Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #2117 > unrolled thread

variable value gets lost

Started byCo <vonclausowitz@gmail.com>
First post2011-06-12 12:13 -0700
Last post2011-06-12 21:24 -0400
Articles 6 — 4 participants

Back to article view | Back to comp.lang.php


Contents

  variable value gets lost Co <vonclausowitz@gmail.com> - 2011-06-12 12:13 -0700
    Re: variable value gets lost Mathieu Maes <mathieu@webberig.be> - 2011-06-12 12:43 -0700
    Re: variable value gets lost Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-12 17:06 -0400
      Re: variable value gets lost Co <vonclausowitz@gmail.com> - 2011-06-12 14:17 -0700
        Re: variable value gets lost Denis McMahon <denis.m.f.mcmahon@gmail.com> - 2011-06-13 00:56 +0000
        Re: variable value gets lost Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-12 21:24 -0400

#2117 — variable value gets lost

FromCo <vonclausowitz@gmail.com>
Date2011-06-12 12:13 -0700
Subjectvariable value gets lost
Message-ID<ebb12a8d-bbb4-4304-82cf-96524189c044@em7g2000vbb.googlegroups.com>
Hi All,

I have a page with shows the profile of one of my users.
the id of the user is send to the page:  profile.php?id=3
It is retrieved on the page by $id = $_GET['id'].

When I click a submit button on the page to add a message
to the user I lose his $id.
How can I preserve the value of $id to add the message to the user?

$sqlName = mysql_query("SELECT * FROM myMembers WHERE
id='$logOptions_id' LIMIT 1") or die ("Sorry we had a mysql error!");

	while ($row = mysql_fetch_array($sqlName)) { $firstname =
$row["firstname"];$lastname = $row["lastname"];$username =
$row["username"];$userid = $row["id"];}

				if ($userid != $id){
					$query = mysql_query("SELECT * FROM profile_comments WHERE
profile_id='$uid' AND user_id='$userid' AND comment='$comment'");
					$numrows = mysql_num_rows($query);
					print $numrows;
					if ($numrows == 0){
						$commdate = date("d F Y"); // 08 October, 2010
						print $commdate;
						mysql_query("INSERT INTO profile_comments VALUES ('', '$uid',
'$userid', '$username', '$comment', '$commdate')");

Marco

[toc] | [next] | [standalone]


#2118

FromMathieu Maes <mathieu@webberig.be>
Date2011-06-12 12:43 -0700
Message-ID<e2f3c2a2-191e-4c38-bf4b-ed5d61501d9e@i4g2000yqg.googlegroups.com>
In reply to#2117
On 12 jun, 21:13, Co <vonclausow...@gmail.com> wrote:
> Hi All,
>
> I have a page with shows the profile of one of my users.
> the id of the user is send to the page:  profile.php?id=3
> It is retrieved on the page by $id = $_GET['id'].
>
> When I click a submit button on the page to add a message
> to the user I lose his $id.
> How can I preserve the value of $id to add the message to the user?
>
> $sqlName = mysql_query("SELECT * FROM myMembers WHERE
> id='$logOptions_id' LIMIT 1") or die ("Sorry we had a mysql error!");
>
>         while ($row = mysql_fetch_array($sqlName)) { $firstname =
> $row["firstname"];$lastname = $row["lastname"];$username =
> $row["username"];$userid = $row["id"];}
>
>                                 if ($userid != $id){
>                                         $query = mysql_query("SELECT * FROM profile_comments WHERE
> profile_id='$uid' AND user_id='$userid' AND comment='$comment'");
>                                         $numrows = mysql_num_rows($query);
>                                         print $numrows;
>                                         if ($numrows == 0){
>                                                 $commdate = date("d F Y"); // 08 October, 2010
>                                                 print $commdate;
>                                                 mysql_query("INSERT INTO profile_comments VALUES ('', '$uid',
> '$userid', '$username', '$comment', '$commdate')");
>
> Marco

Hi Marco,

Since you haven't provided the HTML code from your form, I will assume
the following:
<form method="post" action="profile.php">
...
<input type="submit" />
</form>

Look at the first line where I provide the form "action". If you click
the submit button, the data will be sent to profile.php which does not
contain your user ID (?id=9000).

