登录后如何通过cus_login.php按邮箱/ID在其他页面展示客户信息?
Alright, let's break down how to make this work step by step—since you're already using cus_login.php with the action defined at the top, we'll build on that foundation. The core idea is to use PHP Sessions to store a unique user identifier (like their ID or email) after successful login, then fetch and display their data on other pages using that identifier.
Step 1: Update cus_login.php to Handle Login & Store Session Data
First, we need to add login validation logic at the top of cus_login.php (before the HTML form, since your action points to this file). Here's how to do it:
<?php // Start the session first—this must be called before any output session_start(); // Check if the form was submitted if ($_SERVER['REQUEST_METHOD'] === 'POST') { // Get user input (sanitize to prevent XSS) $user_identifier = filter_input(INPUT_POST, 'user_identifier', FILTER_SANITIZE_EMAIL) ?? filter_input(INPUT_POST, 'user_identifier', FILTER_SANITIZE_STRING); $password = $_POST['password']; // Connect to your database (replace with your DB credentials) $db = new mysqli('localhost', 'username', 'password', 'your_database'); if ($db->connect_error) { die("Database connection failed: " . $db->connect_error); } // Prepare a query to fetch user data (use prepared statement to prevent SQL injection) $stmt = $db->prepare("SELECT id, email, full_name, password_hash FROM customers WHERE email = ? OR id = ?"); $stmt->bind_param("ss", $user_identifier, $user_identifier); $stmt->execute(); $result = $stmt->get_result(); $user = $result->fetch_assoc(); // Verify password (always use password_hash() when storing passwords, never plain text!) if ($user && password_verify($password, $user['password_hash'])) { // Login successful: store user ID in session (use ID instead of email for better security) $_SESSION['user_id'] = $user['id']; // Redirect to profile page (replace with your actual profile URL) header("Location: profile.php"); exit(); } else { $error = "Invalid email/ID or password"; } // Clean up $stmt->close(); $db->close(); } ?> <!-- Your existing login form goes here --> <form action="cus_login.php" method="POST"> <input type="text" name="user_identifier" placeholder="Enter your email or ID" required> <input type="password" name="password" placeholder="Enter your password" required> <button type="submit">Login</button> <?php if (isset($error)) echo "<p style='color: red;'>$error</p>"; ?> </form>
Step 2: Create/Update the Profile Page (e.g., profile.php)
Now, on any page where you want to display user data, start the session, check if the user is logged in, then fetch their data using the stored user_id:
<?php session_start(); // Check if user is logged in if (!isset($_SESSION['user_id'])) { // Redirect to login if not authenticated header("Location: cus_login.php"); exit(); } // Connect to database $db = new mysqli('localhost', 'username', 'password', 'your_database'); if ($db->connect_error) { die("Database connection failed: " . $db->connect_error); } // Fetch user data using the session's user_id $stmt = $db->prepare("SELECT id, email, full_name, phone, address FROM customers WHERE id = ?"); $stmt->bind_param("i", $_SESSION['user_id']); $stmt->execute(); $result = $stmt->get_result(); $user = $result->fetch_assoc(); $stmt->close(); $db->close(); ?> <!DOCTYPE html> <html> <head> <title>Your Profile</title> </head> <body> <h1>Welcome, <?php echo htmlspecialchars($user['full_name']); ?>!</h1> <div class="profile-details"> <p><strong>User ID:</strong> <?php echo htmlspecialchars($user['id']); ?></p> <p><strong>Email:</strong> <?php echo htmlspecialchars($user['email']); ?></p> <p><strong>Phone:</strong> <?php echo htmlspecialchars($user['phone']); ?></p> <p><strong>Address:</strong> <?php echo htmlspecialchars($user['address']); ?></p> </div> <a href="logout.php">Logout</a> </body> </html>
Step 3: Add Logout Functionality (Optional but Recommended)
Create a logout.php file to destroy the session when the user logs out:
<?php session_start(); session_unset(); // Remove all session variables session_destroy(); // Destroy the session header("Location: cus_login.php"); exit(); ?>
Key Security Notes
- Never store plain text passwords: Always use
password_hash()when creating user accounts, andpassword_verify()to check credentials (as shown in the login code). - Use prepared statements: This prevents SQL injection attacks—never concatenate user input directly into SQL queries.
- Sanitize output: Use
htmlspecialchars()when displaying user data to prevent cross-site scripting (XSS) attacks. - Secure your sessions: Configure PHP session settings (like
session.cookie_httponly,session.cookie_secure) to reduce session hijacking risks.
内容的提问来源于stack exchange,提问作者pamacama

