# A quick one

**URL:** <https://forum.kirupa.com/t/a-quick-one/262873>\
**Category:** programming\
**Created:** [June 10, 2008, 6:37pm UTC](https://forum.kirupa.com/t/a-quick-one/262873 "2008-06-10T18:37:24Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![Valerij](https://avatars.discourse-cdn.com/v4/letter/v/e68b1a/32.png) [@Valerij](https://forum.kirupa.com/u/Valerij)\
**Post date:** [June 10, 2008, 6:37pm UTC](https://forum.kirupa.com/t/a-quick-one/262873/1 "2008-06-10T18:37:24Z")

</div>

Hi guys…  
I have a log in system and when you log in you can edit your profile, I just have one problem;  
Since its dynamic link you can just change link at the top and start editing someone elses profile!

I tried to solve this problem like this;

```php
if(isset($user)) // Edit profile
{
if(isset($_GET["edit"]))
{
    // First lets make sure the user is logged in
    if (isLoggedIn() == $user)
    {
        if(isset($_GET["update"]))
        {
            require_once("functions/DbConnector.php");
            $username = $user;
            $db = new DbConnector();
            $db->connect();
            $presentation = $_POST["presentation"];
            $query = "UPDATE login SET presentation='$presentation' WHERE username='$username'";
            $result = $db->query($query);
            echo "Profile updated!";
        } else { // Display edit box
            require_once("functions/DbConnector.php");
            $username = $user;
            $db = new DbConnector();
            $db->connect();
            $query = "SELECT * FROM login WHERE username='$username'";
            $result = $db->query($query);
            $rows = $db->fetchArray($result);
            echo "<center><br/><b>Edit profile</b><br/><form action=\"member.php?edit=".$user."&update\" method='POST'><textarea name='presentation' rows='10' cols='80' align='center'>"
            .$rows["presentation"].
            "</textarea><br/>
            <input type='submit' value='Update Profile' name='submit'>
            </form>
            </center>
            ";
        }
    } 
}
}

```

But instead I cant now even edit my own profile.

Here is the old code if anyone needs it:

```php
if(isset($_GET["edit"])) // Edit profile
{    
    // First lets make sure the user is logged in     
    if(session_is_registered("username") && session_is_registered ("user_password") && $_SESSION["username"] == $_GET["edit"])
    {
        if(isset($_GET["update"]))
        {
            require_once("functions/DbConnector.php");
            $username = $_GET["edit"];
            $db = new DbConnector();
            $db->connect();
            $presentation = $_POST["presentation"];
            $query = "UPDATE login SET presentation='$presentation' WHERE username='$username'";
            $result = $db->query($query);
            echo "Profile updated!";        
        }
        else 
        { // Display edit box
            require_once("functions/DbConnector.php");
            $username = $_GET["edit"];
            $db = new DbConnector();
            $db->connect();
            $query = "SELECT * FROM login WHERE username='$username'";
            $result = $db->query($query);
            $rows = $db->fetchArray($result);
            echo "<center><br/><b>Edit your profile</b><br/>
                <form action=\"member.php?edit=".$_GET["edit"]."&update\" method='POST'>
                    <textarea name='presentation' rows='10' cols='80' align='left'>"
                    .$rows["presentation"].
                    "</textarea><br/>
                    <input type='submit' value='Update' name='submit'>
                </form>
                </center>
            ";
                  }
    }
}

```

All I want to be changed is that the users can edit any other profiles but their own =)

---

<div class="post-metadata">

**Author:** ![borrob](https://avatars.discourse-cdn.com/v4/letter/b/a87d85/32.png) [@borrob](https://forum.kirupa.com/u/borrob)\
**Post date:** [June 10, 2008, 8:24pm UTC](https://forum.kirupa.com/t/a-quick-one/262873/2 "2008-06-10T20:24:17Z")

</div>

The best way to solve your problem is to use the session variables.  
Put session\_start() in the first line of your php file. In the login save the users name in the session and check if the user that is being editted is the same as the logged in user saved in the session.  
Anyhow this is also the way to go if you want to check if a user has logged in.

