关于PHP会话验证中page-two.php访问权限的两类技术咨询
First, let's recap your existing code for context:
Existing Code
page-one.php
<?php //page-one.php session_start(); $_SESSION['page_one'] = time(); ?> hello this is page 1 go to page 2 <a href="www.domain.com/page-two.php">Page 2</a>
page-two.php
<?php //page-two.php session_start(); //Check to see if session variable exists. if(!isset($_SESSION['page_one'])){ //Does not exist. Redirect user back to page-one.php header('Location: 404.php'); exit; } ?> this is page 2
Your Questions & Practical Fixes
1. How to ensure visitors accessing page-two.php via the link can still access it if page-one.php is deleted?
Since page-one.php is where you set the $_SESSION['page_one'] variable, removing it breaks the existing validation flow. Here are a few solid options:
Option 1: Remove the session check entirely (if page-two no longer needs any pre-access restriction):
Just delete the conditional check block inpage-two.php. This lets anyone access the page, including users clicking the original link. Modified code:<?php //page-two.php session_start(); ?> this is page 2Option 2: Use a URL query parameter instead of session (if you still want to distinguish link visitors from direct access):
Update the link in your old page (or wherever it's hosted) to include a parameter:<a href="www.domain.com/page-two.php?valid_access=1">Page 2</a>. Then adjustpage-two.phpto check for this parameter alongside the session (for backward compatibility):<?php //page-two.php session_start(); // Allow access if session exists OR valid query parameter is present if(!isset($_SESSION['page_one']) && !isset($_GET['valid_access'])){ header('Location: 404.php'); exit; } ?> this is page 2This works even with
page-one.phpdeleted, and still honors existing sessions from users who might have visited before the deletion.Option 3: Auto-set the session for valid referrers (if you can't modify the link):
Check the HTTP referrer to see if the user came from your domain (where the original link lives), and auto-set the session if so. Note:HTTP_REFERERisn't 100% reliable (some browsers block it), but it's a quick fix if you can't update the link:<?php //page-two.php session_start(); if(!isset($_SESSION['page_one'])){ $trustedDomain = 'www.domain.com'; // Check if referrer contains your domain if(strpos($_SERVER['HTTP_REFERER'] ?? '', $trustedDomain) !== false){ $_SESSION['page_one'] = time(); // Auto-create the session } else { header('Location: 404.php'); exit; } } ?> this is page 2
2. How can users accessing page-two.php directly from Google pass the page_one session check?
Direct visitors from Google don't have the $_SESSION['page_one'] variable set, so they get redirected to 404. Here's how to adjust the logic to accommodate them:
Option 1: Auto-set the session for first-time direct visitors (simplest fix if you don't need strict access control):
Instead of redirecting, just create the session variable when it's missing. This lets direct visitors access the page immediately, and the session will persist for their visit:<?php //page-two.php session_start(); // Create session if it doesn't exist if(!isset($_SESSION['page_one'])){ $_SESSION['page_one'] = time(); } ?> this is page 2Option 2: Add a landing page for direct visitors (if you want to control access but still let Google users in):
Redirect missing-session users to a landing page where they can confirm access, which then sets the session. Updatepage-two.php:<?php //page-two.php session_start(); if(!isset($_SESSION['page_one'])){ header('Location: landing.php'); exit; } ?> this is page 2Then create
landing.php:<?php session_start(); if(isset($_POST['enter_page_two'])){ $_SESSION['page_one'] = time(); header('Location: page-two.php'); exit; } ?> <h1>Welcome to Page 2!</h1> <p>Click the button below to enter:</p> <form method="post"> <button type="submit" name="enter_page_two">Enter Page 2</button> </form>This way, Google visitors get a friendly entry point instead of a 404, and you still maintain some control over access.
Option 3: Use a cookie for initial access (if you want to remember returning direct visitors):
Set a cookie on the first direct visit, then use that cookie to validate future access (and sync it to the session):<?php //page-two.php session_start(); if(!isset($_SESSION['page_one'])){ if(isset($_COOKIE['allowed_page_two'])){ $_SESSION['page_one'] = time(); // Sync cookie to session } else { // Set a 24-hour cookie to allow future access setcookie('allowed_page_two', '1', time() + 86400, '/'); // Allow access for this visit } } ?> this is page 2First-time direct visitors get access immediately, and returning visitors will have the session set automatically via the cookie.
内容的提问来源于stack exchange,提问作者Bilal

