Succesful-secure-powerful Login System - tested on trap17 and works great

free web hosting
Open Discussion > CONTRIBUTE > The Internet > Website Discussion

Succesful-secure-powerful Login System - tested on trap17 and works great

illdevilinc
Okay,
Before i get started some of the things in this are very hard to understand and may require some time to setup.
Things you should know that gave me trouble when trying to make this work
1) The PHP code is very picky the code will not work if all the filenames are not lowercase
2) The code wil require editing in many of the file names so make sure to read the instructions i give for each!
3) The code requires that you know how to edit the mysql database through code activation( for trap17 servers i include a reference on how to do it.)
4) These codes are not optional if you want a login system you must use all codes!
5) In these codes cookies are used so you must warn your users that they must let cookies come from your site.

Ok well now lets get started in coding.

STEP 1[b]

1) copy this code into note pad
2) save this code as tables.sql

CODE
#
#  dbtables.sql
#
#  Simplifies the task of creating all the database tables
#  used by the login system.
#
#  Can be run from command prompt by typing:
#
#  mysql -u yourusername -D yourdatabasename < dbtables.sql
#
#  That's with dbtables.sql in the mysql bin directory, but
#  you can just include the path to dbtables.sql and that's
#  fine too.
#
#  Written by: Jpmaster77 a.k.a. The Grandmaster of C++ (GMC)
#  Last Updated: August 13, 2004
#

#
#  Table structure for users table
#
DROP TABLE IF EXISTS users;

CREATE TABLE users (
username varchar(30) primary key,
password varchar(32),
userid varchar(32),
userlevel tinyint(1) unsigned not null,
email varchar(50),
timestamp int(11) unsigned not null
);


#
#  Table structure for active users table
#
DROP TABLE IF EXISTS active_users;

CREATE TABLE active_users (
username varchar(30) primary key,
timestamp int(11) unsigned not null
);


#
#  Table structure for active guests table
#
DROP TABLE IF EXISTS active_guests;

CREATE TABLE active_guests (
ip varchar(15) primary key,
timestamp int(11) unsigned not null
);


#
#  Table structure for banned users table
#
DROP TABLE IF EXISTS banned_users;

CREATE TABLE banned_users (
username varchar(30) primary key,
timestamp int(11) unsigned not null
);

(for trap17 hosting users)
Ok now that the file is saved onto your computer log into your website cpanel (ex. yoursite.trap17.com/cpanel or yoursite.com/cpanel) go into mysql databases, create a new database through that or use an existing one if you want. Now on the same page create a login name and password for the database that you want ,set the permission to ALL, then click create. Now go into the bottom of the page and click the link that takes you to an online database editer. Select the database your using on the drop down box at the left. At the top find Query and click it. Now in the select file form click browse and find the file you created above and click ok. Then create the file (if it dosent do it automaticly). Then thats it your done with creating the tables now you may move onto PART 2!


PART 2

1)Okay well we are now getting into the look and edit part. The only part you HAVE to edit in this section is this part:
CODE
define("DB_SERVER", "localhost");
define("DB_USER", "your_name");
define("DB_PASS", "your_pass");
define("DB_NAME", "your_dbname");

Leave localhost as is if your on trap17 hosting
Your_name must be changed to the login name you created for the database you made.
Your_pass must be changed to the password you created for the database you made.
You_dbname must be changed to the name you gave to your database ***WARNING*** REFER TO YOUR MYSQL SERVER FOR YOUR NAME AS IT MAY HAVE MODIFIED THE NAME.
You may change other needs to your liking but im not going into detail with the advanced editing. And also when you edit this stuff make sure ALL the information is 100% CORRECT or you will not make a succesful login system.
2) When all information is modified to the way you like it then save it as constants.php
CODE

<?
/**
* Constants.php
*
* This file is intended to group all constants to
* make it easier for the site administrator to tweak
* the login script.
*
*/

/**
* Database Constants - these constants are required
* in order for there to be a successful connection
* to the MySQL database. Make sure the information is
* correct.
*/
define("DB_SERVER", "localhost");
define("DB_USER", "your_name");
define("DB_PASS", "your_pass");
define("DB_NAME", "your_dbname");

/**
* Database Table Constants - these constants
* hold the names of all the database tables used
* in the script.
*/
define("TBL_USERS", "users");
define("TBL_ACTIVE_USERS",  "active_users");
define("TBL_ACTIVE_GUESTS", "active_guests");
define("TBL_BANNED_USERS",  "banned_users");

/**
* Special Names and Level Constants - the admin
* page will only be accessible to the user with
* the admin name and also to those users at the
* admin user level. Feel free to change the names
* and level constants as you see fit, you may
* also add additional level specifications.
* Levels must be digits between 0-9.
*/
define("ADMIN_NAME", "admin");
define("GUEST_NAME", "Guest");
define("ADMIN_LEVEL", 9);
define("USER_LEVEL",  1);
define("GUEST_LEVEL", 0);

/**
* This boolean constant controls whether or
* not the script keeps track of active users
* and active guests who are visiting the site.
*/
define("TRACK_VISITORS", true);

/**
* Timeout Constants - these constants refer to
* the maximum amount of time (in minutes) after
* their last page fresh that a user and guest
* are still considered active visitors.
*/
define("USER_TIMEOUT", 10);
define("GUEST_TIMEOUT", 5);

