;
      $this->userlevel = GUEST_LEVEL;
   }

   /**
    * register - Gets called when the user has just submitted the
    * registration form. Determines if there were any errors with
    * the entry fields, if so, it records the errors and returns
    * 1. If no errors were found, it registers the new user and
    * returns 0. Returns 2 if registration failed.
    */
   function register($subuser, $subpass, $subemail){
      global $database, $form, $mailer;  //The database, form and mailer object
      
      /* Username error checking */
      $field = "user";  //Use field name for username
      if(!$subuser || strlen($subuser = trim($subuser)) == 0){
         $form->setError($field, "* Username not entered");
      }
      else{
         /* Spruce up username, check length */
         $subuser = stripslashes($subuser);
         if(strlen($subuser) < 5){
            $form->setError($field, "* Username below 5 characters");
         }
         else if(strlen($subuser) > 30){
            $form->setError($field, "* Username above 30 characters");
         }
         /* Check if username is not alphanumeric */
         else if(!eregi("^([0-9a-z])+$", $subuser)){
            $form->setError($field, "* Username not alphanumeric");
         }
         /* Check if username is reserved */
         else if(strcasecmp($subuser, GUEST_NAME) == 0){
            $form->setError($field, "* Username reserved word");
         }
         /* Check if username is already in use */
         else if($database->usernameTaken($subuser)){
            $form->setError($field, "* Username already in use");
         }
         /* Check if username is banned */
         else if($database->usernameBanned($subuser)){
            $form->setError($field, "* Username banned");
         }
      }

      /* Password error checking */
      $field = "pass";  //Use field name for password
      if(!$subpass){
         $form->setError($field, "* Password not entered");
      }
      else{
         /* Spruce up password and check length*/
         $subpass = stripslashes($subpass);
         if(strlen($subpass) < 4){
            $form->setError($field, "* Password too short");
         }
         /* Check if password is not alphanumeric */
         else if(!eregi("^([0-9a-z])+$", ($subpass = trim($subpass)))){
            $form->setError($field, "* Password not alphanumeric");
         }
         /**
          * Note: I trimmed the password only after I checked the length
          * because if you fill the password field up with spaces
          * it looks like a lot more characters than 4, so it looks
          * kind of stupid to report "password too short".
          */
      }
      
      /* Email error checking */
      $field = "email";  //Use field name for email
      if(!$subemail || strlen($subemail = trim($subemail)) == 0){
         $form->setError($field, "* Email not entered");
      }
      else{
         /* Check if valid email address */
         $regex = "^[_+a-z0-9-]+(\.[_+a-z0-9-]+)*"
                 ."@[a-z0-9-]+(\.[a-z0-9-]{1,})*"
                 ."\.([a-z]{2,}){1}$";
         if(!eregi($regex,$subemail)){
            $form->setError($field, "* Email invalid");
         }
         $subemail = stripslashes($subemail);
      }

      /* Errors exist, have user correct them */
      if($form->num_errors > 0){
         return 1;  //Errors with form
      }
      /* No errors, add the new account to the */
      else{
         if($database->addNewUser($subuser, md5($subpass), $subemail)){
            if(EMAIL_WELCOME){
               $mailer->sendWelcome($subuser,$subemail,$subpass);
            }
            return 0;  //New user added succesfully
         }else{
            return 2;  //Registration attempt failed
         }
      }
   }
   
   /**
    * editAccount - Attempts to edit the user's account information
    * including the password, which it first makes sure is correct
    * if entered, if so and the new password is in the right
    * format, the change is made. All other fields are changed
    * automatically.
    */
   function editAccount($subcurpass, $subnewpass, $subemail){
      global $database, $form;  //The database and form object
      /* New password entered */
      if($subnewpass){
         /* Current Password error checking */
         $field = "curpass";  //Use field name for current password
         if(!$subcurpass){
            $form->setError($field, "* Current Password not entered");
         }
         else{
            /* Check if password too short or is not alphanumeric */
            $subcurpass = stripslashes($subcurpass);
            if(strlen($subcurpass) < 4 ||
               !eregi("^([0-9a-z])+$", ($subcurpass = trim($subcurpass)))){
               $form->setError($field, "* Current Password incorrect");
            }
            /* Password entered is incorrect */
            if($database->confirmUserPass($this->username,md5($subcurpass)) != 0){
               $form->setError($field, "* Current Password incorrect");
            }
         }
         
         /* New Password error checking */
         $field = "newpass";  //Use field name for new password
         /* Spruce up password and check length*/
         $subpass = stripslashes($subnewpass);
         if(strlen($subnewpass) < 4){
            $form->setError($field, "* New Password too short");
         }
         /* Check if password is not alphanumeric */
         else if(!eregi("^([0-9a-z])+$", ($subnewpass = trim($subnewpass)))){
            $form->setError($field, "* New Password not alphanumeric");
         }
      }
      /* Change password attempted */
      else if($subcurpass){
         /* New Password error reporting */
         $field = "newpass";  //Use field name for new password
         $form->setError($field, "* New Password not entered");
      }
      
      /* Email error checking */
      $field = "email";  //Use field name for email
      if($subemail && strlen($subemail = trim($subemail)) > 0){
         /* Check if valid email address */
         $regex = "^[_+a-z0-9-]+(\.[_+a-z0-9-]+)*"
                 ."@[a-z0-9-]+(\.[a-z0-9-]{1,})*"
                 ."\.([a-z]{2,}){1}$";
         if(!eregi($regex,$subemail)){
            $form->setError($field, "* Email invalid");
         }
         $subemail = stripslashes($subemail);
      }
      
      /* Errors exist, have user correct them */
      if($form->num_errors > 0){
         return false;  //Errors with form
      }
      
      /* Update password since there were no errors */
      if($subcurpass && $subnewpass){
         $database->updateUserField($this->username,"password",md5($subnewpass));
      }
      
      /* Change Email */
      if($subemail){
         $database->updateUserField($this->username,"email",$subemail);
      }
      
      /* Success! */
      return true;
   }
   
   /**
    * isAdmin - Returns true if currently logged in user is
    * an administrator, false otherwise.
    */
   function isAdmin(){
      return ($this->userlevel == ADMIN_LEVEL ||
              $this->username  == ADMIN_NAME);
   }
   
   /**
    * generateRandID - Generates a string made up of randomized
    * letters (lower and upper case) and digits and returns
    * the md5 hash of it to be used as a userid.
    */
   function generateRandID(){
      return md5($this->generateRandStr(16));
   }
   
   /**
    * generateRandStr - Generates a string made up of randomized
    * letters (lower and upper case) and digits, the length
    * is a specified parameter.
    */
   function generateRandStr($length){
      $randstr = "";
      for($i=0; $i<$length; $i++){
         $randnum = mt_rand(0,61);
         if($randnum < 10){
            $randstr .= chr($randnum+48);
         }else if($randnum < 36){
            $randstr .= chr($randnum+55);
         }else{
            $randstr .= chr($randnum+61);
         }
      }
      return $randstr;
   }
};


/**
 * Initialize session object - This must be initialized before
 * the form object because the form uses session variables,
 * which cannot be accessed unless the session has started.
 */
$session = new Session;

/* Initialize form object */
$form = new Form;

?>

Read through the code and get a feel for how the script knows when the users are logged in or not (checks cookies and $_SESSION variables). Everything is commented so you won't have trouble. Note that the Session functions make good use of the $database object because the database needs to be queried for a lot of functions. Visitor tracking is also being done here. Whenever this page loads, the visitor is added as an active guest or active user, depending on if they are logged in or not, and it also performs the operation to remove any inactive users/guests (people who haven't loaded any pages within the timeout specified in constants.php).