I guess the best solution is to add the user ID inside the form as a
hidden input:
<form>
 <input type="hidden" name="id" value="<?php echo $id;?>" />
</form>

As a result, the User ID is being sent with your form, and can be read
as follows:
<?php
$id = $_POST['id']; //Assuming you're using POST method
?>

I should warn you that the ID is exposed to the user, which can be
manipulated. If there are certain security limitations (i.e. only be
able to post comments to a certain group of users), you must validate
$_POST['id'] to make sure the user is allowed to post using that ID!!

Kind regards,
Mathew

[toc] | [prev] | [next] | [standalone]


#2125

FromJerry Stuckle <jstucklex@attglobal.net>
Date2011-06-12 17:06 -0400
Message-ID<it39of$7m9$1@dont-email.me>
In reply to#2117
On 6/12/2011 3:13 PM, Co wrote:
> Hi All,
>
> I have a page with shows the profile of one of my users.
> the id of the user is send to the page:  profile.php?id=3
> It is retrieved on the page by $id = $_GET['id'].
>
> When I click a submit button on the page to add a message
> to the user I lose his $id.
> How can I preserve the value of $id to add the message to the user?
>
> $sqlName = mysql_query("SELECT * FROM myMembers WHERE
> id='$logOptions_id' LIMIT 1") or die ("Sorry we had a mysql error!");
>
> 	while ($row = mysql_fetch_array($sqlName)) { $firstname =
> $row["firstname"];$lastname = $row["lastname"];$username =
> $row["username"];$userid = $row["id"];}
>
> 				if ($userid != $id){
> 					$query = mysql_query("SELECT * FROM profile_comments WHERE
> profile_id='$uid' AND user_id='$userid' AND comment='$comment'");
> 					$numrows = mysql_num_rows($query);
> 					print $numrows;
> 					if ($numrows == 0){
> 						$commdate = date("d F Y"); // 08 October, 2010
> 						print $commdate;
> 						mysql_query("INSERT INTO profile_comments VALUES ('', '$uid',
> '$userid', '$username', '$comment', '$commdate')");
>
> Marco

You do NOT want to pass the user's id in either the form or the URL.  It 
is so easy to hack and assume the id of another user it's not even funny.

Rather, pass it in the $_SESSION.

Also, anything you pass is in the URL is in the $_GET array.  Variables 
in your program are not automatically set (in a secure system, anyway).

-- 
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@attglobal.net
==================

[toc] | [prev] | [next] | [standalone]


#2128

FromCo <vonclausowitz@gmail.com>
Date2011-06-12 14:17 -0700
Message-ID<f3914c36-2084-4f49-99c6-f6de4f37edc6@k13g2000vbv.googlegroups.com>
In reply to#2125
On 12 jun, 23:06, Jerry Stuckle <jstuck...@attglobal.net> wrote:
> On 6/12/2011 3:13 PM, Co wrote:
>
>
>
>
>
>
>
>
>
> > Hi All,
>
> > I have a page with shows the profile of one of my users.
> > the id of the user is send to the page:  profile.php?id=3
> > It is retrieved on the page by $id = $_GET['id'].
>
> > When I click a submit button on the page to add a message
> > to the user I lose his $id.
> > How can I preserve the value of $id to add the message to the user?
>
> > $sqlName = mysql_query("SELECT * FROM myMembers WHERE
> > id='$logOptions_id' LIMIT 1") or die ("Sorry we had a mysql error!");
>
> >    while ($row = mysql_fetch_array($sqlName)) { $firstname =
> > $row["firstname"];$lastname = $row["lastname"];$username =
> > $row["username"];$userid = $row["id"];}
>
> >                            if ($userid != $id){
> >                                    $query = mysql_query("SELECT * FROM profile_comments WHERE
> > profile_id='$uid' AND user_id='$userid' AND comment='$comment'");
> >                                    $numrows = mysql_num_rows($query);
> >                                    print $numrows;
> >                                    if ($numrows == 0){
> >                                            $commdate = date("d F Y"); // 08 October, 2010
> >                                            print $commdate;
> >                                            mysql_query("INSERT INTO profile_comments VALUES ('', '$uid',
> > '$userid', '$username', '$comment', '$commdate')");
>
> > Marco
>
> You do NOT want to pass the user's id in either the form or the URL.  It
> is so easy to hack and assume the id of another user it's not even funny.
>
> Rather, pass it in the $_SESSION.
>
> Also, anything you pass is in the URL is in the $_GET array.  Variables
> in your program are not automatically set (in a secure system, anyway).
>
> --
> ==================
> Remove the "x" from my email address
> Jerry Stuckle
> JDS Computer Training Corp.
> jstuck...@attglobal.net
> ==================