/**
* Cookie Constants - these are the parameters
* to the setcookie function call, change them
* if necessary to fit your website. If you need
* help, visit www.php.net for more info.
* <http://www.php.net/manual/en/function.setcookie.php>
*/
define("COOKIE_EXPIRE", 60*60*24*100);  //100 days by default
define("COOKIE_PATH", "/");  //Available in whole domain

/**
* Email Constants - these specify what goes in
* the from field in the emails that the script
* sends to users, and whether to send a
* welcome email to newly registered users.
*/
define("EMAIL_FROM_NAME", "YourName");
define("EMAIL_FROM_ADDR", "youremail@address.com");
define("EMAIL_WELCOME", false);

/**
* This constant forces all users to have
* lowercase usernames, capital letters are
* converted automatically.
*/
define("ALL_LOWERCASE", false);
?>



STEP 3
1) Save this file as database.php
NO CHANGES IS NEEDED ON THIS FILE.

CODE
<?
/**
* Database.php
*
* The Database class is meant to simplify the task of accessing
* information from the website's database.
*

*/
include("constants.php");
      
class MySQLDB
{
   var $connection;         //The MySQL database connection
   var $num_active_users;   //Number of active users viewing site
   var $num_active_guests;  //Number of active guests viewing site
   var $num_members;        //Number of signed-up users
   /* Note: call getNumMembers() to access $num_members! */

   /* Class constructor */
   function MySQLDB(){
      /* Make connection to database */
      $this->connection = mysql_connect(DB_SERVER, DB_USER, DB_PASS) or die(mysql_error());
      mysql_select_db(DB_NAME, $this->connection) or die(mysql_error());
      
      /**
       * Only query database to find out number of members
       * when getNumMembers() is called for the first time,
       * until then, default value set.
       */
      $this->num_members = -1;
      
      if(TRACK_VISITORS){
         /* Calculate number of users at site */
         $this->calcNumActiveUsers();
      
         /* Calculate number of guests at site */
         $this->calcNumActiveGuests();
      }
   }

   /**
    * confirmUserPass - Checks whether or not the given
    * username is in the database, if so it checks if the
    * given password is the same password in the database
    * for that user. If the user doesn't exist or if the
    * passwords don't match up, it returns an error code
    * (1 or 2). On success it returns 0.
    */
   function confirmUserPass($username, $password){
      /* Add slashes if necessary (for query) */
      if(!get_magic_quotes_gpc()) {
          $username = addslashes($username);
      }

      /* Verify that user is in database */
      $q = "SELECT password FROM ".TBL_USERS." WHERE username = '$username'";
      $result = mysql_query($q, $this->connection);
      if(!$result || (mysql_numrows($result) < 1)){
         return 1; //Indicates username failure
      }

      /* Retrieve password from result, strip slashes */
      $dbarray = mysql_fetch_array($result);
      $dbarray['password'] = stripslashes($dbarray['password']);
      $password = stripslashes($password);

      /* Validate that password is correct */
      if($password == $dbarray['password']){
         return 0; //Success! Username and password confirmed
      }
      else{
         return 2; //Indicates password failure
      }
   }
  
   /**
    * confirmUserID - Checks whether or not the given
    * username is in the database, if so it checks if the
    * given userid is the same userid in the database
    * for that user. If the user doesn't exist or if the
    * userids don't match up, it returns an error code
    * (1 or 2). On success it returns 0.
    */
   function confirmUserID($username, $userid){
      /* Add slashes if necessary (for query) */
      if(!get_magic_quotes_gpc()) {
          $username = addslashes($username);
      }

      /* Verify that user is in database */
      $q = "SELECT userid FROM ".TBL_USERS." WHERE username = '$username'";
      $result = mysql_query($q, $this->connection);
      if(!$result || (mysql_numrows($result) < 1)){
         return 1; //Indicates username failure
      }

      /* Retrieve userid from result, strip slashes */
      $dbarray = mysql_fetch_array($result);
      $dbarray['userid'] = stripslashes($dbarray['userid']);
      $userid = stripslashes($userid);

      /* Validate that userid is correct */
      if($userid == $dbarray['userid']){
         return 0; //Success! Username and userid confirmed
      }
      else{
         return 2; //Indicates userid invalid
      }
   }
  
   /**
    * usernameTaken - Returns true if the username has
    * been taken by another user, false otherwise.
    */
   function usernameTaken($username){
      if(!get_magic_quotes_gpc()){
         $username = addslashes($username);
      }
      $q = "SELECT username FROM ".TBL_USERS." WHERE username = '$username'";
      $result = mysql_query($q, $this->connection);
      return (mysql_numrows($result) > 0);
   }
  
   /**
    * usernameBanned - Returns true if the username has
    * been banned by the administrator.
    */
   function usernameBanned($username){
      if(!get_magic_quotes_gpc()){
         $username = addslashes($username);
      }
      $q = "SELECT username FROM ".TBL_BANNED_USERS." WHERE username = '$username'";
      $result = mysql_query($q, $this->connection);
      return (mysql_numrows($result) > 0);
   }
  
