# Site with login

**URL:** <https://forum.kirupa.com/t/site-with-login/262130>\
**Category:** programming\
**Created:** [June 3, 2008, 4:23pm UTC](https://forum.kirupa.com/t/site-with-login/262130 "2008-06-03T16:23:39Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Maqrkk](https://avatars.discourse-cdn.com/v4/letter/m/35a633/32.png) [@Maqrkk](https://forum.kirupa.com/u/Maqrkk)\
**Post date:** [June 3, 2008, 4:23pm UTC](https://forum.kirupa.com/t/site-with-login/262130/1 "2008-06-03T16:23:39Z")

</div>

Hello everyone,

I’m starting a new project, and for this I want to first build a very basic site with login system. I’m most concerned about password handling, how do I do that safe?

Basically I will have a table called users, with the following data:

[LIST]  
[_]user\_id  
[_]user\_name  
[_]user\_pw  
[_]user\_firstname  
[\*]user\_lastname  
[/LIST]  
Let’s say someone already registered, and he wants to log in. I don’t think just sending the password data back and forth from the server is very safe? Also I could just check someone’s password in the database, and I don’t want that. Can anyone help me out here? It would be much appreciated!

- Maqrkk

---

<div class="post-metadata">

**Author:** ![simplistik](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/simplistik/32/7747_2.png) [@simplistik](https://forum.kirupa.com/u/simplistik)\
**Post date:** [June 3, 2008, 4:40pm UTC](https://forum.kirupa.com/t/site-with-login/262130/2 "2008-06-03T16:40:52Z")

</div>

ummm well you need to check someone password in the database, there’s no way around it. I fail to see what you think possible security flaws in that are …

Fact of the matter is you NEED to store a password in the database. it should be encrypted.  
You also NEED to reference the database for the username and password.

Your basic login script would be something like

pseudo code …

```php

if ( !empty($_POST['submit']) )
{
   #all your database connection crap goes first

   #query your db with something like
   $username = $_POST['username'];
   $password = sha1($_POST['password']);
   $query = "SELECT COUNT(*) AS valid_user FROM table WHERE user_name = $username AND user_pw = $password";
   #if valid_user = 1 goto logged in page
   
   #if valid_user != 1 error reload login page
}

```

---

<div class="post-metadata">

**Author:** ![Maqrkk](https://avatars.discourse-cdn.com/v4/letter/m/35a633/32.png) [@Maqrkk](https://forum.kirupa.com/u/Maqrkk)\
**Post date:** [June 3, 2008, 4:43pm UTC](https://forum.kirupa.com/t/site-with-login/262130/3 "2008-06-03T16:43:14Z")

</div>

I think encryption is the word I was looking for indeed. How is that done then?

Let’s take as example the Register page, since it needs to be encrypted inside the database, right? Would the user type his password, how do I encrypt it and store it in the database?

---

<div class="post-metadata">

**Author:** ![simplistik](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/simplistik/32/7747_2.png) [@simplistik](https://forum.kirupa.com/u/simplistik)\
**Post date:** [June 3, 2008, 4:50pm UTC](https://forum.kirupa.com/t/site-with-login/262130/4 "2008-06-03T16:50:56Z")

</div>

[QUOTE=Maqrkk;2335674]I think encryption is the word I was looking for indeed. How is that done then?

Let’s take as example the Register page, since it needs to be encrypted inside the database, right? Would the user type his password, how do I encrypt it and store it in the database?[/QUOTE]

On the register page when you submit their password to the database submit it as

```php

sha1($usersubmittedpassword);

```

---

<div class="post-metadata">

**Author:** ![Maqrkk](https://avatars.discourse-cdn.com/v4/letter/m/35a633/32.png) [@Maqrkk](https://forum.kirupa.com/u/Maqrkk)\
**Post date:** [June 3, 2008, 5:02pm UTC](https://forum.kirupa.com/t/site-with-login/262130/5 "2008-06-03T17:02:05Z")

</div>

Thanks! Is that completely safe? 😉

---

<div class="post-metadata">

**Author:** ![actionAction](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/actionaction/32/3987_2.png) [@actionAction](https://forum.kirupa.com/u/actionAction)\
**Post date:** [June 3, 2008, 5:18pm UTC](https://forum.kirupa.com/t/site-with-login/262130/6 "2008-06-03T17:18:08Z")

</div>

Nothing is completely safe. You may want to escape any arguments that the user could submit by using mysql\_real\_escape\_string() on your password and username variables.

