You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于PHP会话验证中page-two.php访问权限的两类技术咨询

Session Validation: Solutions for Your Two Scenarios

First, let's recap your existing code for context:

Existing Code

page-one.php

<?php 
//page-one.php 
session_start(); 
$_SESSION['page_one'] = time(); 
?> 
hello this is page 1 go to page 2 <a href="www.domain.com/page-two.php">Page 2</a>

page-two.php

<?php 
//page-two.php 
session_start(); 
//Check to see if session variable exists. 
if(!isset($_SESSION['page_one'])){ 
    //Does not exist. Redirect user back to page-one.php 
    header('Location: 404.php'); 
    exit; 
} 
?> 
this is page 2

Your Questions & Practical Fixes

Since page-one.php is where you set the $_SESSION['page_one'] variable, removing it breaks the existing validation flow. Here are a few solid options:

  • Option 1: Remove the session check entirely (if page-two no longer needs any pre-access restriction):
    Just delete the conditional check block in page-two.php. This lets anyone access the page, including users clicking the original link. Modified code:

    <?php 
    //page-two.php 
    session_start(); 
    ?> 
    this is page 2
    
  • Option 2: Use a URL query parameter instead of session (if you still want to distinguish link visitors from direct access):
    Update the link in your old page (or wherever it's hosted) to include a parameter: <a href="www.domain.com/page-two.php?valid_access=1">Page 2</a>. Then adjust page-two.php to check for this parameter alongside the session (for backward compatibility):

    <?php 
    //page-two.php 
    session_start(); 
    // Allow access if session exists OR valid query parameter is present
    if(!isset($_SESSION['page_one']) && !isset($_GET['valid_access'])){ 
        header('Location: 404.php'); 
        exit; 
    } 
    ?> 
    this is page 2
    

    This works even with page-one.php deleted, and still honors existing sessions from users who might have visited before the deletion.

  • Option 3: Auto-set the session for valid referrers (if you can't modify the link):
    Check the HTTP referrer to see if the user came from your domain (where the original link lives), and auto-set the session if so. Note: HTTP_REFERER isn't 100% reliable (some browsers block it), but it's a quick fix if you can't update the link:

    <?php 
    //page-two.php 
    session_start(); 
    if(!isset($_SESSION['page_one'])){
        $trustedDomain = 'www.domain.com';
        // Check if referrer contains your domain
        if(strpos($_SERVER['HTTP_REFERER'] ?? '', $trustedDomain) !== false){
            $_SESSION['page_one'] = time(); // Auto-create the session
        } else {
            header('Location: 404.php');
            exit;
        }
    } 
    ?> 
    this is page 2
    

2. How can users accessing page-two.php directly from Google pass the page_one session check?

Direct visitors from Google don't have the $_SESSION['page_one'] variable set, so they get redirected to 404. Here's how to adjust the logic to accommodate them:

  • Option 1: Auto-set the session for first-time direct visitors (simplest fix if you don't need strict access control):
    Instead of redirecting, just create the session variable when it's missing. This lets direct visitors access the page immediately, and the session will persist for their visit:

    <?php 
    //page-two.php 
    session_start(); 
    // Create session if it doesn't exist
    if(!isset($_SESSION['page_one'])){ 
        $_SESSION['page_one'] = time(); 
    } 
    ?> 
    this is page 2
    
  • Option 2: Add a landing page for direct visitors (if you want to control access but still let Google users in):
    Redirect missing-session users to a landing page where they can confirm access, which then sets the session. Update page-two.php:

    <?php 
    //page-two.php 
    session_start(); 
    if(!isset($_SESSION['page_one'])){ 
        header('Location: landing.php'); 
        exit; 
    } 
    ?> 
    this is page 2
    

    Then create landing.php:

    <?php 
    session_start(); 
    if(isset($_POST['enter_page_two'])){
        $_SESSION['page_one'] = time();
        header('Location: page-two.php');
        exit;
    }
    ?>
    <h1>Welcome to Page 2!</h1>
    <p>Click the button below to enter:</p>
    <form method="post">
        <button type="submit" name="enter_page_two">Enter Page 2</button>
    </form>
    

    This way, Google visitors get a friendly entry point instead of a 404, and you still maintain some control over access.

  • Option 3: Use a cookie for initial access (if you want to remember returning direct visitors):
    Set a cookie on the first direct visit, then use that cookie to validate future access (and sync it to the session):

    <?php 
    //page-two.php 
    session_start(); 
    if(!isset($_SESSION['page_one'])){
        if(isset($_COOKIE['allowed_page_two'])){
            $_SESSION['page_one'] = time(); // Sync cookie to session
        } else {
            // Set a 24-hour cookie to allow future access
            setcookie('allowed_page_two', '1', time() + 86400, '/');
            // Allow access for this visit
        }
    } 
    ?> 
    this is page 2
    

    First-time direct visitors get access immediately, and returning visitors will have the session set automatically via the cookie.


内容的提问来源于stack exchange,提问作者Bilal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.06 07:42:48