   /**
    * addNewUser - Inserts the given (username, password, email)
    * info into the database. Appropriate user level is set.
    * Returns true on success, false otherwise.
    */
   function addNewUser($username, $password, $email){
      $time = time();
      /* If admin sign up, give admin user level */
      if(strcasecmp($username, ADMIN_NAME) == 0){
         $ulevel = ADMIN_LEVEL;
      }else{
         $ulevel = USER_LEVEL;
      }
      $q = "INSERT INTO ".TBL_USERS." VALUES ('$username', '$password', '0', $ulevel, '$email', $time)";
      return mysql_query($q, $this->connection);
   }
  
   /**
    * updateUserField - Updates a field, specified by the field
    * parameter, in the user's row of the database.
    */
   function updateUserField($username, $field, $value){
      $q = "UPDATE ".TBL_USERS." SET ".$field." = '$value' WHERE username = '$username'";
      return mysql_query($q, $this->connection);
   }
  
   /**
    * getUserInfo - Returns the result array from a mysql
    * query asking for all information stored regarding
    * the given username. If query fails, NULL is returned.
    */
   function getUserInfo($username){
      $q = "SELECT * FROM ".TBL_USERS." WHERE username = '$username'";
      $result = mysql_query($q, $this->connection);
      /* Error occurred, return given name by default */
      if(!$result || (mysql_numrows($result) < 1)){
         return NULL;
      }
      /* Return result array */
      $dbarray = mysql_fetch_array($result);
      return $dbarray;
   }
  
   /**
    * getNumMembers - Returns the number of signed-up users
    * of the website, banned members not included. The first
    * time the function is called on page load, the database
    * is queried, on subsequent calls, the stored result
    * is returned. This is to improve efficiency, effectively
    * not querying the database when no call is made.
    */
   function getNumMembers(){
      if($this->num_members < 0){
         $q = "SELECT * FROM ".TBL_USERS;
         $result = mysql_query($q, $this->connection);
         $this->num_members = mysql_numrows($result);
      }
      return $this->num_members;
   }
  
   /**
    * calcNumActiveUsers - Finds out how many active users
    * are viewing site and sets class variable accordingly.
    */
   function calcNumActiveUsers(){
      /* Calculate number of users at site */
      $q = "SELECT * FROM ".TBL_ACTIVE_USERS;
      $result = mysql_query($q, $this->connection);
      $this->num_active_users = mysql_numrows($result);
   }
  
   /**
    * calcNumActiveGuests - Finds out how many active guests
    * are viewing site and sets class variable accordingly.
    */
   function calcNumActiveGuests(){
      /* Calculate number of guests at site */
      $q = "SELECT * FROM ".TBL_ACTIVE_GUESTS;
      $result = mysql_query($q, $this->connection);
      $this->num_active_guests = mysql_numrows($result);
   }
  
   /**
    * addActiveUser - Updates username's last active timestamp
    * in the database, and also adds him to the table of
    * active users, or updates timestamp if already there.
    */
   function addActiveUser($username, $time){
      $q = "UPDATE ".TBL_USERS." SET timestamp = '$time' WHERE username = '$username'";
      mysql_query($q, $this->connection);
      
      if(!TRACK_VISITORS) return;
      $q = "REPLACE INTO ".TBL_ACTIVE_USERS." VALUES ('$username', '$time')";
      mysql_query($q, $this->connection);
      $this->calcNumActiveUsers();
   }
  
   /* addActiveGuest - Adds guest to active guests table */
   function addActiveGuest($ip, $time){
      if(!TRACK_VISITORS) return;
      $q = "REPLACE INTO ".TBL_ACTIVE_GUESTS." VALUES ('$ip', '$time')";
      mysql_query($q, $this->connection);
      $this->calcNumActiveGuests();
   }
  
   /* These functions are self explanatory, no need for comments */
  
   /* removeActiveUser */
   function removeActiveUser($username){
      if(!TRACK_VISITORS) return;
      $q = "DELETE FROM ".TBL_ACTIVE_USERS." WHERE username = '$username'";
      mysql_query($q, $this->connection);
      $this->calcNumActiveUsers();
   }
  
   /* removeActiveGuest */
   function removeActiveGuest($ip){
      if(!TRACK_VISITORS) return;
      $q = "DELETE FROM ".TBL_ACTIVE_GUESTS." WHERE ip = '$ip'";
      mysql_query($q, $this->connection);
      $this->calcNumActiveGuests();
   }
  
   /* removeInactiveUsers */
   function removeInactiveUsers(){
      if(!TRACK_VISITORS) return;
      $timeout = time()-USER_TIMEOUT*60;
      $q = "DELETE FROM ".TBL_ACTIVE_USERS." WHERE timestamp < $timeout";
      mysql_query($q, $this->connection);
      $this->calcNumActiveUsers();
   }

   /* removeInactiveGuests */
   function removeInactiveGuests(){
      if(!TRACK_VISITORS) return;
      $timeout = time()-GUEST_TIMEOUT*60;
      $q = "DELETE FROM ".TBL_ACTIVE_GUESTS." WHERE timestamp < $timeout";
      mysql_query($q, $this->connection);
      $this->calcNumActiveGuests();
   }
  
   /**
    * query - Performs the given query on the database and
    * returns the result, which may be false, true or a
    * resource identifier.
    */
   function query($query){
      return mysql_query($query, $this->connection);
   }
};

