如何阻止已登录用户未登出时返回login.php?
Hey Erik, let's get that back button issue sorted out for your LASOW login system! The problem comes down to two key gaps in your current setup: your login.php doesn't check if a user is already authenticated, and browsers are caching the login page so hitting back loads the cached version instead of checking with the server. Here's how to fix both:
1. Add Login Status Check to login.php
First, we need to make sure that if a user is already logged in (has an active session), they get redirected straight to the dashboard instead of seeing the login form. Modify your login.php to include a session check at the top:
<?php session_start(); // Redirect logged-in users to dashboard immediately if (isset($_SESSION['emailaddress'])) { header("Location: registered/dashboard.php"); exit(); // Stop further execution to ensure redirect happens } ?> <!DOCTYPE html> <html> <head> <title>Bejelentkezés | LASOW Projekt</title> <link rel="stylesheet" href="css/login.css"> </head> <body> <?php include 'navbar.html'; ?> <div class="main"> <h1>Bejelentkezés</h1> <form action="loginer.php" method="POST"> <label for="">Email:</label><br> <input type="text" name="emailaddress"><br> <label for="Jelszó:">Jelszó:</label><br> <input type="password" name="password"><br> <input name="login" type="submit" value="Belépek"> </form> </div> </body> </html>
2. Disable Browser Caching for Protected Pages
Even with the server-side check, browsers often cache pages like login.php and dashboard.php to load them faster. This means hitting back might still show the cached login page without triggering the server check. Fix this by adding cache-control headers to both login.php and dashboard.php:
Updated login.php Header
<?php session_start(); // Disable browser caching entirely header("Cache-Control: no-cache, no-store, must-revalidate"); // HTTP 1.1 header("Pragma: no-cache"); // HTTP 1.0 header("Expires: 0"); // Expire immediately for proxies // Redirect logged-in users if (isset($_SESSION['emailaddress'])) { header("Location: registered/dashboard.php"); exit(); } ?>
Updated dashboard.php Header
<?php session_start(); // Disable caching here too to prevent back-button issues header("Cache-Control: no-cache, no-store, must-revalidate"); header("Pragma: no-cache"); header("Expires: 0"); // Redirect unauthenticated users if (!isset($_SESSION['emailaddress'])) { header("Location: ../logout.php"); exit(); } ?> <!DOCTYPE html> <html> <head> <style> h2 { text-align: center; } </style> </head> <body> <?php include 'menu.html'; ?> <h2>Üdv a LASOW rendszerében</h2> </body> </html>
Why This Works
- The session check in
login.phpensures that any user with an active session can't access the login form via direct navigation or back button (once the page is refreshed from the server). - The cache-control headers force the browser to fetch a fresh copy of the page from the server every time, so the session check runs every time the user tries to load
login.php—even via the back button.
Your earlier attempts with session_destroy() didn't work because that's for ending sessions, not preventing access to the login page while a session is active. These changes target the root causes of the issue.
内容的提问来源于stack exchange,提问作者Erik

