doubutao6216 2013-10-17 11:56
浏览 9
已采纳

为什么更好或更安全地检查用户是否登录

I'm wondering about how do you normally check user session if the user try to login.

I use these three ways: Considering that the userid is the userid from a database. So it should be greater than 0 if a user logged in.

 //With empty() function
if(empty($_SESSION['userid'])){
    echo 'you are not logged in';
}


// Check if userid session is zero
if($_SESSION['userid'] == '0'){
    echo 'you are not logged in';
}

// Check if userid is lower than 1
if($_SESSION['userid'] < '1'){
    echo 'you are not logged in';
}

Are these okay or do you prefer another way?

doesn't isset() function return true even userid is 0?

Thanks.

  • 写回答

4条回答 默认 最新

  • dpwgzi7987 2013-10-17 12:03
    关注

    The answer is: It doesn't matter. However, in terms of performance, you want this:

    if (isset($_SESSION['userid']))

    And you want to add protection to the session. Read https://www.owasp.org/index.php/Session_hijacking_attack

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(3条)

报告相同问题?

悬赏问题

  • ¥30 Unity接入微信SDK 无法开启摄像头
  • ¥20 有偿 写代码 要用特定的软件anaconda 里的jvpyter 用python3写
  • ¥20 cad图纸,chx-3六轴码垛机器人
  • ¥15 移动摄像头专网需要解vlan
  • ¥20 access多表提取相同字段数据并合并
  • ¥20 基于MSP430f5529的MPU6050驱动,求出欧拉角
  • ¥20 Java-Oj-桌布的计算
  • ¥15 powerbuilder中的datawindow数据整合到新的DataWindow
  • ¥20 有人知道这种图怎么画吗?
  • ¥15 pyqt6如何引用qrc文件加载里面的的资源