/* Create database connection */
$database = new MySQLDB;

?>




STEP 4
1) Save this file as session.php
NO CHANGES ARE REQUIRED TO THIS FILE

CODE
<?
/**
* Session.php
*
* The Session class is meant to simplify the task of keeping
* track of logged in users and also guests.
*
*/
include("database.php");
include("mailer.php");
include("form.php");

class Session
{
   var $username;     //Username given on sign-up
   var $userid;       //Random value generated on current login
   var $userlevel;    //The level to which the user pertains
   var $time;         //Time user was last active (page loaded)
   var $logged_in;    //True if user is logged in, false otherwise
   var $userinfo = array();  //The array holding all user info
   var $url;          //The page url current being viewed
   var $referrer;     //Last recorded site page viewed
   /**
    * Note: referrer should really only be considered the actual
    * page referrer in process.php, any other time it may be
    * inaccurate.
    */

   /* Class constructor */
   function Session(){
      $this->time = time();
      $this->startSession();
   }

   /**
    * startSession - Performs all the actions necessary to
    * initialize this session object. Tries to determine if the
    * the user has logged in already, and sets the variables
    * accordingly. Also takes advantage of this page load to
    * update the active visitors tables.
    */
   function startSession(){
      global $database;  //The database connection
      session_start();   //Tell PHP to start the session

      /* Determine if user is logged in */
      $this->logged_in = $this->checkLogin();

      /**
       * Set guest value to users not logged in, and update
       * active guests table accordingly.
       */
      if(!$this->logged_in){
         $this->username = $_SESSION['username'] = GUEST_NAME;
         $this->userlevel = GUEST_LEVEL;
         $database->addActiveGuest($_SERVER['REMOTE_ADDR'], $this->time);
      }
      /* Update users last active timestamp */
      else{
         $database->addActiveUser($this->username, $this->time);
      }
      
      /* Remove inactive visitors from database */
      $database->removeInactiveUsers();
      $database->removeInactiveGuests();
      
      /* Set referrer page */
      if(isset($_SESSION['url'])){
         $this->referrer = $_SESSION['url'];
      }else{
         $this->referrer = "/";
      }

      /* Set current url */
      $this->url = $_SESSION['url'] = $_SERVER['PHP_SELF'];
   }

   /**
    * checkLogin - Checks if the user has already previously
    * logged in, and a session with the user has already been
    * established. Also checks to see if user has been remembered.
    * If so, the database is queried to make sure of the user's
    * authenticity. Returns true if the user has logged in.
    */
   function checkLogin(){
      global $database;  //The database connection
      /* Check if user has been remembered */
      if(isset($_COOKIE['cookname']) && isset($_COOKIE['cookid'])){
         $this->username = $_SESSION['username'] = $_COOKIE['cookname'];
         $this->userid   = $_SESSION['userid']   = $_COOKIE['cookid'];
      }

      /* Username and userid have been set and not guest */
      if(isset($_SESSION['username']) && isset($_SESSION['userid']) &&
         $_SESSION['username'] != GUEST_NAME){
         /* Confirm that username and userid are valid */
         if($database->confirmUserID($_SESSION['username'], $_SESSION['userid']) != 0){
            /* Variables are incorrect, user not logged in */
            unset($_SESSION['username']);
            unset($_SESSION['userid']);
            return false;
         }

         /* User is logged in, set class variables */
         $this->userinfo  = $database->getUserInfo($_SESSION['username']);
         $this->username  = $this->userinfo['username'];
         $this->userid    = $this->userinfo['userid'];
         $this->userlevel = $this->userinfo['userlevel'];
         return true;
      }
      /* User not logged in */
      else{
         return false;
      }
   }

   /**
    * login - The user has submitted his username and password
    * through the login form, this function checks the authenticity
    * of that information in the database and creates the session.
    * Effectively logging in the user if all goes well.
    */
   function login($subuser, $subpass, $subremember){
      global $database, $form;  //The database and form object

      /* Username error checking */
      $field = "user";  //Use field name for username
      if(!$subuser || strlen($subuser = trim($subuser)) == 0){
         $form->setError($field, "* Username not entered");
      }
      else{
         /* Check if username is not alphanumeric */
         if(!eregi("^([0-9a-z])*$", $subuser)){
            $form->setError($field, "* Username not alphanumeric");
         }
      }

      /* Password error checking */
      $field = "pass";  //Use field name for password
      if(!$subpass){
         $form->setError($field, "* Password not entered");
      }
      
      /* Return if form errors exist */
      if($form->num_errors > 0){
         return false;
      }

      /* Checks that username is in database and password is correct */
      $subuser = stripslashes($subuser);
      $result = $database->confirmUserPass($subuser, md5($subpass));

      /* Check error codes */
      if($result == 1){
         $field = "user";
         $form->setError($field, "* Username not found");
      }
      else if($result == 2){
         $field = "pass";
         $form->setError($field, "* Invalid password");
      }
      
      /* Return if form errors exist */
      if($form->num_errors > 0){
         return false;
      }

      /* Username and password correct, register session variables */
      $this->userinfo  = $database->getUserInfo($subuser);
      $this->username  = $_SESSION['username'] = $this->userinfo['username'];
      $this->userid    = $_SESSION['userid']   = $this->generateRandID();
      $this->userlevel = $this->userinfo['userlevel'];
      