Forms

The creation of a Form class was meant to facilitate the handling of errors with user-submitted forms. It keeps track of what the user entered into the form fields (the values) and what errors have occurred with the form.

form.php

<? 
/**
 * Form.php
 *
 * The Form class is meant to simplify the task of keeping
 * track of errors in user submitted forms and the form
 * field values that were entered correctly.
 *
 * Written by: Jpmaster77 a.k.a. The Grandmaster of C++ (GMC)
 * Last Updated: August 19, 2004
 */
 
class Form
{
   var $values = array();  //Holds submitted form field values
   var $errors = array();  //Holds submitted form error messages
   var $num_errors;   //The number of errors in submitted form

   /* Class constructor */
   function Form(){
      /**
       * Get form value and error arrays, used when there
       * is an error with a user-submitted form.
       */
      if(isset($_SESSION['value_array']) && isset($_SESSION['error_array'])){
         $this->values = $_SESSION['value_array'];
         $this->errors = $_SESSION['error_array'];
         $this->num_errors = count($this->errors);

         unset($_SESSION['value_array']);
         unset($_SESSION['error_array']);
      }
      else{
         $this->num_errors = 0;
      }
   }

   /**
    * setValue - Records the value typed into the given
    * form field by the user.
    */
   function setValue($field, $value){
      $this->values[$field] = $value;
   }

   /**
    * setError - Records new form error given the form
    * field name and the error message attached to it.
    */
   function setError($field, $errmsg){
      $this->errors[$field] = $errmsg;
      $this->num_errors = count($this->errors);
   }

   /**
    * value - Returns the value attached to the given
    * field, if none exists, the empty string is returned.
    */
   function value($field){
      if(array_key_exists($field,$this->values)){
         return htmlspecialchars(stripslashes($this->values[$field]));
      }else{
         return "";
      }
   }

   /**
    * error - Returns the error message attached to the
    * given field, if none exists, the empty string is returned.
    */
   function error($field){
      if(array_key_exists($field,$this->errors)){
         return "<font size=\"2\" color=\"#ff0000\">".$this->errors[$field]."</font>";
      }else{
         return "";
      }
   }

   /* getErrorArray - Returns the array of error messages */
   function getErrorArray(){
      return $this->errors;
   }
};
 
?>

The $form class object is actually defined at the bottom of session.php, for reasons explained there. Basically how it works is there is a value array and an error array. They can be indexed with the names of the fields in the HTML form. So if you had a field whose name was "email", once the user submits the form and an error occurred, you can display what the user already typed in by calling $form->value("email"). If there was an error with what the user typed into the "email" field, you can display the error with $form->error("email").

Look at session.php, login and register functions, they use the form object well and show how to appropriately specify the form errors. Also look later on at main.php and you'll see how to appropriately use the form object when displaying any HTML form on your website.

process.php

All forms submitted by the user have to be processed in some way, and this file takes care of that. Every form the user fills out is directed to this page, and this page figures out which form needs to be processed (whether it be login, register, forgot pass, etc.) and calls the appropriate functions to handle the request.

This page is also in charge of re-directing the user to the correct page after the form has been processed, whether it be to the page referrer (default), or some other specified page. When errors have been found with the submitted form, the default action is to re-direct to the page where the user filled out the form in order to let them know about the error and fix it. If you want your users when just logging-in to be re-directed to their own specific home page, instead of the website main page, this is the file you want to edit to do that.

<?
/**
 * Process.php
 * 
 * The Process class is meant to simplify the task of processing
 * user submitted forms, redirecting the user to the correct
 * pages if errors are found, or if form is successful, either
 * way. Also handles the logout procedure.
 *
 * Written by: Jpmaster77 a.k.a. The Grandmaster of C++ (GMC)
 * Last Updated: August 19, 2004
 */
include("include/session.php");

class Process
{
   /* Class constructor */
   function Process(){
      global $session;
      /* User submitted login form */
      if(isset($_POST['sublogin'])){
         $this->procLogin();
      }
      /* User submitted registration form */
      else if(isset($_POST['subjoin'])){
         $this->procRegister();
      }
      /* User submitted forgot password form */
      else if(isset($_POST['subforgot'])){
         $this->procForgotPass();
      }
      /* User submitted edit account form */
      else if(isset($_POST['subedit'])){
         $this->procEditAccount();
      }
      /**
       * The only other reason user should be directed here
       * is if he wants to logout, which means user is
       * logged in currently.
       */
      else if($session->logged_in){
         $this->procLogout();
      }
      /**
       * Should not get here, which means user is viewing this page
       * by mistake and therefore is redirected.
       */
       else{
          header("Location: main.php");
       }
   }

   /**
    * procLogin - Processes the user submitted login form, if errors
    * are found, the user is redirected to correct the information,
    * if not, the user is effectively logged in to the system.
    */
   function procLogin(){
      global $session, $form;
      /* Login attempt */
      $retval = $session->login($_POST['user'], $_POST['pass'], isset($_POST['remember']));
      
      /* Login successful */
      if($retval){
         header("Location: ".$session->referrer);
      }
      /* Login failed */
      else{
         $_SESSION['value_array'] = $_POST;
         $_SESSION['error_array'] = $form->getErrorArray();
         header("Location: ".$session->referrer);
      }
   }
   
   /**
    * procLogout - Simply attempts to log the user out of the system
    * given that there is no logout form to process.
    */
   function procLogout(){
      global $session;
      $retval = $session->logout();
      header("Location: main.php");
   }
   
   /**
    * procRegister - Processes the user submitted registration form,
    * if errors are found, the user is redirected to correct the
    * information, if not, the user is effectively registered with
    * the system and an email is (optionally) sent to the newly
    * created user.
    */
   function procRegister(){
      global $session, $form;
      /* Convert username to all lowercase (by option) */
      if(ALL_LOWERCASE){
         $_POST['user'] = strtolower($_POST['user']);
      }
      /* Registration attempt */
      $retval = $session->register($_POST['user'], $_POST['pass'], $_POST['email']);
      
      /* Registration Successful */
      if($retval == 0){
         $_SESSION['reguname'] = $_POST['user'];
         $_SESSION['regsuccess'] = true;
         header("Location: ".$session->referrer);
      }
      /* Error found with form */
      else if($retval == 1){
         $_SESSION['value_array'] = $_POST;
         $_SESSION['error_array'] = $form->getErrorArray();
         header("Location: ".$session->referrer);
      }
      /* Registration attempt failed */
      else if($retval == 2){
         $_SESSION['reguname'] = $_POST['user'];
         $_SESSION['regsuccess'] = false;
         header("Location: ".$session->referrer);
      }
   }
   
   /**
    * procForgotPass - Validates the given username then if
    * everything is fine, a new password is generated and
    * emailed to the address the user gave on sign up.
    */
   function procForgotPass(){
      global $database, $session, $mailer, $form;
      /* Username error checking */
      $subuser = $_POST['user'];
      $field = "user";  //Use field name for username
      if(!$subuser || strlen($subuser = trim($subuser)) == 0){
         $form->setError($field, "* Username not entered<br>");
      }
      else{
         /* Make sure username is in database */
         $subuser = stripslashes($subuser);
         if(strlen($subuser) < 5 || strlen($subuser) > 30 ||
            !eregi("^([0-9a-z])+$", $subuser) ||
            (!$database->usernameTaken($subuser))){
            $form->setError($field, "* Username does not exist<br>");
         }
      }
      
      /* Errors exist, have user correct them */
      if($form->num_errors > 0){
         $_SESSION['value_array'] = $_POST;
         $_SESSION['error_array'] = $form->getErrorArray();
      }
      /* Generate new password and email it to user */
      else{
         /* Generate new password */
         $newpass = $session->generateRandStr(8);
         
         /* Get email of user */
         $usrinf = $database->getUserInfo($subuser);
         $email  = $usrinf['email'];
         
         /* Attempt to send the email with new password */
         if($mailer->sendNewPass($subuser,$email,$newpass)){
            /* Email sent, update database */
            $database->updateUserField($subuser, "password", md5($newpass));
            $_SESSION['forgotpass'] = true;
         }
         /* Email failure, do not change password */
         else{
            $_SESSION['forgotpass'] = false;
         }
      }
      
      header("Location: ".$session->referrer);
   }
   
   /**
    * procEditAccount - Attempts to edit the user's account
    * information, including the password, which must be verified
    * before a change is made.
    */
   function procEditAccount(){
      global $session, $form;
      /* Account edit attempt */
      $retval = $session->editAccount($_POST['curpass'], $_POST['newpass'], $_POST['email']);

      /* Account edit successful */
      if($retval){
         $_SESSION['useredit'] = true;
         header("Location: ".$session->referrer);
      }
      /* Error found with form */
      else{
         $_SESSION['value_array'] = $_POST;
         $_SESSION['error_array'] = $form->getErrorArray();
         header("Location: ".$session->referrer);
      }
   }
};

/* Initialize process */
$process = new Process;

?>

Active Visitors

Tracking active visitors is accomplished in the following way: There are two database tables, one to hold the active users and one to hold the active guests. The users are distinguished by their username and the guests by their IP address. This is so we won't add any given user or guest to the tables more than once, because if we did, our information would be incorrect.

