登录后获取用户完整信息及SESSION字段调用异常解决问询
Hey there! Let's sort this out quickly. The core issue here is that your login logic only saves the username to the session—you're not storing the firstname, lastname, or email values. Here are two simple approaches to get this working:
Option 1: Update Login Logic (Recommended)
This is the most efficient method because it stores all necessary user data in the session once during login, avoiding repeated database calls.
Step 1: Modify your login code
After verifying the user's credentials are correct, fetch their full record from the USERS table and save all required fields to the session. Here's an example using PDO (adjust to your database extension if needed):
// Assume you've already validated the username/password is correct $username = $_POST['username']; // Or the variable you use for the username // Fetch full user data from USERS table $stmt = $pdo->prepare("SELECT ID, USERNAME, FIRSTNAME, LASTNAME, EMAIL FROM USERS WHERE USERNAME = ?"); $stmt->execute([$username]); $user = $stmt->fetch(PDO::FETCH_ASSOC); // Save all user fields to session if ($user) { $_SESSION['user_id'] = $user['ID']; $_SESSION['username'] = $user['USERNAME']; $_SESSION['firstname'] = $user['FIRSTNAME']; $_SESSION['lastname'] = $user['LASTNAME']; $_SESSION['email'] = $user['EMAIL']; // Redirect to homepage or dashboard header("Location: index.php"); exit; }
Step 2: Update your homepage sidebar
Now you can directly access the session variables in your sidebar code, just like you do with username:
<!-- Sidebar User Info Section --> <div class="sidebar-profile"> <h3>Your Profile</h3> <p>Name: <?php echo htmlspecialchars($_SESSION['firstname'] . ' ' . $_SESSION['lastname']); ?></p> <p>Username: <?php echo htmlspecialchars($_SESSION['username']); ?></p> <p>Email: <?php echo htmlspecialchars($_SESSION['email']); ?></p> </div>
Option 2: Fetch Data Directly on Homepage (If You Can't Modify Login Logic)
If for some reason you can't update the login code, you can query the USERS table on the homepage using the stored username to get the missing fields. Note: This makes an extra database call on every page load, so it's less efficient than Option 1.
// At the top of your homepage (after session_start()) session_start(); $user = []; if (isset($_SESSION['username'])) { $stmt = $pdo->prepare("SELECT FIRSTNAME, LASTNAME, EMAIL FROM USERS WHERE USERNAME = ?"); $stmt->execute([$_SESSION['username']]); $user = $stmt->fetch(PDO::FETCH_ASSOC); }
Then use the $user array in your sidebar:
<div class="sidebar-profile"> <h3>Your Profile</h3> <p>Name: <?php echo htmlspecialchars($user['FIRSTNAME'] . ' ' . $user['LASTNAME']); ?></p> <p>Username: <?php echo htmlspecialchars($_SESSION['username']); ?></p> <p>Email: <?php echo htmlspecialchars($user['EMAIL']); ?></p> </div>
Important Notes
- Always use
session_start()at the very top of your PHP files, before any HTML output. - Use
htmlspecialchars()to prevent XSS attacks (you're already doing this forusername—great job!). - Use prepared statements (like the examples above) to avoid SQL injection vulnerabilities.
内容的提问来源于stack exchange,提问作者Je Boy Abi

