# PHP - Login won't redirect

**URL:** <https://forum.kirupa.com/t/php-login-wont-redirect/264510>\
**Category:** programming\
**Created:** [June 26, 2008, 7:01pm UTC](https://forum.kirupa.com/t/php-login-wont-redirect/264510 "2008-06-26T19:01:32Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rollna01](https://avatars.discourse-cdn.com/v4/letter/r/ee59a6/32.png) [@Rollna01](https://forum.kirupa.com/u/Rollna01)\
**Post date:** [June 26, 2008, 7:01pm UTC](https://forum.kirupa.com/t/php-login-wont-redirect/264510/1 "2008-06-26T19:01:32Z")

</div>

I am having issues getting my code to function properly.  
I go to my index page and it redirects me to the login page. After I enter in the Login information correctly it goes to a blank white screen. However, if I go back to the index page I am properly logged in.

Thanks in advance.

```php

session_start(); 
 
$errorMessage = '';
if (isset($_POST['userId']) && isset($_POST['password'])) {
include ('../library/config.php');
include ('../library/opendb.php');
 
$userId = $_POST['userId'];
$password = $_POST['password'];
 
// check if the user id and password combination exist in database
$sql = "SELECT user_id 
FROM blog_user
WHERE user_id = '$userId' 
AND user_pass = PASSWORD('$password')";
$result = mysql_query($sql) 
or die('Query failed. ' . mysql_error()); 
 
if (mysql_num_rows($result) == 1) {
// the user id and password match, 
// set the session
$_SESSION['jim_is_logged_in'] = true;
 
// after login we move to the main page
header('Location: index.php');
exit;
} else {
$errorMessage = 'Sorry, wrong user id / password';
}
 
include ('../library/closedb.php');
}

```

---

<div class="post-metadata">

**Author:** ![jwilliam](https://avatars.discourse-cdn.com/v4/letter/j/cc9497/32.png) [@jwilliam](https://forum.kirupa.com/u/jwilliam)\
**Post date:** [June 26, 2008, 7:15pm UTC](https://forum.kirupa.com/t/php-login-wont-redirect/264510/2 "2008-06-26T19:15:25Z")

</div>

I don’t see anything obviously wrong with your algorithm. Check your error logs and post them, or put this at the top of your script and try it again:

```auto

error_reporting(E_ALL);

```

Additionally, your login script is vulnerable to injection attacks. If an attacker put something like this:

```auto

' OR user_id='jim'; --

```

In the username field, I believe he could gain access without the password. With the above code entered in the username field, the query would look like this:

```auto

SELECT user_id FROM blog_user WHERE user_id='' OR user_id='jim'; -- AND user_pass = PASSWORD('$password');

```

‘–’ denotes a comment, so the part of the query that checks the password is ignored. To defend against this, always escape your data:

```auto

$userId = mysql_real_escape_string($_POST['userId']);

```

---

<div class="post-metadata">

**Author:** ![ajcates](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/ajcates/32/2435_2.png) [@ajcates](https://forum.kirupa.com/u/ajcates)\
**Post date:** [June 27, 2008, 7:54am UTC](https://forum.kirupa.com/t/php-login-wont-redirect/264510/3 "2008-06-27T07:54:34Z")

</div>

My only guess would be that you are sending the user a cookie before the redirection takes place so that makes the header info no good. If you do enable all error reporting, it will tell you this.

[ot]  
Next time if you could wrap your code in these tags.  
[noparse]

```php

```

[/noparse]  
[/ot]

---

<div class="post-metadata">

**Author:** ![Rollna01](https://avatars.discourse-cdn.com/v4/letter/r/ee59a6/32.png) [@Rollna01](https://forum.kirupa.com/u/Rollna01)\
**Post date:** [June 27, 2008, 4:39pm UTC](https://forum.kirupa.com/t/php-login-wont-redirect/264510/4 "2008-06-27T16:39:47Z")

</div>

I am pretty new to PHP so I am not sure how to enable the error log and where I would find the error results. Thanks for taking time to help me with this.

---

<div class="post-metadata">

**Author:** ![jwilliam](https://avatars.discourse-cdn.com/v4/letter/j/cc9497/32.png) [@jwilliam](https://forum.kirupa.com/u/jwilliam)\
**Post date:** [June 27, 2008, 5:44pm UTC](https://forum.kirupa.com/t/php-login-wont-redirect/264510/5 "2008-06-27T17:44:54Z")

</div>

Put this code at the top of your php script:

```auto

error_reporting(E_ALL);

```

Then login again. Instead of a white screen, you should see some errors and/or warnings. Copy those and post them here.

---

<div class="post-metadata">

**Author:** ![jwilliam](https://avatars.discourse-cdn.com/v4/letter/j/cc9497/32.png) [@jwilliam](https://forum.kirupa.com/u/jwilliam)\
**Post date:** [June 27, 2008, 5:45pm UTC](https://forum.kirupa.com/t/php-login-wont-redirect/264510/6 "2008-06-27T17:45:36Z")

</div>

Put this code at the top of your php script:

```auto

error_reporting(E_ALL);

```

Then login again. Instead of a white screen, you should see some errors and/or warnings. Copy those and post them here.