Associated with the user or guest is a timestamp, this is updated every time he/she loads a page. The timestamp tells us when the user/guest was last active. When a visitor loads a page, not only are they added/updated in the active table, but a clean-up operation is performed, one that removes any IP addresses or usernames in the database tables that haven't recently been active, the ones who have a timestamp older than the current time minus the timeout specified in constants.php. The tracking of visitors is accomplished in session.php.

Admin Center

The admin center is the page where admins go to do what they do best, administer the Login System. There they can view the table of users and all the user information, except for user passwords because they are encrypted. But how does someone become an admin, how does the system even recognize admins? Well, I'll tell you. If you look in constants.php you'll see that the admin level and admin name are specified. When a user logs in to the website, their user level is retrieved from the database, if their user level equals the admin level, then they are an admin, and they have all admin priviledges.

Admin Name

Well, who gets the admin name as a username? You do, but you have to register it, just like any other name. You should do this once you get the script up and running. Once you register the admin name, the Login System gives that username an admin user level. Let's assume someone were to steal it from you. You have access to constants.php, which means you can edit it, so you could create a new admin name, then register that name, go to the admin center and delete the guy from the system.

Adding Admins

Let's say you need help with your website, and you want your buddy to help out and be an admin. You can have him register under some username of his choice, then you can go to the admin center and give his username the admin user level. Done. That would put him at your level, ...maybe you don't want to give him that much power. Well, the user level is a number from 0-9. By default, guests are 0, users are 1, and admins are 9. You can just give him a user level of 8, and let your website define what that means as far as privileges.

Main Page

The following is an example for your website's main page. It shows a little bit how to use the $session, $form, and $database variables. It contains the login form of the Login System. Note when looking at the HTML form, there's a hidden field called "sublogin", that's the name of the form. That's important because when process.php is loaded it needs to know what form is being processed. So if you want to create different forms later on, make sure you give it a unique name.

main.php

<?
/**
 * Main.php
 *
 * This is an example of the main page of a website. Here
 * users will be able to login. However, like on most sites
 * the login form doesn't just have to be on the main page,
 * but re-appear on subsequent pages, depending on whether
 * the user has logged in or not.
 *
 * Written by: Jpmaster77 a.k.a. The Grandmaster of C++ (GMC)
 * Last Updated: August 26, 2004
 */
include("include/session.php");
?>

<html>
<title>Jpmaster77's Login Script</title>
<body>

<table>
<tr><td>


<?
/**
 * User has already logged in, so display relevant links, including
 * a link to the admin center if the user is an administrator.
 */
if($session->logged_in){
   echo "<h1>Logged In</h1>";
   echo "Welcome <b>$session->username</b>, you are logged in. <br><br>"
       ."[<a href=\"userinfo.php?user=$session->username\">My Account</a>]   "
       ."[<a href=\"useredit.php\">Edit Account</a>]   ";
   if($session->isAdmin()){
      echo "[<a href=\"admin/admin.php\">Admin Center</a>]   ";
   }
   echo "[<a href=\"process.php\">Logout</a>]";
}
else{
?>

<h1>Login</h1>
<?
/**
 * User not logged in, display the login form.
 * If user has already tried to login, but errors were
 * found, display the total number of errors.
 * If errors occurred, they will be displayed.
 */
if($form->num_errors > 0){
   echo "<font size=\"2\" color=\"#ff0000\">".$form->num_errors." error(s) found</font>";
}
?>
<form action="process.php" method="POST">
<table align="left" border="0" cellspacing="0" cellpadding="3">
<tr><td>Username:</td><td><input type="text" name="user" maxlength="30" value="<? echo $form->value("user"); ?>"></td><td><? echo $form->error("user"); ?></td></tr>
<tr><td>Password:</td><td><input type="password" name="pass" maxlength="30" value="<? echo $form->value("pass"); ?>"></td><td><? echo $form->error("pass"); ?></td></tr>
<tr><td colspan="2" align="left"><input type="checkbox" name="remember" <? if($form->value("remember") != ""){ echo "checked"; } ?>>
<font size="2">Remember me next time     
<input type="hidden" name="sublogin" value="1">
<input type="submit" value="Login"></td></tr>
<tr><td colspan="2" align="left"><br><font size="2">[<a href="forgotpass.php">Forgot Password?</a>]</font></td><td align="right"></td></tr>
<tr><td colspan="2" align="left"><br>Not registered? <a href="register.php">Sign-Up!</a></td></tr>
</table>
</form>

<?
}

/**
 * Just a little page footer, tells how many registered members
 * there are, how many users currently logged in and viewing site,
 * and how many guests viewing site. Active users are displayed,
 * with link to their user information.
 */
echo "</td></tr><tr><td align=\"center\"><br><br>";
echo "<b>Member Total:</b> ".$database->getNumMembers()."<br>";
echo "There are $database->num_active_users registered members and ";
echo "$database->num_active_guests guests viewing the site.<br><br>";

include("include/view_active.php");

?>


</td></tr>
</table>


</body>
</html>

Download

As you've probably noticed, pages have been left out of the article. Where's the Admin Center? User Account Page? Forgot Password Form? ... Well, there's too much code to show it all here, plus most of it is self-explanatory. So if you want to see that stuff, and use what I've shown you, download it!

Conclusion

The only reason I made this advanced Login System was because so many people liked my first one and wanted to see more features get added. So I decided to put all the requested features together into this new Login System and give the people what they wanted. So I want to say thank you to all those who enjoyed my first script and supported me, and I hope you enjoy this one too. Happy programming!

AttachmentSize
Login_System_v.2.0.zip22.83 KB

Compare Passwords

Submitted by NTGre on April 22, 2006 - 17:25.

Iv done this to compare passwords..
  /* Password2 error checking */
      $field = "pass"; //Use field name for password
      $field2 = "pass2"; // Second field for password
      if(!$subpass2){
         $form->setError($field2, "* Password not entered");
      }
      else{
       //$subpass = stripslashes($subpass);
       //$subpass2 = stripslashes($subpass2);
         if($subpass!==$subpass2){
            $form->setError($field2, "* Passwords does not match");
         }
      }
Hope that helps...

login or register to post comments

fatal error on process.php

Submitted by jovypok84 on April 23, 2006 - 15:48.

thanks for gvg such a nice coding for me,tq so much! but there is a small error in my process.php file which needs to run when member trying to get new password.. Fatal error: Call to a member function on a non-object in c:\phpdev\www\process.php on line 159 wat is the possible reason behind? mind to help?thanks

login or register to post comments

useredit.php

Submitted by famous58 on April 26, 2006 - 21:22.

As others have stated, great script. I am trying to modify the useredit.php page. I want to have a script that checks the DB for a value, and then displays a dropdown box for that value. LIke phone type. I want to keep Office as 1 in the DB and Cell as 2 in the DB. Instead of a text box I want a drop down with Office selected, but the ability to change to Cell, make sense? I can't get it to work.... EDIT: found this answer on the bottom of page 2 of these replies.

login or register to post comments

New version

Submitted by Amross on April 27, 2006 - 03:36.

Hey JP, awesome script. I was just curious if you are still working on the new version of the script (as previously mentioned to be launched this summer). If so, is the expected launch date still the same and what features can we expect? Cheers

login or register to post comments

mysql close

Submitted by banana33291 on April 27, 2006 - 16:05.

hi i tried to use mysql_close(); and mysql_close(this->connection); and neither work if the maker of this reads it can you tell me a solution please thanks

login or register to post comments

Try using

Submitted by herschwolf on April 28, 2006 - 15:46.

Try using mysql_close($this->connection); You want the variable that controls the connection to be closed and just (this->connection) is only text and tells script nothing, whereas ($this->connection) points to a variable that should contain the connection to your database. I haven't tested it so don't quote me on that, but you just need to look for the variable that holds the connection and put that there.

login or register to post comments

Adding extra Fields/Extra Error Messages

Submitted by famous58 on April 28, 2006 - 16:48.

OK. I've got the script installed and working no problems. But, I'm trying to add some new fields. I've got them all in and when I go through the registration process it appears to be fine (no errors) but the data is not being inserted into my DB.

