PHP WITH SESSION
// login.php page
<?php
// Start a session or resume the existing session
session_start();
// Check if the user is already logged in, redirect to landing page if logged in
if (isset($_SESSION['user_id'])) {
header("Location: landing.php");
exit;
}
// Check if the login form is submitted
if (isset($_POST['login'])) {
// Validate user credentials (you should hash and securely store passwords)
$username = $_POST['username'];
$password = $_POST['password'];
// Replace with your database connection code
$db_connection = mysqli_connect("localhost", "username", "password", "database_name");
if (!$db_connection) {
die("Connection failed: " . mysqli_connect_error());
}
$sql = "SELECT * FROM users WHERE username = '$username' AND password = '$password'";
$result = mysqli_query($db_connection, $sql);
if (mysqli_num_rows($result) == 1) {
$row = mysqli_fetch_assoc($result);
$_SESSION['user_id'] = $row['id'];
header("Location: landing.php");
exit;
} else {
$error_message = "Invalid username or password.";
}
mysqli_close($db_connection);
}
?>
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>Login Page</title>
</head>
<body>
<h2>Login</h2>
<form method="post" action="">
<label for="username">Username:</label>
<input type="text" name="username" id="username" required><br><br>
<label for="password">Password:</label>
<input type="password" name="password" id="password" required><br><br>
<input type="submit" name="login" value="Login">
</form>
<?php
if (isset($error_message)) {
echo '<p>' . $error_message . '</p>';
}
?>
</body>
</html>
//crud.php
<?php
// Start a new session or resume the existing session
session_start();
// Check if the user is logged in
if (!isset($_SESSION['user_id'])) {
// Redirect to the login page if the user is not logged in
header("Location: login.php");
exit();
}
// Establish a database connection
$conn = new mysqli("localhost", "root", "", "DBNAME");
if ($conn->connect_error) {
die("Connection failed: " . $conn->connect_error);
}
if (isset($_POST["create"])) {
$name = $_POST['name'];
$email = $_POST['email'];
$password = $_POST['password'];
$sql = "INSERT into TBNAME(name, email, password) values ('$name','$email','$password')";
if (mysqli_query($conn, $sql)) {
echo "User created successfully";
} else {
echo "Error creating user: " . mysqli_error($conn);
}
}
if (isset($_POST['update'])) {
$id = $_POST['id'];
$Name = $_POST['name'];
$email = $_POST['email'];
$query = "UPDATE TBNAME set name='$Name', email='$email' where id='$id'";
if (mysqli_query($conn, $query)) {
echo "User updated successfully";
} else {
echo "Error updating user: " . mysqli_error($conn);
}
}
if (isset($_POST['delete'])) {
$id = $_POST['id'];
$query = "DELETE from ad where id='$id'";
if (mysqli_query($conn, $query)) {
echo "User deleted successfully";
} else {
echo "Error deleting user: " . mysqli_error($conn);
}
}
$select = "SELECT * from TBNAME";
$action = mysqli_query($conn, $select);
?>
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Document</title>
</head>
<body>
<h2>Create User</h2>
<form action="" method="post">
Name: <input type="text" name="name"><br>
Email: <input type="email" name="email"><br>
Password: <input type="password" name="password"><br>
<input type="submit" name="create" value="Create">
</form>
<hr>
<h2>Update User</h2>
<form action="" method="post">
User ID: <input type="text" name="id"><br>
New Name: <input type="text" name="name"><br>
New Email: <input type="email" name="email"><br>
<input type="submit" name="update" value="Update">
</form>
<hr>
<h2>Delete User</h2>
<form action="" method="post">
User ID: <input type="text" name="id"><br>
<input type="submit" name="delete" value="Delete">
</form>
<hr>
<h2>Select Users</h2>
<table border="1">
<tr>
<th>ID</th>
<th>Name</th>
<th>Email</th>
</tr>
<?php
while ($row = mysqli_fetch_assoc($action)) {
echo "<tr><td>{$row['id']}</td><td>{$row['name']}</td><td>{$row['email']}</td></tr>";
}
?>
</table>
<p><a href="logout.php">Logout</a></p>
</body>
</html>
// logout.php
<?php
// Start the session
session_start();
// Check if the user is not logged in, redirect to the login page
if (!isset($_SESSION['user_id'])) {
header("Location: login.php");
exit;
}
// Unset the user_id session variable
unset($_SESSION['user_id']);
// Destroy the session
session_destroy();
// Redirect the user to the login page
header("Location: login.php");
exit;
?>
Comments
Post a Comment