PHP是用户会话/cookie有效的重定向错误


php is user session/cookie valid redirect error

下面的代码应该检查是否存在一个有效的会话或一个有效的cookie,如果是include_once file A.php,如果不是include_once login.php

到目前为止,login.phplogout.php正在正确执行(会话/cookie)正在创建和销毁,但以下代码仍然没有显示正确的内容。

正如这段代码所示,我看到的是login.php,无论会话或cookie是否有效。

任何帮助都太好了。谢谢你。

<?php
include_once '../accounts/dbc.php'; 
if (isset($_SESSION['user_id']) && isset($_SESSION['user_name']) ) 
{
    include_once 'A.php';
}
else if(isset($_COOKIE['user_id']) && isset($_COOKIE['user_key'])){
    /* we double check cookie expiry time against stored in database */
    $cookie_user_id  = filter($_COOKIE['user_id']);
    $rs_ctime = mysql_query("select `ckey`,`ctime` from `users` where `id` ='$cookie_user_id'") or die(mysql_error());
    list($ckey,$ctime) = mysql_fetch_row($rs_ctime);
    // coookie expiry
    if( (time() - $ctime) > 60*60*24*COOKIE_TIME_OUT) {
        include_once '../login.php';
        }
/* Security check with untrusted cookies - dont trust value stored in cookie.       
/* We also do authentication check of the `ckey` stored in cookie matches that stored in database during login*/
     if( !empty($ckey) && is_numeric($_COOKIE['user_id']) && isUserID($_COOKIE['user_name']) && $_COOKIE['user_key'] == sha1($ckey)  ) {
          session_regenerate_id(); //against session fixation attacks.
          $_SESSION['user_id'] = $_COOKIE['user_id'];
          $_SESSION['user_name'] = $_COOKIE['user_name'];
        /* query user level from database instead of storing in cookies */  
          list($user_level) = mysql_fetch_row(mysql_query("select user_level from users where id='$_SESSION[user_id]'"));
          $_SESSION['user_level'] = $user_level;
          $_SESSION['HTTP_USER_AGENT'] = md5($_SERVER['HTTP_USER_AGENT']);
          include_once 'A.php';
       } 
       else {
          include_once '../login.php';
       }
  } else {
  include_once '../login.php';
}
?>

花了两个13小时的时间和一些帮助,但在第三次重写之后,事情似乎只有一个小的服务器因果错误,我将不得不忍受。这个问题可以解决。谢谢你。