PHP WITH SESSION

 // login.php page


<?php

// Start a session or resume the existing session

session_start();


// Check if the user is already logged in, redirect to landing page if logged in

if (isset($_SESSION['user_id'])) {

    header("Location: landing.php");

    exit;

}


// Check if the login form is submitted

if (isset($_POST['login'])) {

    // Validate user credentials (you should hash and securely store passwords)

    $username = $_POST['username'];

    $password = $_POST['password'];


    // Replace with your database connection code

    $db_connection = mysqli_connect("localhost", "username", "password", "database_name");


    if (!$db_connection) {

        die("Connection failed: " . mysqli_connect_error());

    }


    $sql = "SELECT * FROM users WHERE username = '$username' AND password = '$password'";

    $result = mysqli_query($db_connection, $sql);


    if (mysqli_num_rows($result) == 1) {

        $row = mysqli_fetch_assoc($result);

        $_SESSION['user_id'] = $row['id'];

        header("Location: landing.php");

        exit;

    } else {

        $error_message = "Invalid username or password.";

    }


    mysqli_close($db_connection);

}

?>


<!DOCTYPE html>

<html lang="en">

<head>

    <meta charset="UTF-8">

    <title>Login Page</title>

</head>

<body>

    <h2>Login</h2>

    <form method="post" action="">

        <label for="username">Username:</label>

        <input type="text" name="username" id="username" required><br><br>

        

        <label for="password">Password:</label>

        <input type="password" name="password" id="password" required><br><br>


        <input type="submit" name="login" value="Login">

    </form>


    <?php

    if (isset($error_message)) {

        echo '<p>' . $error_message . '</p>';

    }

    ?>

</body>

</html>



//crud.php


<?php

// Start a new session or resume the existing session

session_start();


// Check if the user is logged in

if (!isset($_SESSION['user_id'])) {

    // Redirect to the login page if the user is not logged in

    header("Location: login.php");

    exit();

}


// Establish a database connection

$conn = new mysqli("localhost", "root", "", "DBNAME");


if ($conn->connect_error) {

    die("Connection failed: " . $conn->connect_error);

}


if (isset($_POST["create"])) {

    $name = $_POST['name'];

    $email = $_POST['email'];

    $password = $_POST['password'];


    $sql = "INSERT into TBNAME(name, email, password) values ('$name','$email','$password')";


    if (mysqli_query($conn, $sql)) {

        echo "User created successfully";

    } else {

        echo "Error creating user: " . mysqli_error($conn);

    }

}


if (isset($_POST['update'])) {

    $id = $_POST['id'];

    $Name = $_POST['name'];

    $email = $_POST['email'];


    $query = "UPDATE TBNAME set name='$Name', email='$email' where id='$id'";


    if (mysqli_query($conn, $query)) {

        echo "User updated successfully";

    } else {

        echo "Error updating user: " . mysqli_error($conn);

    }

}


if (isset($_POST['delete'])) {

    $id = $_POST['id'];

    $query = "DELETE from ad where id='$id'";

    if (mysqli_query($conn, $query)) {

        echo "User deleted successfully";

    } else {

        echo "Error deleting user: " . mysqli_error($conn);

    }

}


$select = "SELECT * from TBNAME";

$action = mysqli_query($conn, $select);


?>

<!DOCTYPE html>

<html lang="en">


<head>

    <meta charset="UTF-8">

    <meta name="viewport" content="width=device-width, initial-scale=1.0">

    <title>Document</title>

</head>


<body>

    <h2>Create User</h2>

    <form action="" method="post">

        Name: <input type="text" name="name"><br>

        Email: <input type="email" name="email"><br>

        Password: <input type="password" name="password"><br>

        <input type="submit" name="create" value="Create">

    </form>

    <hr>

    <h2>Update User</h2>

    <form action="" method="post">

        User ID: <input type="text" name="id"><br>

        New Name: <input type="text" name="name"><br>

        New Email: <input type="email" name="email"><br>

        <input type="submit" name="update" value="Update">

    </form>

    <hr>

    <h2>Delete User</h2>

    <form action="" method="post">

        User ID: <input type="text" name="id"><br>

        <input type="submit" name="delete" value="Delete">

    </form>

    <hr>

    <h2>Select Users</h2>

    <table border="1">

        <tr>

            <th>ID</th>

            <th>Name</th>

            <th>Email</th>

        </tr>

        <?php

        while ($row = mysqli_fetch_assoc($action)) {

            echo "<tr><td>{$row['id']}</td><td>{$row['name']}</td><td>{$row['email']}</td></tr>";

        }

        ?>

    </table>

  <p><a href="logout.php">Logout</a></p>

</body>


</html>


  



// logout.php



<?php

// Start the session

session_start();


// Check if the user is not logged in, redirect to the login page

if (!isset($_SESSION['user_id'])) {

    header("Location: login.php");

    exit;

}


// Unset the user_id session variable

unset($_SESSION['user_id']);


// Destroy the session

session_destroy();


// Redirect the user to the login page

header("Location: login.php");

exit;

?>




Comments