---

<div class="post-metadata">

**Author:** ![Valerij](https://avatars.discourse-cdn.com/v4/letter/v/e68b1a/32.png) [@Valerij](https://forum.kirupa.com/u/Valerij)\
**Post date:** [June 10, 2008, 8:39pm UTC](https://forum.kirupa.com/t/a-quick-one/262873/3 "2008-06-10T20:39:50Z")

</div>

Yes, sorry I forgot to say that, but this is just a part of the code, I allredy sessioned the username and I do of course have start session. As you can see this is just I been trying to do in the script, but for some reason it doesn’t work:(

---

<div class="post-metadata">

**Author:** ![borrob](https://avatars.discourse-cdn.com/v4/letter/b/a87d85/32.png) [@borrob](https://forum.kirupa.com/u/borrob)\
**Post date:** [June 11, 2008, 6:30am UTC](https://forum.kirupa.com/t/a-quick-one/262873/4 "2008-06-11T06:30:17Z")

</div>

ok, but what is this then?

if(isset($user))  
where did you set this var?

i would expect something like  
if( $\_GET[‘USER’] == $\_SESSION[‘user’] )  
{

}

---

<div class="post-metadata">

**Author:** ![Valerij](https://avatars.discourse-cdn.com/v4/letter/v/e68b1a/32.png) [@Valerij](https://forum.kirupa.com/u/Valerij)\
**Post date:** [June 11, 2008, 9:59am UTC](https://forum.kirupa.com/t/a-quick-one/262873/5 "2008-06-11T09:59:33Z")

</div>

Well, I changed my code to this;

```php

if( $_GET['edit'] == $_SESSION['username'] )
{

if(isset($_GET["edit"])) // Edit profile
{    
    // First lets make sure the user is logged in     
    if(session_is_registered("username") && session_is_registered ("user_password") && $_SESSION["username"] == $_GET["edit"])
    {
        if(isset($_GET["update"]))
        {
            require_once("functions/DbConnector.php");
            $username = $_GET["edit"];
            $db = new DbConnector();
            $db->connect();
            $presentation = $_POST["presentation"];
            $query = "UPDATE login SET presentation='$presentation' WHERE username='$username'";
            $result = $db->query($query);
            echo "Profile updated!";        
        }
        else 
        { // Display edit box
            require_once("functions/DbConnector.php");
            $username = $_GET["edit"];
            $db = new DbConnector();
            $db->connect();
            $query = "SELECT * FROM login WHERE username='$username'";
            $result = $db->query($query);
            $rows = $db->fetchArray($result);
            echo "<center><br/><b>Edit your profile</b><br/>
                <form action=\"member.php?edit=".$_GET["edit"]."&update\" method='POST'>
                    <textarea name='presentation' rows='10' cols='80' align='left'>"
                    .$rows["presentation"].
                    "</textarea><br/>
                    <input type='submit' value='Update' name='submit'>
                </form>
                </center>
            ";
                  }
    }
} else { echo "Error message goes here!"; }
}

```

But now the edit box is just blank, I cant see the box ☹

---

<div class="post-metadata">

**Author:** ![imagined](https://avatars.discourse-cdn.com/v4/letter/i/a87d85/32.png) [@imagined](https://forum.kirupa.com/u/imagined)\
**Post date:** [June 11, 2008, 1:49pm UTC](https://forum.kirupa.com/t/a-quick-one/262873/6 "2008-06-11T13:49:40Z")

</div>

is the textarea blank or the textarea doesnt even appear?

---

<div class="post-metadata">

**Author:** ![Valerij](https://avatars.discourse-cdn.com/v4/letter/v/e68b1a/32.png) [@Valerij](https://forum.kirupa.com/u/Valerij)\
**Post date:** [June 11, 2008, 1:56pm UTC](https://forum.kirupa.com/t/a-quick-one/262873/7 "2008-06-11T13:56:11Z")

</div>

It doesnt appear…

---

<div class="post-metadata">

**Author:** ![imagined](https://avatars.discourse-cdn.com/v4/letter/i/a87d85/32.png) [@imagined](https://forum.kirupa.com/u/imagined)\
**Post date:** [June 11, 2008, 1:59pm UTC](https://forum.kirupa.com/t/a-quick-one/262873/8 "2008-06-11T13:59:59Z")

</div>

[QUOTE=Valerij;2340706]It doesnt appear…[/QUOTE]

You have to find out if it is at least going through the else statement. I always throw in an echo just to check if that part of the code is getting processed. add this echo and let me know if the BLAH is displayed. if it’s not, then it’s not even going throught the else statement.

or you could just check your source in the browser and see if the form tags are there.

```php

else 
        { // Display edit box
            require_once("functions/DbConnector.php");
            $username = $_GET["edit"];
            $db = new DbConnector();
            $db->connect();
            $query = "SELECT * FROM login WHERE username='$username'";
            $result = $db->query($query);
            $rows = $db->fetchArray($result);
            echo "<center><br/><b>Edit your profile</b><br/>
                <form action=\"member.php?edit=".$_GET["edit"]."&update\" method='POST'>
                    <textarea name='presentation' rows='10' cols='80' align='left'>"
                    .$rows["presentation"].
                    "</textarea><br/>
                    <input type='submit' value='Update' name='submit'>
                </form>
echo 'BLAH!';
                </center>
            ";
                  }