A mod of simps code:

```php

if ( !empty($_POST['submit']) )
{
   #all your database connection crap goes first

   #query your db with something like
   $username = mysql_real_escape_string($_POST['username']);
   $password = mysql_real_escape_string($_POST['password']);
   $query = "SELECT COUNT(*) AS valid_user FROM table WHERE user_name = '$username' AND user_pw = SHA1('$password')";
   #if valid_user = 1 goto logged in page
   
   #if valid_user != 1 error reload login page
}  

```

\</span\>\</span\>

This will prevent them from submitting “’…’ OR 1=1” which will select all of your user’s names and passwords.

---

<div class="post-metadata">

**Author:** ![djheru](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/djheru/32/3190_2.png) [@djheru](https://forum.kirupa.com/u/djheru)\
**Post date:** [June 3, 2008, 5:51pm UTC](https://forum.kirupa.com/t/site-with-login/262130/7 "2008-06-03T17:51:29Z")

</div>

If you want to make the password recoverable, you can use the mysql AES\_ENCRYPT function.

---

<div class="post-metadata">

**Author:** ![Maqrkk](https://avatars.discourse-cdn.com/v4/letter/m/35a633/32.png) [@Maqrkk](https://forum.kirupa.com/u/Maqrkk)\
**Post date:** [June 3, 2008, 6:06pm UTC](https://forum.kirupa.com/t/site-with-login/262130/8 "2008-06-03T18:06:42Z")

</div>

[quote=actionAction;2335707]Nothing is completely safe. You may want to escape any arguments that the user could submit by using mysql\_real\_escape\_string() on your password and username variables.

A mod of simps code:

```php

if ( !empty($_POST['submit']) )
{
   #all your database connection crap goes first

   #query your db with something like
   $username = mysql_real_escape_string($_POST['username']);
   $password = mysql_real_escape_string($_POST['password']);
   $query = "SELECT COUNT(*) AS valid_user FROM table WHERE user_name = '$username' AND user_pw = SHA1('$password')";
   #if valid_user = 1 goto logged in page
   
   #if valid_user != 1 error reload login page
}  

```

\</span\>\</span\>

This will prevent them from submitting “‘…’ OR 1=1” which will select all of your user’s names and passwords.[/quote]

So mysql\_real\_escape\_string is basically a protection for possible ‘hacks’ users can use to do things I would not want them to do? Thanks for the suggestion. I think I got most of it, thanks! I’ll give it a try 😃

> [@djheru;2335749](#):
>
> If you want to make the password recoverable, you can use the mysql AES\_ENCRYPT function.

And how safe is that compared to the other method?

---

<div class="post-metadata">

**Author:** ![Maqrkk](https://avatars.discourse-cdn.com/v4/letter/m/35a633/32.png) [@Maqrkk](https://forum.kirupa.com/u/Maqrkk)\
**Post date:** [June 3, 2008, 6:23pm UTC](https://forum.kirupa.com/t/site-with-login/262130/9 "2008-06-03T18:23:16Z")

</div>

Ok I tried the following:

```php
	$username = mysql_real_escape_string($_POST['uname']);
	$password = sha1(mysql_real_escape_string($_POST['pword']));

```

Which gave me the following error:

```auto
Warning: mysql_real_escape_string() [function.mysql-real-escape-string]: Access denied for user ' ***'@'***' (using password: ***) in D:\***\***.php on line 36

Warning: mysql_real_escape_string() [function.mysql-real-escape-string]: A link to the server could not be established in D:\ ***\***.php on line 36

Warning: mysql_real_escape_string() [function.mysql-real-escape-string]: Access denied for user ' ***'@'***' (using password: ***) in D:\***\***.php on line 37

Warning: mysql_real_escape_string() [function.mysql-real-escape-string]: A link to the server could not be established in D:\ ***\***.php on line 37

