Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #2131

Re: variable value gets lost

From Jerry Stuckle <jstucklex@attglobal.net>
Newsgroups comp.lang.php
Subject Re: variable value gets lost
Date 2011-06-12 21:24 -0400
Organization A noiseless patient Spider
Message-ID <it3os9$ur6$1@dont-email.me> (permalink)
References <ebb12a8d-bbb4-4304-82cf-96524189c044@em7g2000vbb.googlegroups.com> <it39of$7m9$1@dont-email.me> <f3914c36-2084-4f49-99c6-f6de4f37edc6@k13g2000vbv.googlegroups.com>

Show all headers | View raw


On 6/12/2011 5:17 PM, Co wrote:
> On 12 jun, 23:06, Jerry Stuckle<jstuck...@attglobal.net>  wrote:
>> On 6/12/2011 3:13 PM, Co wrote:
>>
>>
>>
>>
>>
>>
>>
>>
>>
>>> Hi All,
>>
>>> I have a page with shows the profile of one of my users.
>>> the id of the user is send to the page:  profile.php?id=3
>>> It is retrieved on the page by $id = $_GET['id'].
>>
>>> When I click a submit button on the page to add a message
>>> to the user I lose his $id.
>>> How can I preserve the value of $id to add the message to the user?
>>
>>> $sqlName = mysql_query("SELECT * FROM myMembers WHERE
>>> id='$logOptions_id' LIMIT 1") or die ("Sorry we had a mysql error!");
>>
>>>     while ($row = mysql_fetch_array($sqlName)) { $firstname =
>>> $row["firstname"];$lastname = $row["lastname"];$username =
>>> $row["username"];$userid = $row["id"];}
>>
>>>                             if ($userid != $id){
>>>                                     $query = mysql_query("SELECT * FROM profile_comments WHERE
>>> profile_id='$uid' AND user_id='$userid' AND comment='$comment'");
>>>                                     $numrows = mysql_num_rows($query);
>>>                                     print $numrows;
>>>                                     if ($numrows == 0){
>>>                                             $commdate = date("d F Y"); // 08 October, 2010
>>>                                             print $commdate;
>>>                                             mysql_query("INSERT INTO profile_comments VALUES ('', '$uid',
>>> '$userid', '$username', '$comment', '$commdate')");
>>
>>> Marco
>>
>> You do NOT want to pass the user's id in either the form or the URL.  It
>> is so easy to hack and assume the id of another user it's not even funny.
>>
>> Rather, pass it in the $_SESSION.
>>
>> Also, anything you pass is in the URL is in the $_GET array.  Variables
>> in your program are not automatically set (in a secure system, anyway).
>>
>
> Jerry,
>
> so instead of doing profle.php?id=3
> I should put it in a $_session ?
> what was the code for that again?
>
> Marco

Try the manual.  You can find it at http://www.php.net.  There are 
plenty of examples.

Don't expect people to write your code for you.  If you're too lazy to 
try to learn how to properly code in PHP (i.e. get books, read 
tutorials, etc.), then hire someone to do it for you.

-- 
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@attglobal.net
==================

Back to comp.lang.php | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

variable value gets lost Co <vonclausowitz@gmail.com> - 2011-06-12 12:13 -0700
  Re: variable value gets lost Mathieu Maes <mathieu@webberig.be> - 2011-06-12 12:43 -0700
  Re: variable value gets lost Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-12 17:06 -0400
    Re: variable value gets lost Co <vonclausowitz@gmail.com> - 2011-06-12 14:17 -0700
      Re: variable value gets lost Denis McMahon <denis.m.f.mcmahon@gmail.com> - 2011-06-13 00:56 +0000
      Re: variable value gets lost Jerry Stuckle <jstucklex@attglobal.net> - 2011-06-12 21:24 -0400

csiph-web