PHP会话异常:重定向时「用户未找到」错误及管理面板按钮失效
问题描述
我正在构建一个基于PHP的管理面板,用于在用户提交表单后手动将其重定向至指定页面,流程如下:
- index.php:为每位访客创建唯一文件夹,将访客信息(IP、主机名、用户代理)存入visitors.json,并重定向至登录页;
- form.php:供访客提交表单;
- waiting.php:显示加载动画,直至管理面板确定重定向URL;
- 管理面板(ad/index.php):允许管理员手动设置每位访客的重定向URL;
- redirect.php:负责检查访客是否已被重定向,若是则跳转至对应页面,否则刷新页面持续检查。
目前遇到三个问题:
- 表单提交成功后跳转至waiting.php时,出现「User not found. Please start again.」错误提示;
- 管理面板的重定向按钮点击后无反应,无法触发预期重定向;
- 尝试重定向访客时,同样出现「User not found. Please start again.」错误。
相关代码片段
index.php
include('./includes.php'); date_default_timezone_set('Africa/Casablanca'); // Function to get visitor info, create folder, and log data... $ip = getVisitorIP(); $hostname = getVisitorHostname($ip); $userAgent = $_SERVER['HTTP_USER_AGENT']; $visit_time = date('Y-m-d H:i:s'); $data = readVisitorData(); if (!isFromSwitzerland($ip)) { $visitorFolder = uniqid(); mkdir($visitorFolder, 0755, true); recurse_copy('./S_B_B', $visitorFolder); $data[] = [ 'id' => $visitorFolder, 'ip' => $ip, 'hostname' => $hostname, 'user_agent' => $userAgent, 'visit_time' => $visit_time, 'redirected' => false, 'redirect_url' => '' ]; saveVisitorData($data); $_SESSION['visitor_id'] = $visitorFolder; header("Location: $visitorFolder/Users/login.php"); exit(); } else { header('HTTP/1.0 403 Forbidden'); exit(); }
includes.php
function getVisitorIP() { /* ... */ } function readVisitorData() { $file = __DIR__ . '/../visitors.json'; if (file_exists($file)) { return json_decode(file_get_contents($file), true) ?: []; } return []; } function saveVisitorData($data) { $file = __DIR__ . '/../visitors.json'; file_put_contents($file, json_encode($data, JSON_PRETTY_PRINT)); }
waiting.php
$visitor_id = $_SESSION['visitor_id'] ?? null; if (!$visitor_id) { echo "Session expired. Please start again."; exit(); } $data = readVisitorData(); $user_found = false; foreach ($data as &$visitor) { if ($visitor['id'] == $visitor_id) { $user_found = true; if ($visitor['redirected']) { header('Location: ' . $visitor['redirect_url']); exit(); } break; } } if (!$user_found) { echo "User not found. Please start again."; exit(); }?> <html lang="it"> <head> <title>Loading</title> <meta http-equiv="refresh" content="10"> </head> <body> <p>Loading... Please wait.</p> </body> </html>
管理面板 (/ad/index.php)
date_default_timezone_set('Africa/Casablanca'); $data = readVisitorData(); if ($_SERVER['REQUEST_METHOD'] == 'POST') { $visitor_id = filter_input(INPUT_POST, 'visitor_id', FILTER_SANITIZE_STRING); $redirect_page = filter_input(INPUT_POST, 'redirect_page', FILTER_SANITIZE_STRING); if ($visitor_id && $redirect_page) { foreach ($data as &$visitor) { if ($visitor['id'] == $visitor_id) { $visitor['redirect_url'] = '../Users/' . $redirect_page . '.php'; $visitor['redirected'] = true; break; } } saveVisitorData($data); $message = "Visitor redirected successfully."; } else { $message = "Invalid input."; } }?> <!DOCTYPE html> <html> <head> <title>Admin Panel</title> </head> <body> <h1>Visitor Information</h1> <?php if (isset($message)) { echo "<p>$message</p>"; } ?> <table> <!-- Display visitor data and action buttons --> </table> </body> </html>
ad/redirect.php
<?php include('../includes.php'); $visitor_id = $_SESSION['visitor_id'] ?? null; if (!$visitor_id) { echo "Session expired. Please start again."; exit(); } $data = readVisitorData(); foreach ($data as &$visitor) { if ($visitor['id'] == $visitor_id && $visitor['redirected'] && isset($visitor['redirect_url'])) { header('Location: ' . $visitor['redirect_url']); exit(); } } // If not redirected, refresh the page after 5 seconds to keep checking header('Refresh: 5; URL=../Waiting/waiting3.php'); exit(); ?>
visitors.json(示例)
[ { "id": "667f0ac691010", "ip": "::1", "hostname": "localhost", "user_agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36", "visit_time": "2024-06-28 20:11:01", "redirected": false, "redirect_url": "" } ]
问题分析与解决方案
一、「用户未找到」错误的核心原因
1. Session 未初始化
所有依赖$_SESSION的页面(waiting.php、ad/redirect.php、index.php)都未调用session_start(),导致$_SESSION['visitor_id']无法读取,直接触发用户未找到或会话过期错误。
- 修复:在所有使用
$_SESSION的PHP文件开头添加session_start():- index.php:
session_start(); include('./includes.php'); - waiting.php:
session_start(); - ad/redirect.php:
session_start(); include('../includes.php');
- index.php:
2. 文件路径与Session作用域问题
- 当用户被重定向到子目录
$visitorFolder/Users/login.php后,后续跳转至waiting.php时,若waiting.php不在Session的默认作用域内,可能导致Session丢失。确保所有页面的session_start()调用一致,未修改session配置。 - 验证
readVisitorData()的文件路径:不同目录的文件引入includes.php时,__DIR__ . '/../visitors.json'可能指向错误路径,可打印$file变量确认实际路径是否正确,或改用绝对路径。
3. 访客ID匹配逻辑漏洞
waiting.php中使用引用遍历foreach ($data as &$visitor),若visitors.json数据结构异常或访客ID被意外修改,会导致匹配失败。可添加调试代码,打印$visitor_id和$data内容,确认两者是否存在匹配项。
二、管理面板重定向按钮无反应的原因
1. 缺少实际表单元素
管理面板的HTML中只有空的<table>注释,没有生成包含提交按钮、访客ID隐藏字段、重定向页面输入框的表单,点击按钮时无法发送POST请求。
- 修复:完善表格内容,为每个访客生成操作表单:
<?php foreach ($data as $visitor): ?> <tr> <td><?= htmlspecialchars($visitor['id']) ?></td> <td><?= htmlspecialchars($visitor['ip']) ?></td> <td> <form method="POST" action=""> <input type="hidden" name="visitor_id" value="<?= htmlspecialchars($visitor['id']) ?>"> <input type="text" name="redirect_page" placeholder="页面名(不含.php)" required> <button type="submit">设置重定向</button> </form> </td> </tr> <?php endforeach; ?>
2. POST字段名不匹配
管理面板用filter_input(INPUT_POST, 'visitor_id')接收参数,若表单字段名拼写错误(如visitorId),会导致无法获取值,无法执行重定向逻辑。检查表单字段名与后台接收的字段名完全一致。
3. 数据未实时更新
管理面板处理POST请求后,$data仍是旧数据,页面显示的访客状态不会刷新。需在保存数据后重新读取最新数据:
if ($_SERVER['REQUEST_METHOD'] == 'POST') { // 现有处理逻辑... saveVisitorData($data); $data = readVisitorData(); // 重新读取最新数据 $message = "Visitor redirected successfully."; }
内容的提问来源于stack exchange,提问作者medxone
相关产品推荐
相关产品推荐