```

Did I do something wrong? This is in the register.php, after I type in values to be registered…

---

<div class="post-metadata">

**Author:** ![actionAction](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/actionaction/32/3987_2.png) [@actionAction](https://forum.kirupa.com/u/actionAction)\
**Post date:** [June 3, 2008, 7:41pm UTC](https://forum.kirupa.com/t/site-with-login/262130/10 "2008-06-03T19:41:25Z")

</div>

you need to connect to the db before this code is executed.

---

<div class="post-metadata">

**Author:** ![djheru](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/djheru/32/3190_2.png) [@djheru](https://forum.kirupa.com/u/djheru)\
**Post date:** [June 3, 2008, 9:02pm UTC](https://forum.kirupa.com/t/site-with-login/262130/11 "2008-06-03T21:02:54Z")

</div>

Usually I just use sprintf to do it right when I define the query string

```php

//First you must connect to db, as noted above
$sql = sprintf("SELECT * FROM tablename WHERE foo='%s'",
                  mysql_real_escape_string($foo)
                  );

```

---

<div class="post-metadata">

**Author:** ![Maqrkk](https://avatars.discourse-cdn.com/v4/letter/m/35a633/32.png) [@Maqrkk](https://forum.kirupa.com/u/Maqrkk)\
**Post date:** [June 4, 2008, 10:39am UTC](https://forum.kirupa.com/t/site-with-login/262130/12 "2008-06-04T10:39:59Z")

</div>

Thanks, connecting first does the trick, silly me.  
Djheru, what does sprintf do? Your example wasn’t really clear to me, sorry!

---

<div class="post-metadata">

**Author:** ![Charleh](https://avatars.discourse-cdn.com/v4/letter/c/a9a28c/32.png) [@Charleh](https://forum.kirupa.com/u/Charleh)\
**Post date:** [June 4, 2008, 11:14am UTC](https://forum.kirupa.com/t/site-with-login/262130/13 "2008-06-04T11:14:45Z")

</div>

sprintf allows you to place tokens in a target string which it will then replace with a given list of arguments

i.e. in Djherus example - the %s in the target string will be replaced by the value of mysql\_real\_escape\_string($foo)

The percent then letter determines the treatment of the argument passed in - in this case %s means it gets treated as string.

It’s possible to pass as many arguments as you want - i.e.

sprintf(“Some values %s, %s, %s”, “one”, “two”, “three”);

Check out

[http://uk2.php.net/sprintf](http://uk2.php.net/sprintf)

Always useful!

Would produce “Some values one, two, three”

---

<div class="post-metadata">

**Author:** ![Maqrkk](https://avatars.discourse-cdn.com/v4/letter/m/35a633/32.png) [@Maqrkk](https://forum.kirupa.com/u/Maqrkk)\
**Post date:** [June 4, 2008, 12:22pm UTC](https://forum.kirupa.com/t/site-with-login/262130/14 "2008-06-04T12:22:35Z")

</div>

Oh right I get it, thanks! That’s basically a shortcut way then, right?

---

<div class="post-metadata">

**Author:** ![Maqrkk](https://avatars.discourse-cdn.com/v4/letter/m/35a633/32.png) [@Maqrkk](https://forum.kirupa.com/u/Maqrkk)\
**Post date:** [June 4, 2008, 1:18pm UTC](https://forum.kirupa.com/t/site-with-login/262130/15 "2008-06-04T13:18:49Z")

</div>

Ok, the register and log in functions are working partially. Register checks if all fields are filled, then puts it in the database, and login checks if the fields are checked, then if the user exists in the database, and if so checks if the password matches.

However, I’m kind of stuck at this point. How do I tell my index if someone is logged in or not?