I've edited the following:
register.php (obviously)
session.php: $database->addNewUser()
process.php: $retval
database.php: function addNewUser() and $q

Is there another I file I should edit? It adds the username, password and time stamp, but won't add any other data.

I'm also having problems adding other error checking fields. I've added them as such:

function register($subuser, $subpass, $subemail, $subfirst_name, $sublast_name, $subtitle){


/* Other Fields Error Checking */
      $field = "first_name"; //Use field name for password
      if(!$subfirst_name){
         $form->setError($field, "* First Name not entered");
      }
      $field = "last_name"; //Use field name for password
      if(!$sublast_name){
         $form->setError($field, "* Last Name not entered");
      }
      $field = "title"; //Use field name for password
      if(!$subtitle){
         $form->setError($field, "* Title not entered");
      }
When I enter something for last name, it removes the error message for title, even when there is nothing entered in title and leaves the error message for last name, even though there is a name entered. If I enter a first name, it removes the error message for last name even though there is no last name entered, etc. Any help is greatly appreciated.

login or register to post comments

CHAT

Submitted by banana33291 on April 28, 2006 - 18:26.

i know this is a bit over the top but can we please have a chat system made for this script. it will make it tonnes better

if this chat be done GREAT thanks
and if it cant thanks for the great script

login or register to post comments

Help with Warning

Submitted by aviatorisu on April 29, 2006 - 01:36.

I've read through all of these posts in hopes of finding an answer to my question. It sounds as if others are having the same problem, so maybe someone can offer a little help.

I'm trying to insert the main.php file into a TABLE and FIELDSET on my homepage, but I get this error:

Warning: Cannot send session cache limiter - headers already sent (output started at /home/virtual/site5/fst/var/www/html/test.php:8) in /home/virtual/site5/fst/var/www/html/include/session.php on line 46

After reading several others' posts here, I tried including the session file before including the main.php file, and now I get this:

Fatal error: Cannot redeclare class mysqldb in /home/virtual/site5/fst/var/www/html/database.php on line 14

Now then, other than to include my own database information, I have not altered the files that came with this script. Can anyone offer any insight here? If need be, I can supply my actual web address.

Much appreciated.

~Z~

login or register to post comments

script not working

Submitted by jacobjmorris on April 30, 2006 - 05:52.

I just installed WAMP5 on my personal computer and have it up and running. I successfully installed the dbtables.sql file on the server. I have all the source files uploaded into the www folder, and when i try to access the main.php file on localhost, it shows all the php code in the browser. The PHP is not being parsed. Anyone have this problem before?

login or register to post comments

useredit

Submitted by Jrrt on April 30, 2006 - 09:15.

Just like some others, I've tried to extend the userinfo.php page, with things like location, avatar, etc. It's all working fine: When I try to change the location, I'm redirected to the page that says "User Account Edit Success!". The only problem is, that the information I fill in, isn't taken in the Database. How can I manage that? Thanks in forward ;) (Here's the code I used in the useredit.php page. The word "plaats" means "location". I used it, as I'm Dutch)
<tr>
<td>Plaats:</td>
<td><input type="text" name="location" maxlength="255" value="
<?
if($form->value("location") == ""){
   echo $session->userinfo['location'];
}else{
   echo $form->value("location");
}
?>">
</td>
<td><? echo $form->error("location"); ?></td>
</tr>

login or register to post comments

I cante get it to work in IE iframe??

Submitted by ukjim on May 1, 2006 - 22:12.

It works fine in firefox using an iframe, but when I open up the same page with internet explorer and try it in there I login and instead of going to the logged in page, it just displays my websites index file in the iframe?????? Any help would be great cuz I need this script its sexy. If you find anything please e-mail me support@ukjim.affordable-host.info Thanx Jim

login or register to post comments

Nothing works

Submitted by bcraig on May 2, 2006 - 04:36.

im using Apache 2.0.55 PHP 5.1.2 MySQL 5.0.18 phpMyadmin 2.7.0-pl2 this script doesnt work at all for me :( this is how the page looks when browsed. Its like this on evry page. the forms dont work and all thers php and errors all over the page.


logged_in){ echo " Logged In "; echo "Welcome $session->username, you are logged in. " ."[username\">My Account] " ."[Edit Account] "; if($session->isAdmin()){ echo "[Admin Center] "; } echo "[Logout]"; } else{ ?> Login num_errors > 0){ echo "".$form->num_errors." error(s) found"; } ?> Username: "> error("user"); ?> Password: "> error("pass"); ?> value("remember") != ""){ echo "checked"; } ?>> Remember me next time [Forgot Password?] Not registered? Sign-Up! "; echo "Member Total: ".$database->getNumMembers()." "; echo "There are $database->num_active_users registered members and "; echo "$database->num_active_guests guests viewing the site. "; include("include/view_active.php"); ?>

login or register to post comments

How To end new fields to the register page

Submitted by Switch on May 2, 2006 - 16:19.

Hi I am having problem with adding fields with the registration page as i am new to PHP, I want add name addess etc and can any body help with make an online appointment page where user can book on line appointments. thank You

login or register to post comments

kick ass script!

Submitted by saturnx on May 3, 2006 - 07:51.

I have been roaming around in search of the perfect login system and yours by far is way more superior. I am re-structuring the code to better suite my website that I am working as while learning PHP. At the moment your script has the registratin on a separate page without the login being their. I tried to merge both files together and when I clicked to register it shows up with errors instead as the login form is empty. How to I get it to only trigger the register form only and not both forms on the same page. How do I go about changing the codes? Thanks. Oh did I already mention that this is a kick ass script ;)

login or register to post comments

Having troulbe logging in

Submitted by downbike on May 3, 2006 - 20:43.

When I try to run the main.php which is the page for user to login.

I recive an error that said:

 "Warning: mysql_connect(): Unknown MySQL Server Host 'DB_SERVER' (1) in /home/vhosts/chuyenanh92.myfreewebs.net/login/database.php on line 24"

THE LINE 24 (according to the original code) is :

/* Class constructor */
   function MySQLDB(){
      /* Make connection to database */
      $this->connection = mysql_connect(DB_SERVER, DB_USER, DB_PASS) or die(mysql_error());
      mysql_select_db(DB_NAME, $this->connection) or die(mysql_error());
I had change the DB_SERVER, DB_USER, DB_PASS so that it can connect to my database... I had check everything and didn't find anyway to fix that error. Can anyone help me?

login or register to post comments

Adding NULL fields

Submitted by alincoredwing on May 4, 2006 - 18:01.

Okay, I got adding fields. No problem. BUT whenever I try to add a field where the value is null it gives me the "Registration Failed". I've tried using a value of 0 on the registration form, I've tried changing my database settings so that that field is set as null. I've tried it as zero. I'm not sure what else to try.

login or register to post comments

script code

Submitted by sasha on May 6, 2006 - 06:06.

this is great script but got some problems.after i instal code in my web pages a got this error " ?>" ?>" ?> ..i changed cople templates html and xhtml but i got same error...my web pages is http://cameldesigns.com/root/main.php ....this is only problem i got whit this script.anyone can help whit this.thx up to front :)

login or register to post comments

useredit.php

Submitted by guardian on May 6, 2006 - 19:44.

Really nice login script I greatly appreciate this tutorial and have implemented a similar script based on this on my website. I have one problem however: I have the same problem as stated a few posts above. I have managed to make the new fields work for my database but when I add them into useredit.php and a signed up user tries to edit the information it is not saved to the database. But when a user registers the field is addded to the mysql database but then they cannot change it from useredit.php so they are stuck with the same field information. Thank you, Guardian

login or register to post comments

All new low - help a rookie

Submitted by StevenB on May 6, 2006 - 19:46.

Recently forced to swich my server and can't use my access db and .asp pages I used for my logins. This script looks great but I'm new to php and mysql.

I loaded the files and I think I've got the db set up properly, but I'm getting the following errors...

Warning: session_start(): Cannot send session cache limiter - headers already sent (output started at /home/www/mysite.com/include/database.php:207) in /home/www/mysite.com/include/session.php on line 46 Warning: mysql_numrows(): supplied argument is not a valid MySQL result resource in /home/www/mysite.com/include/database.php on line 218 Warning: mysql_numrows(): supplied argument is not a valid MySQL result resource in /home/www/mysite.com/include/database.php on line 207

Any ideas, tutorial links, or help would be greatly appreciated.

login or register to post comments

database.php

Submitted by Finau on May 7, 2006 - 06:24.

