有些事情困扰了我一段时间,我正在学习使用oop-php、ajax和使用pdo的bootstrap来创建一个登录系统。
到目前为止,我已经得到了登录和注册部分的权利。用户在表单中输入信息,然后提交给auth.php,auth.php通过一个类似下面的ajax文件在user.php中运行其各自的方法
$(function(){
$('.form').on('submit', function(e){
e.preventDefault();
$form = $(this);
submitForm($form);
});
});
function submitForm($form){
$footer = $form.parent('.modal-body').next('.modal-footer');
$footer.html('<img src="images/ajax-loader.gif">');
$.ajax({
url: $form.attr('action'),
method: $form.attr('method'),
data : $form.serialize(),
success : function( response ){
response = $.parseJSON( response );
if(response.success){
if(!response.signout){
$footer.html( response.message );
setTimeout(function(){
$footer.html( response.message );
window.location = response.url;
}, 1500
);
}
else if(response.signout == 2){
$footer.html( response.message );
setTimeout(function() {
$('#signup').modal('hide');
$('#login').modal('show');
}, 2000
);
}
else if(response.signout == 3){
$footer.html( response.idid );
}
}
else if(response.error){
$footer.html( response.message );
}
console.log(response);
}
})
}
在登录的情况下,ajax将信息提交给auth.php,auth.php在user.php中运行方法并登录用户
auth.php如下所示:
<?php
require_once 'includes/init.php';
$status = $user->login($_POST, $db);
if($status === 'success'){
echo json_encode([
'success' => 'success',
'message'=> '<p class="alert alert-success">Authenticated successfully</p>',
'url' => 'profile.php',
]);
}
else if($status === 'successAdmin'){
echo json_encode([
'success' => 'success',
'message'=> '<p class="alert alert-info">Welcome Admin</p>',
'url' => 'profileAdmin.php',
]);
}
else if($status === 'missing_fields'){
echo json_encode([
'error' => 'error',
'message'=> '<p class="alert alert-danger">All fields are mandatory</p>',
]);
}
else if($status === 'email_dosent_exist'){
echo json_encode([
'error' => 'error',
'message'=> '<p class="alert alert-danger">The e-mail/phone number address you provided does not exist. Please create an account first.</p>',
]);
}
else if($status === 'error'){
echo json_encode([
'error' => 'error',
'message'=> '<p class="alert alert-danger">Incorrect e-mail/phone number or password</p>',
]);
}
然后在user.php中运行一个方法并设置会话变量
public function login($user, $db){
if(empty($user['emailPhone']) OR empty($user['password'])){
return 'missing_fields';
}
else if(!$this->emailExists($user['emailPhone'],$db) AND !$this->phoneExists($user['emailPhone'],$db)){
return 'email_dosent_exist';
}
else{
$sql = "SELECT * FROM `users` WHERE `email`=? OR `phone_number`=?" ;
$statement = $db->prepare($sql);
if( is_object($statement) ){
$statement->bindParam(1, $user['emailPhone'], PDO::PARAM_STR);
$statement->bindParam(2, $user['emailPhone'], PDO::PARAM_STR);
$statement->execute();
if($row = $statement->fetch(PDO::FETCH_OBJ)){
if(password_verify($user['password'], $row->password)){
if ( $row->is_admin == 'admin') {
$_SESSION['logged_in'] = [
'id' => $row->id,
'name' => $row->name,
'c1' => $row->course1,
'conf1' => $row->paid1,
'c2' => $row->course2,
'conf2' => $row->paid2,
'c3' => $row->course3,
'conf3' => $row->paid3,
'c4' => $row->course4,
'conf4' => $row->paid4,
'c5' => $row->course5,
'conf5' => $row->paid5,
'isBossMan' => $row->is_admin,
];
return 'successAdmin';
}
$_SESSION['logged_in'] = [
'id' => $row->id,
'name' => $row->name,
'c1' => $row->course1,
'conf1' => $row->paid1,
'c2' => $row->course2,
'conf2' => $row->paid2,
'c3' => $row->course3,
'conf3' => $row->paid3,
'c4' => $row->course4,
'conf4' => $row->paid4,
'c5' => $row->course5,
'conf5' => $row->paid5,
];
return 'success';
}
}
}
}
return 'error';
}
但是我使用了太多的会话变量。这是个好习惯吗?
