You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP登录/登出会话记录转PHP求助:sessionid与logintime存储疑问

How to Track User Login/Logout Times in PHP

Hey there! As a PHP beginner, it’s totally normal to hit a snag when translating code from another language like ASP to PHP. Let’s walk through exactly what you need to fill in for sessionid and logintime in your INSERT INTO statement, plus cover the full login/logout flow to make this work smoothly.

1. Clarifying the Required Field Values

First, let’s break down what each field should contain:

  • sessionid: PHP assigns every user a unique session ID when a session starts. You can grab this ID with the session_id() function — just make sure you call session_start() at the very top of your script (before any HTML or output, otherwise it’ll throw an error).
  • logintime: You have two reliable options here:
    • Use PHP’s date() function to generate a timestamp that matches MySQL’s datetime format: date('Y-m-d H:i:s')
    • Let MySQL handle the timestamp directly with its built-in NOW() function (this uses the database server’s time, which is often simpler)

2. Example Login Insert Code

Assuming you’ve already validated the user’s credentials and pulled their userid from your users table, here’s how to expand your existing code to insert the login record:

<?php
// Start the session FIRST — this is critical!
session_start();

if(isset($_POST['submit'])) {
    include 'dbheader.php';
    
    // Sanitize input (though prepared statements are safer — more on that later)
    $username = mysqli_real_escape_string($conn, $_POST['uname']);
    $password = mysqli_real_escape_string($conn, $_POST['pword']);
    
    // First, validate the user's credentials (example query)
    // Note: Always use password_hash()/password_verify() for real password checks!
    $user_check = "SELECT userid FROM users WHERE username = '$username' AND password = '$password'";
    $user_result = mysqli_query($conn, $user_check);
    
    if(mysqli_num_rows($user_result) === 1) {
        $user = mysqli_fetch_assoc($user_result);
        $userid = $user['userid'];
        
        // Get session ID and login time
        $session_id = session_id();
        $login_time = date('Y-m-d H:i:s'); // Or skip this and use NOW() in SQL
        
        // Insert login record into userlogtime
        // Option 1: Using PHP-generated timestamp
        $insert_query = "INSERT INTO userlogtime (userid, sessionid, logintime, offline) VALUES ('$userid', '$session_id', '$login_time', 0)";
        
        // Option 2: Using MySQL's NOW() (no need for $login_time variable)
        // $insert_query = "INSERT INTO userlogtime (userid, sessionid, logintime, offline) VALUES ('$userid', '$session_id', NOW(), 0)";
        
        if(mysqli_query($conn, $insert_query)) {
            // Login successful — redirect to dashboard
            header("Location: dashboard.php");
            exit();
        } else {
            echo "Error logging login time: " . mysqli_error($conn);
        }
    } else {
        echo "Invalid username or password";
    }
}
?>

3. Handling Logout (Updating Logout Time)

When the user logs out, you’ll need to update their existing record in userlogtime to set logouttime and mark offline as 1. Here’s how to implement that:

<?php
session_start();

if(isset($_GET['logout'])) {
    include 'dbheader.php';
    
    $session_id = session_id();
    $logout_time = date('Y-m-d H:i:s');
    
    // Update the logout time and offline status
    $update_query = "UPDATE userlogtime SET logouttime = '$logout_time', offline = 1 WHERE sessionid = '$session_id' AND offline = 0";
    
    if(mysqli_query($conn, $update_query)) {
        // Destroy the session and redirect to login page
        session_destroy();
        header("Location: login.php");
        exit();
    } else {
        echo "Error logging logout time: " . mysqli_error($conn);
    }
}
?>

Key Security & Best Practices

  • Use Prepared Statements: Instead of mysqli_real_escape_string(), use prepared statements to avoid SQL injection. Here’s a quick example of the insert query with prepared statements:
    $insert_query = "INSERT INTO userlogtime (userid, sessionid, logintime, offline) VALUES (?, ?, NOW(), 0)";
    $stmt = mysqli_prepare($conn, $insert_query);
    mysqli_stmt_bind_param($stmt, "is", $userid, $session_id);
    mysqli_stmt_execute($stmt);
    
  • Password Security: Never store plain-text passwords! Use password_hash() when creating user accounts and password_verify() when checking login credentials.
  • Session Security: After a successful login, call session_regenerate_id(true) to regenerate the session ID — this helps prevent session hijacking.

内容的提问来源于stack exchange,提问作者user9246796

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 10:33:34