Please help... How could I use or call the valuable $database in database.php files and why did you assign $database = new MySQLDB How could I access to all the function inside database.php

login or register to post comments

Back to restricted page after login

Submitted by sanjum on May 7, 2006 - 13:33.

Does this script have the functionality to bring a user back to the same (restricted) page after login was successfull. For example when I try to access a restricted page without being logged in, i am redirected to the login page but after login I go to the default page set to after login rather than directed back to the original page I was trying to access. How do I implement this?

login or register to post comments

Amazing script..

Submitted by Finau on May 7, 2006 - 13:50.

I just go through your script and its amazing ....U r genius...keep up the good works.

login or register to post comments

useredit.php

Submitted by guardian on May 7, 2006 - 17:51.

I am having the same problem as Jrrt I cannot get the alterates I've made in useredit.php to go into the database. I don't understand why. Here is my alteration:
<tr>
<td>AIM:</td>
<td><input type="text" name="aim" maxlength="50" value="
<?
if($form->value("aim") == ""){
   echo $session->userinfo['aim'];
}else{
   echo $form->value("aim");
}
?>"></td>
<td>
<? echo $form->error("aim"); ?>
</td>
</tr>
However on signup it does offer the field AIM and it goes into the database then. But you cannot edit it from useredit.php and users that have already signed up cannot input it at all.

login or register to post comments

Solution to Adding Fields

Submitted by blis102 on May 7, 2006 - 20:18.

An Answer At Last... After much work I have found my way onto fixing the problem i was having with adding new fields. This solutions should solve all of your problems with adding fields to this script and having them transfer to the database. I will be showing you how to add the field LASTNAME into a database but you can add any field that you want. If the field is non-text, as in an image, you will have to alter your database appropriately. This is going to be a text only solution, but it could help for using other fields like photos and such.
FIRST Create the fields in your REGISTER.PHP form with proper names:

<input name="last" type="text" value="<? echo $form->value("last"); ?>" size="30" maxlength="30">

This is the lastname field for my script. That is the easy part.
SECOND Alter the DATABASE.PHP script. Note that the variable "$lastname" is used instead of "last" as in the previous code. Do not worry about this much. Just choose two approriate names for your script. I use "lastname" and "last" because it is an abreviation.

<?php
function addNewUser($username, $password, $email, $lastname){
      
$time = time();
      
/* If admin sign up, give admin user level */
      
if(strcasecmp($username, ADMIN_NAME) == 0){
         
$ulevel = ADMIN_LEVEL;
      }else{
         
$ulevel = USER_LEVEL;
      }
      
$q = "INSERT INTO ".TBL_USERS." VALUES ('$username', '$password', '0', $ulevel, '$email', $time, '$lastname')";
      return
mysql_query($q, $this->connection);
   }
?>

In DATABASE.PHP you simply add the field to the two arrays. THIRD Alter the PROCESS script.

<?php
function procRegister(){
      global
$session, $form;
      
/* Convert username to all lowercase (by option) */
      
if(ALL_LOWERCASE){
         
$_POST['user'] = strtolower($_POST['user']);
      }
      
/* Registration attempt */
      
$retval = $session->register($_POST['user'], $_POST['pass'], $_POST['email'], $_POST['last']);
      
      
/* Registration Successful */
      
if($retval == 0){
         
$_SESSION['reguname'] = $_POST['user'];
         
$_SESSION['regsuccess'] = true;
         
header("Location: ".$session->referrer);
      }
      
/* Error found with form */
      
else if($retval == 1){
         
$_SESSION['value_array'] = $_POST;
         
$_SESSION['error_array'] = $form->getErrorArray();
         
header("Location: ".$session->referrer);
      }
      
/* Registration attempt failed */
      
else if($retval == 2){
         
$_SESSION['reguname'] = $_POST['user'];
         
$_SESSION['regsuccess'] = false;
         
header("Location: ".$session->referrer);
      }
   }
?>

You only need to add the $_POST['last'] variable into the "$retval" field. Simple as that
FOURTH Edit SESSION.PHP. This is the hardest of all because you need to add in error handeling. You can choose not to do error handling but i would suggest it and it makes it easy for your guest and you to determine errors.
First, add the variables in the "class session field to include your variable. our variable will be $lastname:

<?php
class Session
{
   var
$username;     //Username given on sign-up
   
var $userid;       //Random value generated on current login
   
var $lastname;     //User's last name.
   
var $userlevel;    //The level to which the user pertains
   
var $time;         //Time user was last active (page loaded)
   
var $logged_in;    //True if user is logged in, false otherwise
   
var $userinfo = array();  //The array holding all user info
   
var $url;          //The page url current being viewed
   
var $referrer;     //Last recorded site page viewed
?>

Next, change the register functions to include your field ($sublast):

<?php
function register($subuser, $subpass, $subemail, $sublast){
      global
$database, $form, $mailer;  //The database, form and mailer object
?>

Next, add the error checking field to your register function. Put it between any of the other functions in the same script syntax as the other error handling fields:

<?php
      
//Last Name
      
$field = "last"; //Use field name for lastname
        
if(!$sublast || strlen($sublast = trim($sublast)) == 0){
            
$form->setError($field, "* Last Name not entered");
        }
?>

And then, finally, must add the new fields into the addNewUSer array ($sublast). You can also choose whether or not to send this information in the welcome email. I chose to include it so that you can send the last name in the email body. Im not going to explain how to change the email field but if you want, you can contact me.

<?php
      
/* No errors, add the new account to the */
      
else{
         if(
$database->addNewUser($subuser, md5($subpass), $subemail,  $sublast)){
            if(
EMAIL_WELCOME){
               
$mailer->sendWelcome($subuser,$subemail,$subpass,$sublast);
            }
            return
0;  //New user added succesfully
         
}else{
            return
2;  //Registration attempt failed
         
}
      }
   }
?>

So, now all you have to do is add the appropiate field to your database with the proper parameters. See JP's script dbtables.sql for syntax. Heres what you would write:

CREATE TABLE users (
 username varchar(30) primary key,
 password varchar(32),
 userid varchar(32),
 userlevel tinyint(1) unsigned not null,
 email varchar(50),
 timestamp int(11) unsigned not null,
 lastname varchar(30)not null
);

So thats about it. Pretty easy if you break it down. Of course there is always going to be problems but this should help all you with problems. I am 95% sure I did everything correct in there but i may have made a mistake. If I did, or if you have questions, comments or feedback, please feel free to email me at blis102@gmail.com.

Also, if you want to see the script in action, please visit SmellyTroll.com. It is my project site and is underconstruction but it is a good example of how you can utilize JP's script. Register as a user and go to the "My Account" section and you can see all your information.

And once again, thanks JP for a great script!
Files Edited
REGISTER.PHP
DATABASE.PHP
SESSION.PHP
PROCESS.PHP

login or register to post comments

found something

Submitted by b_ruce on May 8, 2006 - 09:13.

Your script works great in every aspect, it was a great tutorial for me to learn about sessions and object oriented principles in php. As I as working through with the script I found one thing that I couldn't get done right.

Updating the active_user table for users loggin out.
If a user closes the browser without loggin out, the active_user table will hold the user's information until 60 mins past the login timestamp. Is there a way to update the active_user table information when the user closes the browser without loggin out? It seems to me like users will be confused about who's all logged in at the current time because some users might have logged out already.

login or register to post comments

Changing useredit.php and friends correctly

Submitted by emuexplosion on May 8, 2006 - 17:34.

guardian,

You have edited that part of the file correctly, but that is only 1 file of a few that you need to make changes to. I'll paste my code for adding a zipcode to the user's account - and making it editable.

First off you will need to change the useredit.php - I know guardian has already done this, but for the rest of you I'll just paste everything. This edit shows an addition of a zip code field.

useredit.php
<tr>
<td>Zip Code:</td>
<td><input type="text" name="zipcode" maxlength="50" value="
<?
if($form->value("zipcode") == ""){
   echo $session->userinfo['zipcode'];
}else{
   echo $form->value("zipcode");
}
?>">
</td>
<td><? echo $form->error("zipcode"); ?></td>
</tr>

But that is only the beginning. If the user has set a zip code upon registering, it will show up there otherwise it won't and might fail or give you an undefined error. But fixing that is at your own will, I force my users to enter in a zip code, so it is fine with me.