      /* Insert userid into database and update active users table */
      $database->updateUserField($this->username, "userid", $this->userid);
      $database->addActiveUser($this->username, $this->time);
      $database->removeActiveGuest($_SERVER['REMOTE_ADDR']);

      /**
       * This is the cool part: the user has requested that we remember that
       * he's logged in, so we set two cookies. One to hold his username,
       * and one to hold his random value userid. It expires by the time
       * specified in constants.php. Now, next time he comes to our site, we will
       * log him in automatically, but only if he didn't log out before he left.
       */
      if($subremember){
         setcookie("cookname", $this->username, time()+COOKIE_EXPIRE, COOKIE_PATH);
         setcookie("cookid",   $this->userid,   time()+COOKIE_EXPIRE, COOKIE_PATH);
      }

      /* Login completed successfully */
      return true;
   }

   /**
    * logout - Gets called when the user wants to be logged out of the
    * website. It deletes any cookies that were stored on the users
    * computer as a result of him wanting to be remembered, and also
    * unsets session variables and demotes his user level to guest.
    */
   function logout(){
      global $database;  //The database connection
      /**
       * Delete cookies - the time must be in the past,
       * so just negate what you added when creating the
       * cookie.
       */
      if(isset($_COOKIE['cookname']) && isset($_COOKIE['cookid'])){
         setcookie("cookname", "", time()-COOKIE_EXPIRE, COOKIE_PATH);
         setcookie("cookid",   "", time()-COOKIE_EXPIRE, COOKIE_PATH);
      }

      /* Unset PHP session variables */
      unset($_SESSION['username']);
      unset($_SESSION['userid']);

      /* Reflect fact that user has logged out */
      $this->logged_in = false;
      
      /**
       * Remove from active users table and add to
       * active guests tables.
       */
      $database->removeActiveUser($this->username);
      $database->addActiveGuest($_SERVER['REMOTE_ADDR'], $this->time);
      
      /* Set user level to guest */
      $this->username  = GUEST_NAME;
      $this->userlevel = GUEST_LEVEL;
   }

   /**
    * register - Gets called when the user has just submitted the
    * registration form. Determines if there were any errors with
    * the entry fields, if so, it records the errors and returns
    * 1. If no errors were found, it registers the new user and
    * returns 0. Returns 2 if registration failed.
    */
   function register($subuser, $subpass, $subemail){
      global $database, $form, $mailer;  //The database, form and mailer object
      
      /* Username error checking */
      $field = "user";  //Use field name for username
      if(!$subuser || strlen($subuser = trim($subuser)) == 0){
         $form->setError($field, "* Username not entered");
      }
      else{
         /* Spruce up username, check length */
         $subuser = stripslashes($subuser);
         if(strlen($subuser) < 5){
            $form->setError($field, "* Username below 5 characters");
         }
         else if(strlen($subuser) > 30){
            $form->setError($field, "* Username above 30 characters");
         }
         /* Check if username is not alphanumeric */
         else if(!eregi("^([0-9a-z])+$", $subuser)){
            $form->setError($field, "* Username not alphanumeric");
         }
         /* Check if username is reserved */
         else if(strcasecmp($subuser, GUEST_NAME) == 0){
            $form->setError($field, "* Username reserved word");
         }
         /* Check if username is already in use */
         else if($database->usernameTaken($subuser)){
            $form->setError($field, "* Username already in use");
         }
         /* Check if username is banned */
         else if($database->usernameBanned($subuser)){
            $form->setError($field, "* Username banned");
         }
      }

      /* Password error checking */
      $field = "pass";  //Use field name for password
      if(!$subpass){
         $form->setError($field, "* Password not entered");
      }
      else{
         /* Spruce up password and check length*/
         $subpass = stripslashes($subpass);
         if(strlen($subpass) < 4){
            $form->setError($field, "* Password too short");
         }
         /* Check if password is not alphanumeric */
         else if(!eregi("^([0-9a-z])+$", ($subpass = trim($subpass)))){
            $form->setError($field, "* Password not alphanumeric");
         }
         /**
          * Note: I trimmed the password only after I checked the length
          * because if you fill the password field up with spaces
          * it looks like a lot more characters than 4, so it looks
          * kind of stupid to report "password too short".
          */
      }
      
      /* Email error checking */
      $field = "email";  //Use field name for email
      if(!$subemail || strlen($subemail = trim($subemail)) == 0){
         $form->setError($field, "* Email not entered");
      }
      else{
         /* Check if valid email address */
         $regex = "^[_+a-z0-9-]+(\.[_+a-z0-9-]+)*"
                 ."@[a-z0-9-]+(\.[a-z0-9-]{1,})*"
                 ."\.([a-z]{2,}){1}$";
         if(!eregi($regex,$subemail)){
            $form->setError($field, "* Email invalid");
         }
         $subemail = stripslashes($subemail);
      }

      /* Errors exist, have user correct them */
      if($form->num_errors > 0){
         return 1;  //Errors with form
      }
      /* No errors, add the new account to the */
      else{
         if($database->addNewUser($subuser, md5($subpass), $subemail)){
            if(EMAIL_WELCOME){
               $mailer->sendWelcome($subuser,$subemail,$subpass);
            }
            return 0;  //New user added succesfully
         }else{
            return 2;  //Registration attempt failed
         }
      }
   }
  
