PHP页面权限控制:如何仅允许Admin用户访问指定页面
Hey there! Let's get this sorted out so only the user with the nickname "Admin" can access your page. I'll break this down into clear, actionable steps with code examples:
Step 1: Update Your Login Logic to Store the User's Nickname in Session
First, when a user logs in, you need to validate their credentials against your SQL database. If they're valid, store their nick in the session—this is what we'll use to check access later. Always use prepared statements to prevent SQL injection—this is critical for keeping your database secure.
Here's an example of a login handler script (login.php):
<?php session_start(); // Replace with your actual database credentials $dbHost = 'your_host'; $dbUser = 'your_db_user'; $dbPass = 'your_db_password'; $dbName = 'your_database_name'; // Using mysqli for database connection (PDO works too!) $conn = new mysqli($dbHost, $dbUser, $dbPass, $dbName); if ($conn->connect_error) { die("Connection failed: " . $conn->connect_error); } if ($_SERVER['REQUEST_METHOD'] === 'POST') { $email = $_POST['email']; $password = $_POST['password']; // Prepare SQL query to fetch user data safely $stmt = $conn->prepare("SELECT nick, password FROM users WHERE email = ?"); $stmt->bind_param("s", $email); $stmt->execute(); $stmt->store_result(); if ($stmt->num_rows === 1) { $stmt->bind_result($userNick, $hashedPassword); $stmt->fetch(); // Verify password (never store plain-text passwords! Use password_hash() when creating accounts) if (password_verify($password, $hashedPassword)) { // Store the user's nickname in the session $_SESSION['user_nick'] = $userNick; // Redirect to the restricted page header("Location: restricted_page.php"); exit(); } else { echo "Incorrect password!"; } } else { echo "No user found with that email address!"; } $stmt->close(); $conn->close(); } ?>
Critical reminder: Always store hashed passwords in your database (use
password_hash()when creating user accounts) instead of plain text. This keeps user data safe if your database is ever compromised.
Step 2: Update Your Restricted Page's Access Control
Now, modify your restricted page to check two things: whether the user is logged in, and whether their stored nickname is exactly "Admin". If either condition fails, deny access:
<?php session_start(); // Check if user is logged in AND their nickname is "Admin" if (!isset($_SESSION['user_nick']) || $_SESSION['user_nick'] !== "Admin") { echo "Only the Admin can access this page!"; // Optional: Redirect unauthorised users to the login page // header("Location: login.php"); // exit(); exit(); } ?> <head> <title>WWW</title> </head> <body> <header>Welcome Admin</header> <!-- Add your restricted page content here --> </body>
Key Additional Tips:
- Session Security: For better security, enable
session.cookie_secure = On(if you use HTTPS) andsession.cookie_httponly = Onin your PHP settings. This helps prevent session hijacking and XSS attacks. - User Experience: Instead of just echoing a message, redirect unauthorised users to a login page or a custom 403 Forbidden page for a smoother experience.
- Database Hygiene: Double-check that your
userstable has thenickfield, and that the admin account's nickname is exactly "Admin" (case-sensitive—adjust the check if you need case-insensitive matching).
内容的提问来源于stack exchange,提问作者Martin Švejda