Next you are going to need to change the next file in order. If you notice which file it POSTs to, that would be process.php - let's edit that next. Look for the line below and add your new fields accordingly.

process.php
      $retval = $session->editAccount($_POST['curpass'], $_POST['newpass'], $_POST['email'], $_POST['zipcode']);

The code gives us clues to which file to edit next, in this case it would be session.php at the editAccount function. Let's go there. You are going to need to add the new field to the begining of the function line.

session.php
   function editAccount($subcurpass, $subnewpass, $subemail, $zipcode){

Then you need to add any sort of verifying process for whatever you are checking. Since mine is a zip code, I don't want anything longer than 5 digits, and it will ONLY take digits. Make sure you create your error fields correctly

session.php
/* Zip Code Verify */
$field = "zipcode"; //Use field name for zipcode
      if(!$zipcode || strlen($zipcode = trim($zipcode)) == 0){
         $form->setError($field, "* Zip Code not entered");
      }
      else{
         /* Spruce up zipcode, check length */
         $zipcode = stripslashes($zipcode);
         /* Check if zip code is digits only */
         if(!eregi("^([0-9])+$", $zipcode)){
            $form->setError($field, "* Zip Code can only have digits in it");
         }
         else if(strlen($zipcode) != 5){
            $form->setError($field, "* Zip Code needs to be in 5 digit format");
         }
      }

After that you need to add in a line for updates. This line will trigger the database file to actually editing/updating what is in the database

session.php
/* Change Zip Code */
if($zipcode){
         $database->updateUserField($this->username,"zipcode",$zipcode);
      }
 

And that should be all. Hopefully that example will get you a little down the road in user edits.

-emu

login or register to post comments

Updating the archive_users table

Submitted by guardian on May 8, 2006 - 18:58.

I might be wrong but I think that is a editable variable in constants.php

login or register to post comments

Dropdown for Users in Admin

Submitted by ChristopheB on May 9, 2006 - 06:43.

Great script. I have been playing around with it for a little while and am using it on one of my (family) site, with some serious modifications. I was going to write a quick tutorial on how to add fields (I have read all the comments on this site -yes!!- and see that many people still have trouble with adding fields). But Blis102 and Emuexplosion have just beat me to it!! :o) Good.

My very modest contribution this morning will be for the below. I did not find convenient, in the Admin Page to have to type the name of the users (for level update, deleting users, etc...). So I have created a very simple function to have a user dropdown box (rather than a text box). This is extremely simple. Here we go :

1.) Open admin/admin.php and locate the below code :

/**
 * displayBannedUsers - Displays the banned users
 * database table in a nicely formatted html table.
 */
function displayBannedUsers(){ .....

Simply add the below code just above :
/**
 * Dropdown for Users - to allow easy selection of users
 *
 */
function dropdownUsers($nom_du_champs){
   global $database;
   $q = "SELECT username "
       ."FROM ".TBL_USERS." ORDER BY username ASC";
   $result = $database->query($q);
   /* Error occurred, return given name by default */
   $num_rows = mysql_numrows($result);
   if(!$result || ($num_rows < 0)){
      echo "Error displaying info";
      return;
   }
   if($num_rows == 0){
      echo "Table is Empty";
      return;
   }
   /* Display table contents */
    echo " <select name=\"$nom_du_champs\">";

   for($i=0; $i<$num_rows; $i++){
      $uname = mysql_result($result,$i,"username");
      
echo "<option value=\"" .$uname."\">$uname</option>";
   }
   echo "</select>";
}

2.) In the form below (for username, for example), find : <input type="text" name="upduser" maxlength="30" value="<? echo $form->value("upduser"); ?>"> and replace it by :

<?php
dropdownUsers(upduser);
?>

Et voilà !. That's it. Repeat Step 2 for the other 2 form fields (Delete User & Ban User), making sure you adapt the function call (it should be dropdownUsers(deluser) and dropdownUsers(banuser) respectively).

My next contribution will be to show how I did the Profile Photo upload for my users (or Avatar Function).

This is my first post, your comments and/or suggestions are more than welcome!. Have a great day. Hello from Brussels (Belgium). Christophe.

login or register to post comments

good work!

Submitted by Nitro on May 9, 2006 - 14:08.

Hello all! wow, i'm impresed... good work, but tell me please, can i see more new info? Best regards, Nitro Thank you.

login or register to post comments

thx

Submitted by selavi on May 9, 2006 - 21:12.

when i run main.php in browser i obtain something like:(copy text &paste) logged_in){ echo " Logged In "; echo "Welcome $session->username, you are logged in. " ."[username\">My Account] " ."[Edit Account] "; if($session->isAdmin()){ echo "[Admin Center] "; } echo "[Logout]"; } else{ ?> Login num_errors > 0){ echo "".$form->num_errors." error(s) found"; } ?> Username: "> error("user"); ?> Password: "> error("pass"); ?> value("remember") != ""){ echo "checked"; } ?>> Remember me next time [Forgot Password?] Not registered? Sign-Up! "; echo "Member Total: ".$database->getNumMembers()." "; echo "There are $database->num_active_users registered members and "; echo "$database->num_active_guests guests viewing the site. "; include("include/view_active.php"); ?> does anybody have patiente to explain me?

login or register to post comments

reply to Selavi -

Submitted by ChristopheB on May 10, 2006 - 17:31.

Selavi, It seems your PHP does not get parsed by your host before being output to the browser. A couple of questions...
  • Do you have a website address we could check ?
  • Are you sure your host provides PHP ?
  • Are you sure you started your PHP code by the proper opening PHP tag ? (i mean by <? or <?PHP). Have you tried both ? (some PHP configurations do not allow short tags such as <? and do require the full <?PHP tag. (there are some posts here about that)
  • If your HTML/PHP editor does allow several views/working panes, are you sure you have not copied/pasted the PHP script in the "Creation" pane ? In Dreamweaver, for example, all PHP coding needs to be done in the CODE view/pane, as in the CREATION view/pane (i.e. WYSIWYG) all codes gets corrupted (for ex. "<?" gets translated to "& lt;?").

Sorry for those questions, but without knowing more about your knowledge and what you already tried, it is hard to tell for sure what is wrong.

Christophe

login or register to post comments

Copying Image

Submitted by famous58 on May 10, 2006 - 18:15.

Hello. I've added an image upload filed to the script. It works initially, however, I cannot get it to edit the image. It changes the database with a partial URL but does not include the image info and does not copy the image. Here is my code. process.php
   function procEditAccount(){
      global $session, $form;
      /* Account edit attempt */

  
$target_path = "uploads/";
$target_path = $target_path . basename($_FILES['img']['name']);
move_uploaded_file($_FILES['img']['tmp_name'], $target_path);

$retval = $session->editAccount($_POST['curpass'], $_POST['newpass'], $_POST['email'], $_POST['first_name'], $_POST['last_name'], $_POST['title'], $_POST['ofcname'], $_POST['ofcaddress'], $_POST['ofccity'], $_POST['ofcstate'], $_POST['ofczip'], $_POST['phone1'], $_POST['phlabel1'], $_POST['phone2'], $_POST['phlabel2'], $_POST['phone3'], $_POST['phlabel3'], $_POST['website'], $target_path);
session.php
function editAccount($subcurpass, $subnewpass, $subemail, $first_name, $last_name, $title, $ofcname, $ofcaddress, $ofccity, $ofcstate, $ofczip, $phone1, $phlabel1, $phone2, $phlabel2, $phone3, $phlabel3, $website, $target_path){
      global $database, $form; //The database and form object
      /* New password entered */
      if($subnewpass){
         /* Current Password error checking */
         $field = "curpass"; //Use field name for current password
         if(!$subcurpass){
            $form->setError($field, "* Current Password not entered");
         }
         else{
            /* Check if password too short or is not alphanumeric */
            $subcurpass = stripslashes($subcurpass);
            if(strlen($subcurpass) < 4 ||
               !eregi("^([0-9a-z])+$", ($subcurpass = trim($subcurpass)))){
               $form->setError($field, "* Current Password incorrect");
            }
            /* Password entered is incorrect */
            if($database->confirmUserPass($this->username,md5($subcurpass)) != 0){
               $form->setError($field, "* Current Password incorrect");
            }
         }
         