   /**
    * editAccount - Attempts to edit the user's account information
    * including the password, which it first makes sure is correct
    * if entered, if so and the new password is in the right
    * format, the change is made. All other fields are changed
    * automatically.
    */
   function editAccount($subcurpass, $subnewpass, $subemail){
      global $database, $form;  //The database and form object
      /* New password entered */
      if($subnewpass){
         /* Current Password error checking */
         $field = "curpass";  //Use field name for current password
         if(!$subcurpass){
            $form->setError($field, "* Current Password not entered");
         }
         else{
            /* Check if password too short or is not alphanumeric */
            $subcurpass = stripslashes($subcurpass);
            if(strlen($subcurpass) < 4 ||
               !eregi("^([0-9a-z])+$", ($subcurpass = trim($subcurpass)))){
               $form->setError($field, "* Current Password incorrect");
            }
            /* Password entered is incorrect */
            if($database->confirmUserPass($this->username,md5($subcurpass)) != 0){
               $form->setError($field, "* Current Password incorrect");
            }
         }
        
         /* New Password error checking */
         $field = "newpass";  //Use field name for new password
         /* Spruce up password and check length*/
         $subpass = stripslashes($subnewpass);
         if(strlen($subnewpass) < 4){
            $form->setError($field, "* New Password too short");
         }
         /* Check if password is not alphanumeric */
         else if(!eregi("^([0-9a-z])+$", ($subnewpass = trim($subnewpass)))){
            $form->setError($field, "* New Password not alphanumeric");
         }
      }
      /* Change password attempted */
      else if($subcurpass){
         /* New Password error reporting */
         $field = "newpass";  //Use field name for new password
         $form->setError($field, "* New Password not entered");
      }
      
      /* Email error checking */
      $field = "email";  //Use field name for email
      if($subemail && strlen($subemail = trim($subemail)) > 0){
         /* Check if valid email address */
         $regex = "^[_+a-z0-9-]+(\.[_+a-z0-9-]+)*"
                 ."@[a-z0-9-]+(\.[a-z0-9-]{1,})*"
                 ."\.([a-z]{2,}){1}$";
         if(!eregi($regex,$subemail)){
            $form->setError($field, "* Email invalid");
         }
         $subemail = stripslashes($subemail);
      }
      
      /* Errors exist, have user correct them */
      if($form->num_errors > 0){
         return false;  //Errors with form
      }
      
      /* Update password since there were no errors */
      if($subcurpass && $subnewpass){
         $database->updateUserField($this->username,"password",md5($subnewpass));
      }
      
      /* Change Email */
      if($subemail){
         $database->updateUserField($this->username,"email",$subemail);
      }
      
      /* Success! */
      return true;
   }
  
   /**
    * isAdmin - Returns true if currently logged in user is
    * an administrator, false otherwise.
    */
   function isAdmin(){
      return ($this->userlevel == ADMIN_LEVEL ||
              $this->username  == ADMIN_NAME);
   }
  
   /**
    * generateRandID - Generates a string made up of randomized
    * letters (lower and upper case) and digits and returns
    * the md5 hash of it to be used as a userid.
    */
   function generateRandID(){
      return md5($this->generateRandStr(16));
   }
  
   /**
    * generateRandStr - Generates a string made up of randomized
    * letters (lower and upper case) and digits, the length
    * is a specified parameter.
    */
   function generateRandStr($length){
      $randstr = "";
      for($i=0; $i<$length; $i++){
         $randnum = mt_rand(0,61);
         if($randnum < 10){
            $randstr .= chr($randnum+48);
         }else if($randnum < 36){
 

 

 

 


Reply

jlhaslip
Just noticed that the 4th Part code listing ends with an open-ended ElseIf statement. So the code will fail as it exists.
Perhaps the Author could remedy this flaw in the listing by including the Part Four (and the balance of the Script) as an additional posting???
Also, this code looks to be written by someone other than the posting Member, with no credit given to the original author except the line inside the code field.
QUOTE
Written by: Jpmaster77 a.k.a. The Grandmaster of C++ (GMC)
#  Last Updated: August 13, 2004


Plagarism??

Here is a link to the Original article. http://evolt.org/article/rating/17/60384/index.html
When you read the article, notice that this Log-in Script is intended for Intermediate to Advanced PHP coders.

THIS IS NOT A BEGINNER'S SCRIPT. Attempting to include this Script in a website would not be reccomended unless you are knowledgable about PHP and scripting in general. Be forewarned.

 

 

 


Reply



Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

(Maximum characters: 10,000)
You have characters left.