```

---

<div class="post-metadata">

**Author:** ![Valerij](https://avatars.discourse-cdn.com/v4/letter/v/e68b1a/32.png) [@Valerij](https://forum.kirupa.com/u/Valerij)\
**Post date:** [June 11, 2008, 2:10pm UTC](https://forum.kirupa.com/t/a-quick-one/262873/9 "2008-06-11T14:10:28Z")

</div>

No form in the source code, and no BLAH! When I tried your code =/

---

<div class="post-metadata">

**Author:** ![imagined](https://avatars.discourse-cdn.com/v4/letter/i/a87d85/32.png) [@imagined](https://forum.kirupa.com/u/imagined)\
**Post date:** [June 11, 2008, 2:21pm UTC](https://forum.kirupa.com/t/a-quick-one/262873/10 "2008-06-11T14:21:18Z")

</div>

[QUOTE=Valerij;2340720]No form in the source code, and no BLAH! When I tried your code =/[/QUOTE]

Then it’s not even going through the else statement and that’s why the textarea doesnt come out.

try this…

```php
if( $_GET['edit'] == $_SESSION['username'] )
{

if(isset($_GET["edit"])) // Edit profile
{    
    // First lets make sure the user is logged in     
    if(session_is_registered("username") && session_is_registered ("user_password") && $_SESSION["username"] == $_GET["edit"])
    {

// TESTING IF ITS GOING THROUGH THIS IF STATEMENT
echo 'BLAH!';

        if(isset($_GET["update"]))
        {
            require_once("functions/DbConnector.php");
            $username = $_GET["edit"];
            $db = new DbConnector();
            $db->connect();
            $presentation = $_POST["presentation"];
            $query = "UPDATE login SET presentation='$presentation' WHERE username='$username'";
            $result = $db->query($query);
            echo "Profile updated!";        
        }
        else 
        { // Display edit box
            require_once("functions/DbConnector.php");
            $username = $_GET["edit"];
            $db = new DbConnector();
            $db->connect();
            $query = "SELECT * FROM login WHERE username='$username'";
            $result = $db->query($query);
            $rows = $db->fetchArray($result);
            echo "<center><br/><b>Edit your profile</b><br/>
                <form action=\"member.php?edit=".$_GET["edit"]."&update\" method='POST'>
                    <textarea name='presentation' rows='10' cols='80' align='left'>"
                    .$rows["presentation"].
                    "</textarea><br/>
                    <input type='submit' value='Update' name='submit'>
                </form>
                </center>
            ";
                  }
    }
} else { echo "Error message goes here!"; }
}  

```

Let me know if the BLAH is displayed

---

<div class="post-metadata">

**Author:** ![Valerij](https://avatars.discourse-cdn.com/v4/letter/v/e68b1a/32.png) [@Valerij](https://forum.kirupa.com/u/Valerij)\
**Post date:** [June 11, 2008, 2:30pm UTC](https://forum.kirupa.com/t/a-quick-one/262873/11 "2008-06-11T14:30:26Z")

</div>

No, still nothing…

---

<div class="post-metadata">

**Author:** ![imagined](https://avatars.discourse-cdn.com/v4/letter/i/a87d85/32.png) [@imagined](https://forum.kirupa.com/u/imagined)\
**Post date:** [June 11, 2008, 2:38pm UTC](https://forum.kirupa.com/t/a-quick-one/262873/12 "2008-06-11T14:38:15Z")

</div>

[QUOTE=Valerij;2340735]No, still nothing…[/QUOTE]

Ok, lets just do this…

```php
if( $_GET['edit'] == $_SESSION['username'] ) 
{ 
echo 'TEST 1 PASSED';
if(isset($_GET["edit"])) // Edit profile 
{     
echo 'TEST 2 PASSED';
    // First lets make sure the user is logged in      
    if(session_is_registered("username") && session_is_registered ("user_password") && $_SESSION["username"] == $_GET["edit"]) 
    { 
echo 'TEST 3 PASSED';
        if(isset($_GET["update"])) 
        { 
echo 'TEST 4 PASSED';
            require_once("functions/DbConnector.php"); 
            $username = $_GET["edit"]; 
            $db = new DbConnector(); 
            $db->connect(); 
            $presentation = $_POST["presentation"]; 
            $query = "UPDATE login SET presentation='$presentation' WHERE username='$username'"; 
            $result = $db->query($query); 
            echo "Profile updated!";         
        } 
        else  
        { // Display edit box 
            require_once("functions/DbConnector.php"); 
            $username = $_GET["edit"]; 
            $db = new DbConnector(); 
            $db->connect(); 
            $query = "SELECT * FROM login WHERE username='$username'"; 
            $result = $db->query($query); 
            $rows = $db->fetchArray($result); 
            echo "<center><br/><b>Edit your profile</b><br/> 
                <form action=\"member.php?edit=".$_GET["edit"]."&update\" method='POST'> 
                    <textarea name='presentation' rows='10' cols='80' align='left'>" 
                    .$rows["presentation"]. 
                    "</textarea><br/> 
                    <input type='submit' value='Update' name='submit'> 
                </form> 
                </center> 
            "; 
                  } 
    } 
} else { echo "Error message goes here!"; } 
}  