Jerry,

so instead of doing profle.php?id=3
I should put it in a $_session ?
what was the code for that again?

Marco

[toc] | [prev] | [next] | [standalone]


#2130

FromDenis McMahon <denis.m.f.mcmahon@gmail.com>
Date2011-06-13 00:56 +0000
Message-ID<4df56056$0$2368$bed64819@gradwell.net>
In reply to#2128
On Sun, 12 Jun 2011 14:17:57 -0700, Co wrote:

> so instead of doing profle.php?id=3
> I should put it in a $_session ?
> what was the code for that again?

http://lmgtfy.com/?q=php+session

Rgds

Denis McMahon

[toc] | [prev] | [next] | [standalone]


#2131

FromJerry Stuckle <jstucklex@attglobal.net>
Date2011-06-12 21:24 -0400
Message-ID<it3os9$ur6$1@dont-email.me>
In reply to#2128
On 6/12/2011 5:17 PM, Co wrote:
> On 12 jun, 23:06, Jerry Stuckle<jstuck...@attglobal.net>  wrote:
>> On 6/12/2011 3:13 PM, Co wrote:
>>
>>
>>
>>
>>
>>
>>
>>
>>
>>> Hi All,
>>
>>> I have a page with shows the profile of one of my users.
>>> the id of the user is send to the page:  profile.php?id=3
>>> It is retrieved on the page by $id = $_GET['id'].
>>
>>> When I click a submit button on the page to add a message
>>> to the user I lose his $id.
>>> How can I preserve the value of $id to add the message to the user?
>>
>>> $sqlName = mysql_query("SELECT * FROM myMembers WHERE
>>> id='$logOptions_id' LIMIT 1") or die ("Sorry we had a mysql error!");
>>
>>>     while ($row = mysql_fetch_array($sqlName)) { $firstname =
>>> $row["firstname"];$lastname = $row["lastname"];$username =
>>> $row["username"];$userid = $row["id"];}
>>
>>>                             if ($userid != $id){
>>>                                     $query = mysql_query("SELECT * FROM profile_comments WHERE
>>> profile_id='$uid' AND user_id='$userid' AND comment='$comment'");
>>>                                     $numrows = mysql_num_rows($query);
>>>                                     print $numrows;
>>>                                     if ($numrows == 0){
>>>                                             $commdate = date("d F Y"); // 08 October, 2010
>>>                                             print $commdate;
>>>                                             mysql_query("INSERT INTO profile_comments VALUES ('', '$uid',
>>> '$userid', '$username', '$comment', '$commdate')");
>>
>>> Marco
>>
>> You do NOT want to pass the user's id in either the form or the URL.  It
>> is so easy to hack and assume the id of another user it's not even funny.
>>
>> Rather, pass it in the $_SESSION.
>>
>> Also, anything you pass is in the URL is in the $_GET array.  Variables
>> in your program are not automatically set (in a secure system, anyway).
>>
>
> Jerry,
>
> so instead of doing profle.php?id=3
> I should put it in a $_session ?
> what was the code for that again?
>
> Marco

Try the manual.  You can find it at http://www.php.net.  There are 
plenty of examples.

Don't expect people to write your code for you.  If you're too lazy to 
try to learn how to properly code in PHP (i.e. get books, read 
tutorials, etc.), then hire someone to do it for you.

-- 
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@attglobal.net
==================

[toc] | [prev] | [standalone]


Back to top | Article view | comp.lang.php


csiph-web