Recent Queries:-
  1. jpmaster77 dropdown - 476.91 hr back. (1)
  2. login succesful - 765.93 hr back. (1)
Similar Topics

Keywords : succesful secure login tested trap17 works

  1. How Do I Get My Domain To Point To Ns1.trap17.com - moving from Microsoft Office Live (1)
  2. What Website Do You Find Your Always Goin Back To? - and not trap17 lol (77)
    hey wanted to know what type of site you guys like and wot are the sites you always find your self
    lookin at and checkin for updates. and dont put trap17 /tongue.gif' border='0'
    style='vertical-align:middle' alt='tongue.gif' /> i no its great and that put this topic is about
    other sites /laugh.gif' border='0' style='vertical-align:middle' alt='laugh.gif' /> cheers lil
    chris...
  3. [ih] Login Needed - (0)
    Hey everyone! I am Currently running a Website (No Host yet, getting my Post's Up to get one
    on Trap17 ^^) Yes if you Guessed 'is it a Habbo Fansite?' yes it is x] Right now I am
    looking for someone with REALLY good skill with creating a login with some great features. If
    someone could help out, It would mean alot to us!...
  4. Image Board Software With Password. - Image Board with user login. (4)
    Now- not that I'm naming any boards in particular (FOURCHAN) but the "Futallaby" image board
    software really appealed to me. One problem- you have to be Anonymous (Or root admin). What I'm
    looking for is the same basic structure (Start a topic with an image) but with a user system in
    place. I've had a look around but the demand for anonymous only boards is too great. Help me
    Trap17!...
  5. How Do I Secure My Download Page? - (4)
    I am considering selling websites. I plan on useing paypal and after people pay for a template or
    site i want an email to be sent to them with a link to a download. i want the link to deactivate so
    that they cant use it anymore. i dont really know how or if i can do that. also i want to secure
    that download page by only alowing the person who made the payment to access the page. i think that
    can be done buy ip address tracking or something like that. the only way i can think of doing this
    is using php and mysql and im not even sure if i can do that because im still new t...
  6. What Is Logic Of Trap17 - (8)
    There'r many websites like trap17 which offer free hosting but require you to post on forums..
    just curious, what is logic behind this ? they get money from ads what they have put on forums...
    but, is it good enough that they are in this business ??? dont tell me that they are paying by their
    pockets /biggrin.gif" style="vertical-align:middle" emoid=":D" border="0" alt="biggrin.gif" />...
  7. Web Page Working Except On Internet Explorer - Site works on everything but IE (4)
    OK well i have been really taking my time on getting my site to have no errors or warnings. I have
    also tried to make it much more professional then my last ( http://ojproductions.net )cI have
    gotten to have NO errors or warnings on both of my page and CSS document. It even works on Netscape,
    Firefox, and Opera, but not IE. Can someone tell me why http://beta.ojproductions.net does not
    work on IE?...
  8. Take Over My Website - http://www.metalmusic.trap17.com (3)
    hi everyone, I am looking for someone to take over my website IDI Metal Music. I am still wishing
    to own the site but i just want someone to manage the site. I am willing to give full controls over
    to the person who wants to take over the site and i will also keep up all the posting required to
    keep the site running for no cost. The person who takes over the site must know what he/she is
    doing and must listen to Metal or Rock. I will also still provide the video space (up to 10 gigs)
    for the site at no cost. The videos will be hosted on my paid web host. I will giv...
  9. Free Image Hosting - Exclusive To Trap17 Members - for now at least.... (0)
    Hi, I just introduced free image hosting and thought I'd make it available exclusively to the
    members of Trap17 (you are the only people to know about it... for now at least /tongue.gif"
    style="vertical-align:middle" emoid=":P" border="0" alt="tongue.gif" />) The site is:
    http://www.indoxyldesigns.com/freeimages2 You can host images for free. The size restriction is
    125KB (I will increase this upon request), and the allowed file types are GIF, JPG, PNG, BMP, SWF,
    PDF, ZIP (yea.. even zip files) So tell me what you think of the template i just put together for ...
  10. Trap17 Flashback - trap17 in past few years (5)
    Well, the T17 birthday was celebrated and i found this page on net. you can see how T17 was looking
    in the begining... /smile.gif" style="vertical-align:middle" emoid=":)" border="0" alt="smile.gif"
    /> Trap17 flashback ...
  11. Hmm Better Site Than Trap17? (for Phpnuke Users) - uh oh i think i found a better site lol check it out urself (6)
    freephpnuke.org hmm i wus just looking for some phpnuke shoutboxes and i found this site that
    allows you to make a free account with phpnuke....and it even came with the shoutbox ive been
    wanting...and you dont have to do nething to try to keep your server up unlike trap17 =P...well for
    you phpnuke users i think this site is for you.. i find it to be really kool to be able to just have
    a free nuke site just lke that....and plus you dont have to set it up....they set it up for you
    isntantly...peace pls try this site out n tell me what you think p.s. even thou i found t...
  12. Experiences Of Building My Trap17 Website - Maybe you can learn from other's experiences (8)
    1) Application form for free hosting account didn't work, it just sent me to post a new topic.
    So I posted I wanted an account, and had no form, so it was denied. Ended up trying the next
    morning, same thing happened, no form, so I did what somebody else did, and just copied the info
    from another post, and filled it in. Application approved. 2) I had over 100 credits, and asked
