ASP登录/登出会话记录转PHP求助:sessionid与logintime存储疑问
Hey there! As a PHP beginner, it’s totally normal to hit a snag when translating code from another language like ASP to PHP. Let’s walk through exactly what you need to fill in for sessionid and logintime in your INSERT INTO statement, plus cover the full login/logout flow to make this work smoothly.
1. Clarifying the Required Field Values
First, let’s break down what each field should contain:
- sessionid: PHP assigns every user a unique session ID when a session starts. You can grab this ID with the
session_id()function — just make sure you callsession_start()at the very top of your script (before any HTML or output, otherwise it’ll throw an error). - logintime: You have two reliable options here:
- Use PHP’s
date()function to generate a timestamp that matches MySQL’s datetime format:date('Y-m-d H:i:s') - Let MySQL handle the timestamp directly with its built-in
NOW()function (this uses the database server’s time, which is often simpler)
- Use PHP’s
2. Example Login Insert Code
Assuming you’ve already validated the user’s credentials and pulled their userid from your users table, here’s how to expand your existing code to insert the login record:
<?php // Start the session FIRST — this is critical! session_start(); if(isset($_POST['submit'])) { include 'dbheader.php'; // Sanitize input (though prepared statements are safer — more on that later) $username = mysqli_real_escape_string($conn, $_POST['uname']); $password = mysqli_real_escape_string($conn, $_POST['pword']); // First, validate the user's credentials (example query) // Note: Always use password_hash()/password_verify() for real password checks! $user_check = "SELECT userid FROM users WHERE username = '$username' AND password = '$password'"; $user_result = mysqli_query($conn, $user_check); if(mysqli_num_rows($user_result) === 1) { $user = mysqli_fetch_assoc($user_result); $userid = $user['userid']; // Get session ID and login time $session_id = session_id(); $login_time = date('Y-m-d H:i:s'); // Or skip this and use NOW() in SQL // Insert login record into userlogtime // Option 1: Using PHP-generated timestamp $insert_query = "INSERT INTO userlogtime (userid, sessionid, logintime, offline) VALUES ('$userid', '$session_id', '$login_time', 0)"; // Option 2: Using MySQL's NOW() (no need for $login_time variable) // $insert_query = "INSERT INTO userlogtime (userid, sessionid, logintime, offline) VALUES ('$userid', '$session_id', NOW(), 0)"; if(mysqli_query($conn, $insert_query)) { // Login successful — redirect to dashboard header("Location: dashboard.php"); exit(); } else { echo "Error logging login time: " . mysqli_error($conn); } } else { echo "Invalid username or password"; } } ?>
3. Handling Logout (Updating Logout Time)
When the user logs out, you’ll need to update their existing record in userlogtime to set logouttime and mark offline as 1. Here’s how to implement that:
<?php session_start(); if(isset($_GET['logout'])) { include 'dbheader.php'; $session_id = session_id(); $logout_time = date('Y-m-d H:i:s'); // Update the logout time and offline status $update_query = "UPDATE userlogtime SET logouttime = '$logout_time', offline = 1 WHERE sessionid = '$session_id' AND offline = 0"; if(mysqli_query($conn, $update_query)) { // Destroy the session and redirect to login page session_destroy(); header("Location: login.php"); exit(); } else { echo "Error logging logout time: " . mysqli_error($conn); } } ?>
Key Security & Best Practices
- Use Prepared Statements: Instead of
mysqli_real_escape_string(), use prepared statements to avoid SQL injection. Here’s a quick example of the insert query with prepared statements:$insert_query = "INSERT INTO userlogtime (userid, sessionid, logintime, offline) VALUES (?, ?, NOW(), 0)"; $stmt = mysqli_prepare($conn, $insert_query); mysqli_stmt_bind_param($stmt, "is", $userid, $session_id); mysqli_stmt_execute($stmt); - Password Security: Never store plain-text passwords! Use
password_hash()when creating user accounts andpassword_verify()when checking login credentials. - Session Security: After a successful login, call
session_regenerate_id(true)to regenerate the session ID — this helps prevent session hijacking.
内容的提问来源于stack exchange,提问作者user9246796