         /* New Password error checking */
         $field = "newpass"; //Use field name for new password
         /* Spruce up password and check length*/
         $subpass = stripslashes($subnewpass);
         if(strlen($subnewpass) < 4){
            $form->setError($field, "* New Password too short");
         }
         /* Check if password is not alphanumeric */
         else if(!eregi("^([0-9a-z])+$", ($subnewpass = trim($subnewpass)))){
            $form->setError($field, "* New Password not alphanumeric");
         }
      }
      /* Change password attempted */
      else if($subcurpass){
         /* New Password error reporting */
         $field = "newpass"; //Use field name for new password
         $form->setError($field, "* New Password not entered");
      }
      
      /* Email error checking */
      $field = "email"; //Use field name for email
      if(!$subemail || strlen($subemail = trim($subemail)) == 0){
         $form->setError($field, "* Email not entered");
      }
      else{
         /* Check if valid email address */
       if($subemail && strlen($subemail = trim($subemail)) > 0){
         $regex = "^[_+a-z0-9-]+(\.[_+a-z0-9-]+)*"
                 ."@[a-z0-9-]+(\.[a-z0-9-]{1,})*"
                 ."\.([a-z]{2,}){1}$";
         if(!eregi($regex,$subemail)){
            $form->setError($field, "* Email invalid");
         }
         $subemail = stripslashes($subemail);
      }
}
      
      /* Errors exist, have user correct them */
      if($form->num_errors > 0){
         return false; //Errors with form
      }
      
      /* Update password since there were no errors */
      if($subcurpass && $subnewpass){
         $database->updateUserField($this->username,"password",md5($subnewpass));
      }
      
      /* Change Email */
      if($subemail){
         $database->updateUserField($this->username,"email",$subemail);
      }

      /* Change First Name */
      if($first_name){
         $database->updateUserField($this->username,"first_name",$first_name);
      }
      /* Change Last Name */
      if($last_name){
         $database->updateUserField($this->username,"last_name",$last_name);
      }
      /* Change Title */
      if($title){
         $database->updateUserField($this->username,"title",$title);
      }
      /* Change Office Name */
      if($ofcname){
         $database->updateUserField($this->username,"ofcname",$ofcname);
      }
      /* Change Address */
      if($ofcaddress){
         $database->updateUserField($this->username,"ofcaddress",$ofcaddress);
      }
      /* Change City */
      if($ofccity){
         $database->updateUserField($this->username,"ofccity",$ofccity);
      }
      /* Change State */
      if($ofcstate){
         $database->updateUserField($this->username,"ofcstate",$ofcstate);
      }
      /* Change Zip */
      if($ofczip){
         $database->updateUserField($this->username,"ofczip",$ofczip);
      }
      /* Change Phone 1 */
      if($phone1){
         $database->updateUserField($this->username,"phone1",$phone1);
      }
      /* Change Phone Label 1 */
      if($phlabel1){
         $database->updateUserField($this->username,"phlabel1",$phlabel1);
      }
      /* Change Phone 2 */
      if($phone2){
         $database->updateUserField($this->username,"phone2",$phone2);
      }
      /* Change Phone Label 2 */
      if($phlabel2){
         $database->updateUserField($this->username,"phlabel2",$phlabel2);
      }
      /* Change Phone 3 */
      if($phone3){
         $database->updateUserField($this->username,"phone3",$phone3);
      }
      /* Change Phone Label 3 */
      if($phlabel3){
         $database->updateUserField($this->username,"phlabel3",$phlabel3);
      }
      /* Change Website */
      if($website){
         $database->updateUserField($this->username,"website",$website);
      }

      /* Change Photo */
      if($target_path){
         $database->updateUserField($this->username,"target_path",$target_path);
      }

      /* Success! */
      return true;
   }
As I said, it inserts "upload/" into the DB, but not the image file name. This is the same code that works during registration to upload the image the first time. T.I.A. for any help!

login or register to post comments

Logging Out

Submitted by aviatorisu on May 11, 2006 - 14:44.

Okay, again, I have not changed the files (other than to my server specs) and the logout function is not working. Did anyone else have this problem? Thanx

login or register to post comments

Validation Email upon Registration

Submitted by netrover on May 13, 2006 - 15:21.

Hi there, compliments on the work it looks fantastic. I'm a newbie and was going to try it out and see what I could do with it. Has anyone got any sample code to incorporate a validation email to users upon registration or is this something you could add? I am also interested in if you think it could also be adapted to allow registered users to securly and safely email or PM each other? kind regards for the work, i'm off to install it now. :D Andy

login or register to post comments

New DB connection or table?

Submitted by redroy on May 15, 2006 - 22:05.

Hi, First off, excellent script! Had it up and running within minutes. My php skills are intermediate at best and I'm just barely grasping the OOP side of php. So, my problem is I need to update the script to be able to connect to another db or table (new db preferably) and gather information. If I try to use the methods I'm used too I get: Warning: mysql_numrows(): supplied argument is not a valid MySQL result resource in database.php on line 185. This of course is not part of my attempted new sql function but only happens when I try to call the new function. Any pointers would be GREATLY APPRECIATED! Thanks!

login or register to post comments

When code displays...

Submitted by Kilbey1 on May 17, 2006 - 18:10.

I had this problem on PHP 5. Solve it by doing a search/replace for all instances of <?, and replace with <?php.

login or register to post comments

Adding new functionality to adminprocess.php

Submitted by Kilbey1 on May 17, 2006 - 18:40.

I am having some difficulty posting my code, so I'll attempt to explain. I want to set up functionality that will approve/unapprove a user. I have attempted to add a new function (procUpdateApproval()) to adminprocess.php, which is meant to act on a new form in admin.php. However, when submitting, I am redirected to the referrer. What other things might I be missing? - Eve

login or register to post comments

Cache Full Problem

Submitted by kimchi209 on May 17, 2006 - 20:02.

JPMaster, This script rocks my socks. Ive been working on this website for a few weeks and the login is based on your system here. Its is flippin beautiful and I have learned a lot from it. Got one small problem though. It seems a lot of other people are having an issue with the login that Ive seen once or twice. When the login is submitted it refreshes to the current page and doesnt really login though the name is listed in the bottom as logged in, and no error pops up. So it looks like nothing happened, other than being mentioned on the bottom that you are logged in, though no secure content will load. I can have the user resolve this issue by clearing their cache, but some users have to clear their cache everytime they login. Which is causing them to not want to come to the site anymore. So Im wondering if Im doing something wrong or if you have any ideas. Thanks, kim kimchi209ATgmail.com

login or register to post comments

adding a textfield into the registration form

Submitted by Roninblade on May 18, 2006 - 04:18.

Hello JP Tanks for the script love it and customizing is really eazy. I have worked out how to add fields to database from registration, but I am having problems adding a textfield for comments. can anyone please give me the code needed to add a textfield with the relivent php code to get it to add to the database.

login or register to post comments

reply - nothing works

Submitted by lavag on May 18, 2006 - 11:12.

I had this problem. Its just that you've got short_open_tag=off in your php.ini file. This is the default setting for PHP5, so every php tag has to start

login or register to post comments

Still getting error...

Submitted by redroy on May 18, 2006 - 14:52.

Thanks Kilbey1 for the reply (I'm guessing that was meant for me). But I'm still getting the same error when updating <? to <?php Any ideas?

login or register to post comments

Thanks

Submitted by jonpv on May 18, 2006 - 21:05.

This code is fantastic. It saves me the effort of writing a whole login system myself, although I will have to extend it a bit for my own purposes. I'm currently implementing a login system for my school website, which will hopefully one day also end up being the front end to a remote access file server enabling students to more easily access their network files from home - if the school's bandwidth and capital investment is up to it.

Thanks again.

login or register to post comments

Admin Center - login problem

Submitted by mforesto on May 18, 2006 - 22:33.

I haven't modified any of the files except main.php to add a link to my site. I have no problems other than when trying to access the [Admin Center] link on my account which has userlevel=9. "Access denied for user 'your_name'@'localhost' (using password: YES)" Any ideas, I have filled in all my correct mysql info so that I can create new users and such, but the Admin Center alone, does not work. Is it due in some way to the admin center files being in a subdirectory (by default)? Thanks for your help, -mike

login or register to post comments

adding textarea

Submitted by Roninblade on May 18, 2006 - 23:50.