    for a 10 credit account, so I wouldn't use extra resources until my site was ready to open for
    business, as it were. Skipped coming into forum for one day (doing backups, pc maintenance,...
  13. Gabbly Web Integrated Chat - Very Cool.. Look at the sample on Trap17 (4)
    I've found out this chat script, free, from a friend's web page. It's really cool based
    on AJAX technology. The chat window simply floats on top of your site and it's draggable and
    resizeable. I only can say, wow, when I see this real cool service. Unfortunately, it still does
    not have support for Opera browser. Trap17.com sample
    http://www.gabbly.com/www.trap17.com/forums/ ...
  14. Blogspot To Trap17 - how to do? (3)
    i have a blog on blogger and want to import it to a website here on trap17, be it wordpress or any
    cms (joomla i'd like) what should i do, i'm not much of a web designer but i don't like
    blogger and i quite neglected updating it so i'd like it in a more customizable format....
  15. Login Script Problem - (0)
    i have created a login script that enables my costomours to login into there cPanel,web mail and if
    there a reseller WHM. But when i test the script on the webserver its dosnt work on some pages, on
    the pages that dont work i get this error message QUOTE Method Not Allowed The requested method
    POST is not allowed for the URL /index.htm. Apache/1.3.34 Server at www.mxweb.co.uk Port 80 and
    i know its nothing to do with the frontpage server extentions, and what gets me is that it works on
    some pages but not others. Ive tried everything in my knowlage to get it worki...
  16. Blogs? - How many trap17 members are bloggers? (0)
    So, do you use blogs and if you do which ones? How many? I myself hated that (and I still do a bit)
    but have started my blog today acctualy. I'll use it to send a message to the world
    /biggrin.gif' border='0' style='vertical-align:middle' alt='biggrin.gif' /> ...
  17. Trap17 Problem - (2)
    Ok Im Having A Problem To Visit This Sites Forum. After I Press Post In Some Topics It Times Out For
    Me. What Is THe Prioblem?...
  18. No Jsp Support? - Than why did I register @ trap17 (5)
    Hi all.. I just received my trap17 hosting account which I registered because I read that it
    supported java and JSP .. But this http://www.vitrus.trap17.com/ makes me think it does
    not......
  19. Comparing Trap17? - What Trap17 reminds me of. (8)
    When I came across this hosting site, it suddenly reminded me of Inuration dot net, the hosting site
    that shut down a few years ago. They had the same system, IT points by posting on their forum and
    such... They shut down because of something that happened to them. Are there more sites like this
    one and Inuration? Plus, does anyone remember or know Inuration?...
  20. Mambo In Trap17 - (1)
    Good afternoon, There is some problem, with free Web hosting, to install Mambo. At this moment
    I have installed a Web in host.sk and it does not support Mambo suitably. With 20 Mb, I have
    sufficient to install Mambo basic? Thank you very much to all....
  21. Need Hhlp With My Trap17 Hosting! - (4)
    Hi. Ive made a fodler called Videos on my acount and iv uploaded a video called Fre3 cat. I cannot
    link this to my webpge at all! what would the URL be for this video? Cheers, Karl...
  22. Looking For Free Hosting Service (other Than Trap17) - Are there any free hosting with a cpanel and good features? (6)
    Does anyone know where I can find a free hosting service with no ads (or maybe popups only) and lets
    me use a Cpanel? Here's what I need: 100+ web space 1GB+ transfer unlimited email unlimited
    subdomains phpbb forum Thanks....
  23. Tweaking Fire Fox To Make It Faster. - This works. (7)
    Do the following to tweak Fire Fox to make it go faster. Type about:config in the URL bar. Now,
    find network.dns.disableIPv6 in the index. Double click it to make it true. Now for these
    modifications: network.http.max-connections : Double click and type 30
    network.http.max-connections-per-server : Double click and type 12
    network.http.pipelining.maxrequests : Double click and type 32 network.http.request.max-start-delay
    : Double click and type 0 network.http.pipelining : Double click to make it true. Finally, right
    click anywhere and make a new integer. Call it...
  24. New Real Phpbb Forum Started With My Trap17 Accoun - clan Finaldark (2)
    Before i might of mentioned a forum that was used with a crappy myfreebb site, but now we got the
    real thing. i am going to get a domain name very very soon so please wait! PLEASE JOIN MY CLAN
    ahha go to WWW.FINALDARK.UNI.CC It will be awsome. i am so glad trap17 helped be set up that stuff,
    especially with the database etc etc! anyway thx to all and please join my clan. When you
    register at the forums, please use your gamertag as your name! I am hoping this will be Trap17s
    halo 2 clan! Admins if you want to make a section that would be awsome, but i wou...
  25. Http://boards.gamefaqsexploits.trap17.com/index.ph - (2)
    This is a cool place ...



Looking for succesful, secure, powerful, login, system, tested, trap17, works, great

*RANDOM STUFF*





*SIMILAR VIDEOS*
Searching Video's for succesful, secure, powerful, login, system, tested, trap17, works, great

*MORE FROM TRAP17.COM*
advertisement



Succesful-secure-powerful Login System - tested on trap17 and works great



 

 

 

 

ADD REPLY / Got an Opinion! a humble request :-) RAPID SEARCH! Free Hosting [X]
Express your Opinions, Thoughts or Contribute your information that might help someone here.
Ask your Doubts & Queries to get answers.. "Together, We enlight each other!"
Register FREE for AD-FREE forum, Create your own topics, Ask Questions, track topics, setup subscriptions & notifications and Get a Free Website w/ Email and FTP.
500MB Space *No Ads*, CPanel, FTP, PHP, MySQL, EMails - 100% FREE