```

Let me know what tests are echoed

---

<div class="post-metadata">

**Author:** ![Valerij](https://avatars.discourse-cdn.com/v4/letter/v/e68b1a/32.png) [@Valerij](https://forum.kirupa.com/u/Valerij)\
**Post date:** [June 11, 2008, 2:57pm UTC](https://forum.kirupa.com/t/a-quick-one/262873/13 "2008-06-11T14:57:35Z")

</div>

Test 1 Passed  
Test 2 Passed

---

<div class="post-metadata">

**Author:** ![imagined](https://avatars.discourse-cdn.com/v4/letter/i/a87d85/32.png) [@imagined](https://forum.kirupa.com/u/imagined)\
**Post date:** [June 11, 2008, 3:08pm UTC](https://forum.kirupa.com/t/a-quick-one/262873/14 "2008-06-11T15:08:02Z")

</div>

[QUOTE=Valerij;2340765]Test 1 Passed  
Test 2 Passed[/QUOTE]

Obviously, this statement is resulting in false

```php
if(session_is_registered("username") && session_is_registered ("user_password") && $_SESSION["username"] == $_GET["edit"])

```

Analyze that if statement. you can probably echo those variables BEFORE THE STATEMENT to see what they contain and see why the if statement is resulting in false.

like this:

```php

echo 'username: '.$_SESSION['username'].'<br />';
echo 'user_password: '.$_SESSION['user_password'].'<br />';
echo 'GET edit: '.$_GET['edit'].'<br />';

```

You can also try this instead

```php
if(isset($_SESSION['username']) && isset($_SESSION['user_password']) && $_SESSION["username"] == $_GET["edit"])

```

Let me know what you get.

---

<div class="post-metadata">

**Author:** ![Valerij](https://avatars.discourse-cdn.com/v4/letter/v/e68b1a/32.png) [@Valerij](https://forum.kirupa.com/u/Valerij)\
**Post date:** [June 11, 2008, 3:16pm UTC](https://forum.kirupa.com/t/a-quick-one/262873/15 "2008-06-11T15:16:19Z")

</div>

```php
echo 'username: '.$_SESSION['username'].'<br />';
echo 'user_password: '.$_SESSION['user_password'].'<br />';
echo 'GET edit: '.$_GET['edit'].'<br />';  

```

Worked perfect! I could also see my edit box and it works =)

```php
if(isset($_SESSION['username']) && isset($_SESSION['user_password']) && $_SESSION["username"] == $_GET["edit"])  

```

Didnt make any change.  
\</span\>\</span\>

---

<div class="post-metadata">

**Author:** ![imagined](https://avatars.discourse-cdn.com/v4/letter/i/a87d85/32.png) [@imagined](https://forum.kirupa.com/u/imagined)\
**Post date:** [June 11, 2008, 3:24pm UTC](https://forum.kirupa.com/t/a-quick-one/262873/16 "2008-06-11T15:24:07Z")

</div>

[QUOTE=Valerij;2340774]

```php
echo 'username: '.$_SESSION['username'].'<br />';
echo 'user_password: '.$_SESSION['user_password'].'<br />';
echo 'GET edit: '.$_GET['edit'].'<br />';  

```

Worked perfect! I could also see my edit box and it works =)

```php
if(isset($_SESSION['username']) && isset($_SESSION['user_password']) && $_SESSION["username"] == $_GET["edit"])  

```

Didnt make any change.  
\</span\>\</span\>[/QUOTE]

Just curiosity… why were you using session\_is\_registered ?

So everything works now?

---

<div class="post-metadata">

**Author:** ![Valerij](https://avatars.discourse-cdn.com/v4/letter/v/e68b1a/32.png) [@Valerij](https://forum.kirupa.com/u/Valerij)\
**Post date:** [June 11, 2008, 3:33pm UTC](https://forum.kirupa.com/t/a-quick-one/262873/17 "2008-06-11T15:33:28Z")

</div>

Yes, everything works now, thanks a lot =D

I wasnt really using session\_is\_registered, someone told me to try that and see if that helps, and then I forgot to remove it when I create this thread.