Hello All I Just want to say how fantastic this script is, got it all working and customized, just having a problem adding textareas to the registration page. can anyone help me with the code i need for this.

login or register to post comments

Adding fields problem - db not populating

Submitted by lavag on May 19, 2006 - 10:28.

Hi I've been attempting to add new fields along the lines of the post by blis102, but I can't get the db to populate. I'm trying to add street, dob, and radio button ouput for gender, and marital status. I've set up the database with the columns in the correct order. With the new input fields varchar - I just want to be able to know if I can populate newfields, then I'll try processing the radio buttons properly and error-checking. Here's my set-up In register.php
value="<?php echo $form->value("user"); ?>"></td><td><?php echo $form->error("user"); ?></td></tr>
value="<?php echo $form->value("pass"); ?>"></td><td><?php echo $form->error("pass"); ?></td></tr>
value="<?php echo $form->value("street");?>"></td><td><?php echo $form->error("street"); ?></td></tr>
<value="<?php echo $form->value("email"); ?>"></td><td><?php echo $form->error("email"); ?></td></tr>
value="<?php echo $form->value("dob");?>"></td>
  <input type="radio" name="gender" value="<?php if($form->value("gender") != ""){ echo "1"; } ?>">
  <input type="radio" name="gender" value="<?php if($form->value("gender") != ""){ echo "2"; } ?>">
    <input type="radio" name="mstatus" value="<?php if($form->value("mstatus") != ""){ echo "3"; } ?>">
    <input type="radio" name="mstatus" value="<?php if($form->value("mstatus") != ""){ echo "1"; } ?>">
    <input type="radio" name="mstatus" value="<?php if($form->value("mstatus") != ""){ echo "2"; } ?>">
  co-habiting</label>
In process.php
$retval = $session->register($_POST['user'], $_POST['pass'], $_POST['street'], $_POST['email'], $_POST['dob'], $_POST['gender'], $_POST['mstatus'])
In session.php
function register($subuser, $subpass, $substreet, $subemail, $subdob, $subgender, $submstatus){
      global $database, $form, $mailer; //The database, form and mailer object
...
else{
         if($database->addNewUser($subuser, md5($subpass), $substreet, $subemail, $subdob, $subgender, $submstatus)){
            if(EMAIL_WELCOME){
               $mailer->sendWelcome($subuser,$subemail,$subpass);
            }
            return 0; //New user added succesfully
         }else{
            return 2; //Registration attempt failed
In database.php
function addNewUser($username, $password, $street, $email, $dob, $gender, $mstatus){
      $time = time();
      /* If admin sign up, give admin user level */
      if(strcasecmp($username, ADMIN_NAME) == 0){
         $ulevel = ADMIN_LEVEL;
      }else{
         $ulevel = USER_LEVEL;
      }
      $q = "INSERT INTO ".TBL_USERS." VALUES ('$username', '$password', '0', $ulevel, '$street', '$time', '$email', '$dob', '$gender', '$mstatus', '0')";
      return mysql_query($q, $this->connection);
   }
Notice, I have an extra field at the end in the SQL for an auto-increment primary key. All the orders seem correct - but the database still doesn't populate the new fields, and no errors are shown. This is so frustrating. What am I missing/doing wrong? As you can see I'm fairly new at this, so some guidance would be much appreciated!! thanks.

login or register to post comments

This post is for Roninblade

Submitted by blis102 on May 19, 2006 - 18:12.

This post is for Roninblade and all those that want to add textfields (such as biography…) to their login script.

It follows the exact same principles that I stated in my previous post about adding more fields to the login script.
The main difference is in the Database part of the code.

Follow these steps to change it.........

1.Add the text field in the Register.php form, name is appropriately referencing the other fields in the form for proper syntax. You want to use the short variable in this field : aka bio instead of biography.
2. Change the Process.php file to include your new field, $_POST['bio']. Use short name here as well.
<?php
function procRegister(){
      global
$session, $form;
      
/* Convert username to all lowercase (by option) */
      
if(ALL_LOWERCASE){
         
$_POST['user'] = strtolower($_POST['user']);
      }
      
/* Registration attempt */
      
$retval = $session->register($_POST['user'], $_POST['pass'], $_POST['email'],$_POST['bio']);
   
?>

3.Change the Database.php file to include the field using the long variable name, aka biography. NOW THIS IS CRUCIAL: YOU MUST PLACE THIS NAME IN THE PROPER ORDER IN THE STRING, meaning, if your database goes: username, password, emailadd, biography, you need to add it just like that. Add it in this order to both of the strings you will see under the function addNewUser like this:
<?php
function addNewUser($username, $password, $email, $biography){
      
$time = time();
      
/* If admin sign up, give admin user level */
      
if(strcasecmp($username, ADMIN_NAME) == 0){
         
$ulevel = ADMIN_LEVEL;
      }else{
         
$ulevel = USER_LEVEL;
      }
      
$q = "INSERT INTO ".TBL_USERS." VALUES ('$username', '$password', '0', $ulevel, '$email', $time,'$biography')";
      return
mysql_query($q, $this->connection);
   }


?>
4. Change the Sessions.php file to include the variable under class Session area, like this:
<?php
class Session
{
   var
$username;     //Username given on sign-up
   
var $userid;       //Random value generated on current login
   
var $biography;    //User biography
   
var $userlevel;    //The level to which the user pertains
   
var $time;         //Time user was last active (page loaded)
   
var $logged_in;    //True if user is logged in, false otherwise
   
var $userinfo = array();  //The array holding all user info
   
var $url;          //The page url current being viewed
   
var $referrer;     //Last recorded site page viewed
?>
Then you will want to add the field into the register function in proper order, this time in this form
<?php
function register($subuser, $subpass, $subemail, $subbio){
      global
$database, $form, $mailer;  //The database, form and mailer object
?>
5. FINALLY! Now, the most crucial step of this change, and the biggest difference between adding regular forms, is the DATABASE.
My database is run by phpMyAdmin, so it is easy for me to add and edit fields, but it follow the same process for adding fields to a table, and this is what you need to do:
insert into the users table the field “userid” where type is text.

Any Questions or Comments? See an error? Contact me at blis102@gmail.com
http://www.organixdesign.com

login or register to post comments

my protected site

Submitted by rikske on May 19, 2006 - 18:13.

hi JP Very nice script, but where i put the member part of my site? in the script or? in the main.php? ....

login or register to post comments

error line 58 of sessions.php

Submitted by timallard on May 20, 2006 - 18:04.

everyhting was installed correctly i thought.. Fatal error: Call to a member function on a non-object in /homepages/31/d141230049/htdocs/include/session.php on line 58
<?php
/**
       * Set guest value to users not logged in, and update
       * active guests table accordingly.
       */
      
if(!$this->logged_in){
         
$this->username = $_SESSION['username'] = GUEST_NAME;
         
$this->userlevel = GUEST_LEVEL;
         --------------->>>>>>>>>>>>>>>>
$database->addActiveGuest($_SERVER['REMOTE_ADDR'], $this->time);<<<<<<<<<<<<<<<<--------------
      }
      
/* Update users last active timestamp */
      
else{
         
$database->addActiveUser($this->username, $this->time);
      }
      
?>
Great code tho im fairly new to php but have taken a few classes. please help, thanks! -Tim

login or register to post comments

Putting login-functionality in external function

Submitted by Frederik_h on May 21, 2006 - 13:16.

Hey, great script. I got it to work in, though i'm very new to php.

I have a site with many separate php-files. Each of them call functions from an external php-file to create the header, navigation menu and footer, whlie only the page-specific content is handled in the page's own php-file. Could I put the functionality from your main.php inside a similar external function and have login functionality handled like this, and how would I do it? I tried several ways, but none seemed to work so far, but then again, I'm new to php.

The problem I encounter seems to be that "session.php" must be included on each separate page and also in the php-file that only holds the utility functions, which causes a problem because then the $database object is instantiated several times (which it can't so it causes an error).

I think this login system would be so cool, if it could be instantly uploaded to an existing php-site and included to the existing pages by simply calling a function from each of the existing pages. But maybe that's naive?

login or register to post comments

The access keys for this page are: ALT (Control on a Mac) plus:

evolt.orgEvolt.org is an all-volunteer resource for web developers made up of a discussion list, a browser archive, and member-submitted articles. This article is the property of its author, please do not redistribute or use elsewhere without checking with the author.