---

<div class="post-metadata">

**Author:** ![Rollna01](https://avatars.discourse-cdn.com/v4/letter/r/ee59a6/32.png) [@Rollna01](https://forum.kirupa.com/u/Rollna01)\
**Post date:** [June 27, 2008, 7:22pm UTC](https://forum.kirupa.com/t/php-login-wont-redirect/264510/7 "2008-06-27T19:22:41Z")

</div>

Here are the logs that my script was generating. Seems like the issue is with this line

```php
<form id="frmLogin" name="frmLogin" method="post" action="<?php echo $_SERVER['php_SELF']?>">

```

Thanks again!

[Fri Jun 27 13:20:00 2008] [error] [client 129.176.151.10] FastCGI: server “/home/httpd/vhosts/default/fcgi-bin/phpfcgi” stderr: PHP Notice: Undefined index: php\_SELF in /var/www/vhosts/example.com/httpdocs/Journal/login.php on line 63

[Fri Jun 27 13:20:00 2008] [error] [client 129.176.151.10] FastCGI: server “/home/httpd/vhosts/default/fcgi-bin/phpfcgi” stderr: PHP Notice: Undefined index: php\_SELF in /var/www/vhosts/example.com/httpdocs/Journal/login.php on line 63

[Fri Jun 27 13:20:06 2008] [error] [client 129.176.151.10] FastCGI: server “/home/httpd/vhosts/default/fcgi-bin/phpfcgi” stderr: PHP Warning: Cannot modify header information - headers already sent by (output started at /var/www/vhosts/example.com/httpdocs/library/config.php:8) in /var/www/vhosts/example.com/httpdocs/Journal/login.php on line 28, referer: [http://www.example.com/Journal/login.php](http://www.example.com/Journal/login.php)

---

<div class="post-metadata">

**Author:** ![jwilliam](https://avatars.discourse-cdn.com/v4/letter/j/cc9497/32.png) [@jwilliam](https://forum.kirupa.com/u/jwilliam)\
**Post date:** [June 27, 2008, 7:32pm UTC](https://forum.kirupa.com/t/php-login-wont-redirect/264510/8 "2008-06-27T19:32:35Z")

</div>

Your config file is printing something and causing your call to header() to fail. Once output has started (ie, you print something to stdout) you can no longer change the header information and, thus, you can not call header(). Check config.php and look for something like that, or post it here if it isn’t sensitive information.

---

<div class="post-metadata">

**Author:** ![Rollna01](https://avatars.discourse-cdn.com/v4/letter/r/ee59a6/32.png) [@Rollna01](https://forum.kirupa.com/u/Rollna01)\
**Post date:** [June 27, 2008, 7:36pm UTC](https://forum.kirupa.com/t/php-login-wont-redirect/264510/9 "2008-06-27T19:36:05Z")

</div>

This is all my config.php has in it…  
then it calls a opendb.php file which just sets up my DB connection

```php
<?php
// This is the Example config.php
$dbhost = "localhost";
$dbuser = "username";
$dbpass = "pass";
$dbname = "dbname";
?> 

```

---

<div class="post-metadata">

**Author:** ![jwilliam](https://avatars.discourse-cdn.com/v4/letter/j/cc9497/32.png) [@jwilliam](https://forum.kirupa.com/u/jwilliam)\
**Post date:** [June 27, 2008, 7:48pm UTC](https://forum.kirupa.com/t/php-login-wont-redirect/264510/10 "2008-06-27T19:48:19Z")

</div>

That’s odd. If I were you I’d trying buffering my output. Put ob\_start() at the beginning of your script and ob\_end\_flush() at the end of it like so:

```auto

ob_start();

PHP code...

ob_end_flush();

```

I’m pretty sure this will fix the problem, but if it doesn’t it will help with troubleshooting.

---

<div class="post-metadata">

**Author:** ![Rollna01](https://avatars.discourse-cdn.com/v4/letter/r/ee59a6/32.png) [@Rollna01](https://forum.kirupa.com/u/Rollna01)\
**Post date:** [June 27, 2008, 9:04pm UTC](https://forum.kirupa.com/t/php-login-wont-redirect/264510/11 "2008-06-27T21:04:06Z")

</div>

That worked!!! Everything is functioning properly now. Thanks a TON!!

Could you explain a little why & how the ob\_start() solved the problem?

Thanks!

---

<div class="post-metadata">

**Author:** ![jwilliam](https://avatars.discourse-cdn.com/v4/letter/j/cc9497/32.png) [@jwilliam](https://forum.kirupa.com/u/jwilliam)\
**Post date:** [June 27, 2008, 10:23pm UTC](https://forum.kirupa.com/t/php-login-wont-redirect/264510/12 "2008-06-27T22:23:18Z")

</div>

Sure…

Web pages begin with a chunk of text called http headers. This block contains information about the page. In a php script, if you want to modify the header information, it has to be the first thing you do (ie, before you print any plain text, or markup like html, etc…). For some reason, the server thought that you had already started printing your document and, thus, it would not allow you to modify header information so you could not redirect the user by called header(‘location: whatever.php’).

When you buffer your output using ob\_start(), nothing is sent to stdout (standard out). Everything you print is stored in a memory buffer until you do something with it (check [php.net](http://php.net) for more info on how you can handle the buffer). So, whatever was being output in your script and causing it to crash is now being put into a buffer, so you can still modify header information anywhere in your script until you dump that buffer to stdout.

I hope that makes sense. I’m not great at explaining things, but maybe someone else could post a better explanation.

FYI… if you’ve ever seen a page that takes a couple seconds to load and looks a bit funky as it’s loading, since the browser is rendering all the html as it comes in… buffering your output prevents this. The user will see a blank screen until all html is loaded and the page is rendered in its entirety.