---

<div class="post-metadata">

**Author:** ![Charleh](https://avatars.discourse-cdn.com/v4/letter/c/a9a28c/32.png) [@Charleh](https://forum.kirupa.com/u/Charleh)\
**Post date:** [June 4, 2008, 1:36pm UTC](https://forum.kirupa.com/t/site-with-login/262130/16 "2008-06-04T13:36:39Z")

</div>

Use the PHP SESSION variables to store information about the users session.

Create a session variable called “login\_ID” and set it to 0 - when a user is logged in set it to their ID.

$\_SESSION[“login\_ID”] = $some\_database\_id\_value\_for\_the\_user;

Then you can check this on subsequent pages - you might want to check the documentation on PHP sessions - you will need to start a session

[http://uk.php.net/manual/en/function.session-start.php](http://uk.php.net/manual/en/function.session-start.php)

---

<div class="post-metadata">

**Author:** ![Maqrkk](https://avatars.discourse-cdn.com/v4/letter/m/35a633/32.png) [@Maqrkk](https://forum.kirupa.com/u/Maqrkk)\
**Post date:** [June 4, 2008, 1:40pm UTC](https://forum.kirupa.com/t/site-with-login/262130/17 "2008-06-04T13:40:05Z")

</div>

Oh wow, just what I needed 🙂 Thanks again! 😉

---

<div class="post-metadata">

**Author:** ![Maqrkk](https://avatars.discourse-cdn.com/v4/letter/m/35a633/32.png) [@Maqrkk](https://forum.kirupa.com/u/Maqrkk)\
**Post date:** [June 4, 2008, 2:09pm UTC](https://forum.kirupa.com/t/site-with-login/262130/18 "2008-06-04T14:09:39Z")

</div>

I’m trying to get this, but it’s pretty tough for a first-timer. How do I detect in the index if a user has a session running? Basically I want to display ‘Logout’ when someone is logged in, and ‘Login’ when someone is logged out. Once I get that right, the rest shouldn’t be too hard… But I can not get this to work with sessions… lots of new information… Can you show me a really basic example of how to get this done?

---

<div class="post-metadata">

**Author:** ![djheru](https://yyz1.discourse-cdn.com/flex011/user_avatar/forum.kirupa.com/djheru/32/3190_2.png) [@djheru](https://forum.kirupa.com/u/djheru)\
**Post date:** [June 4, 2008, 2:52pm UTC](https://forum.kirupa.com/t/site-with-login/262130/19 "2008-06-04T14:52:30Z")

</div>

When you check to see if the username/password matches, set up an if/else conditional where if they don’t match, you display an error message, and if they do match, you set some $\_SESSION variables, which have values that are “carried across” different pages. For example, you could set $\_SESSION[‘logged\_in’] = true and $\_SESSION[‘username’] = $\_POST[‘username’];

Then, when they navigate from the login page to a different page, the $\_SESSION array keeps the values. You can also test the $\_SESSION[‘logged\_in’] variable to determine what content they see.

edit: In order to use sessions, you must call the PHP built in function session\_start(); before any content is sent to the browser, including headers. I usually just place it at the top of the page, immediately after the opening php tag.

---

<div class="post-metadata">

**Author:** ![Maqrkk](https://avatars.discourse-cdn.com/v4/letter/m/35a633/32.png) [@Maqrkk](https://forum.kirupa.com/u/Maqrkk)\
**Post date:** [June 4, 2008, 4:41pm UTC](https://forum.kirupa.com/t/site-with-login/262130/20 "2008-06-04T16:41:09Z")

</div>

Well my index.php is basically a HTML file with some php code in the body. Does that mean I need an additional php area somewhere in the \<head\>, or even above that with just this: “session\_start();”?  
Also, I guess session\_start initiates a session somehow, and if I do this after session\_start();, does it count?

```php
<?php
session_start();
if($_SESSION['logged_in'])
{
$log = 1;
}
else
{
$log = 0;
}
?>

```

Then could I render the rest of my site by checking $log?

[Next page](https://forum.kirupa.com/t/site-with-login/262130.md?page=2)