我还需要帮助在profile.php中显示数据,而不使用会话变量。我想在user.php中运行一个sql语句,从表中选择所有当前用户的数据,并在profile.php页面中显示为一个表?
到目前为止我得到的是
public function displayInfo($user, $db){
$sql = "SELECT `name`, `email`,`institute_name`, `country_code`, `phone_number`, FROM `users` WHERE `email`=? OR `phone_number`=?" ;
$statement = $db->prepare($sql);
if( is_object($statement) ){
$statement->bindParam(1, $user['adminFetch'], PDO::PARAM_STR);
$statement->bindParam(2, $user['adminFetch'], PDO::PARAM_STR);
$statement->execute();
if($row = $statement->fetch(PDO::FETCH_OBJ)){
if (!empty($_SESSION['logged_in']['isBossMan'])) {
return 'success';
echo json_encode($row);
}
}
}
}
我该怎么办?我知道row变量有我想要显示的必要信息,但是如何在profile.php页面上显示这些信息呢?我是否需要编写另一个ajax代码来进行显示,或者可以使用同一个代码来进行显示?
到目前为止,我取得了一些进展:profile.php页面上有一个字段,用户在其中输入任何人的电子邮件,然后按下按钮从数据库获取该用户的信息从表中获取用户信息,并在profile.php上的div中显示我为其编写的新获取ajax代码:
function fetchForm($fetch){
$fetchFooter = $fetch.parent('.modal-body').next('.modal-fetchFooter');
$fetchFooter.html('<img src="images/ajax-loader.gif">');
$fetchBody = $fetchFooter.next();
$.ajax({
url: $fetch.attr('action'),
method: $fetch.attr('method'),
data : $fetch.serialize(),
success : function( data ){
data = $.parseJSON( data );
$fetchFooter.html(data);
if(data.error){
$fetchFooter.html(data.message);
}
else{
$fetchFooter.html(data);
}
}
})
}
它将它发送到fetch.php文件,该文件包含以下代码,并在user.php中运行一个方法来检索信息
<?php
require_once 'includes/init.php';
$status = $user->displayInfo($_POST, $db);
if( $status === 'missing_fields'){
echo json_encode([
'error'=> 'error',
'message'=> '<p class="alert alert-danger">Please enter a e-mail address or phone number to fetch data.</p>',
]);
}
php的方法如下
public function displayInfo($user, $db){
if(empty($user['adminFetch'])){
return 'missing_fields';
}
else if(!$this->emailExists($user['adminFetch'],$db) AND !$this->phoneExists($user['adminFetch'],$db)){
return 'emailphone_dosent_exist';
}
else{
$sql = "SELECT `name`, `email`,`institute_name`, `country_code`, `phone_number` FROM `users` WHERE `email`=? OR `phone_number`=?" ;
$statement = $db->prepare($sql);
if( is_object($statement) ){
$statement->bindParam(1, $user['adminFetch'], PDO::PARAM_STR);
$statement->bindParam(2, $user['adminFetch'], PDO::PARAM_STR);
$statement->execute();
if($row = $statement->fetch(PDO::FETCH_ASSOC)){
if (!empty($_SESSION['logged_in']['isBossMan'])) {
echo json_encode($row);
}
}
}
}
return 'missing_fields';
}
如果您不输入任何内容并按下按钮,它工作正常。div被错误代码替换。
但当用户键入正确的现有电子邮件或电话号码时,方法和fetch.php将返回2个json对象。一个有用户信息,另一个有错误状态。
我做错了什么,我如何使它只返回1个json与信息在真的情况下或错误json在假的情况下?
1条答案
按热度按时间snvhrwxg1#
解决了的。我所要做的就是在user.php中返回$row,并在fetch.php中对$status进行编码
然后ajax就可以很好地显示错误和数据了!