You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP页面权限控制:如何仅允许Admin用户访问指定页面

Solution to Restrict Access to Only the "Admin" Nickname User

Hey there! Let's get this sorted out so only the user with the nickname "Admin" can access your page. I'll break this down into clear, actionable steps with code examples:

Step 1: Update Your Login Logic to Store the User's Nickname in Session

First, when a user logs in, you need to validate their credentials against your SQL database. If they're valid, store their nick in the session—this is what we'll use to check access later. Always use prepared statements to prevent SQL injection—this is critical for keeping your database secure.

Here's an example of a login handler script (login.php):

<?php
session_start();
// Replace with your actual database credentials
$dbHost = 'your_host';
$dbUser = 'your_db_user';
$dbPass = 'your_db_password';
$dbName = 'your_database_name';

// Using mysqli for database connection (PDO works too!)
$conn = new mysqli($dbHost, $dbUser, $dbPass, $dbName);

if ($conn->connect_error) {
    die("Connection failed: " . $conn->connect_error);
}

if ($_SERVER['REQUEST_METHOD'] === 'POST') {
    $email = $_POST['email'];
    $password = $_POST['password'];

    // Prepare SQL query to fetch user data safely
    $stmt = $conn->prepare("SELECT nick, password FROM users WHERE email = ?");
    $stmt->bind_param("s", $email);
    $stmt->execute();
    $stmt->store_result();

    if ($stmt->num_rows === 1) {
        $stmt->bind_result($userNick, $hashedPassword);
        $stmt->fetch();

        // Verify password (never store plain-text passwords! Use password_hash() when creating accounts)
        if (password_verify($password, $hashedPassword)) {
            // Store the user's nickname in the session
            $_SESSION['user_nick'] = $userNick;
            // Redirect to the restricted page
            header("Location: restricted_page.php");
            exit();
        } else {
            echo "Incorrect password!";
        }
    } else {
        echo "No user found with that email address!";
    }

    $stmt->close();
    $conn->close();
}
?>

Critical reminder: Always store hashed passwords in your database (use password_hash() when creating user accounts) instead of plain text. This keeps user data safe if your database is ever compromised.

Step 2: Update Your Restricted Page's Access Control

Now, modify your restricted page to check two things: whether the user is logged in, and whether their stored nickname is exactly "Admin". If either condition fails, deny access:

<?php
session_start();

// Check if user is logged in AND their nickname is "Admin"
if (!isset($_SESSION['user_nick']) || $_SESSION['user_nick'] !== "Admin") {
    echo "Only the Admin can access this page!";
    // Optional: Redirect unauthorised users to the login page
    // header("Location: login.php");
    // exit();
    exit();
}
?>
<head>
    <title>WWW</title>
</head>
<body>
    <header>Welcome Admin</header>
    <!-- Add your restricted page content here -->
</body>

Key Additional Tips:

  • Session Security: For better security, enable session.cookie_secure = On (if you use HTTPS) and session.cookie_httponly = On in your PHP settings. This helps prevent session hijacking and XSS attacks.
  • User Experience: Instead of just echoing a message, redirect unauthorised users to a login page or a custom 403 Forbidden page for a smoother experience.
  • Database Hygiene: Double-check that your users table has the nick field, and that the admin account's nickname is exactly "Admin" (case-sensitive—adjust the check if you need case-insensitive matching).

内容的提问来源于stack exchange,提问作者Martin Švejda

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:15:49