Ok well in dologin.php (~process.php), I sessioned. now in acccount.php i cannot echo them:
doLogin.php
PHP Code:
<?php
session_start();
include("dbsettings.php");
mysql_connect("$host", "$username", "$password")or die("cannot connect");
mysql_select_db("$db_name")or die("cannot select DB");
$username = mysql_real_escape_string($_POST['username']);
$password = md5(mysql_real_escape_string($_POST['password']));
$sql="SELECT * FROM `user` WHERE `username`='{$username}' AND `password`='{$password}'";
$result=mysql_query($sql);
// do the check
if($result)
{
if(mysql_num_rows($result) == 1)
{
$_SESSION['username'] = $username;
$_SESSION['password'] = $password;
$_SESSION['firstname'] = $firstname;
$_SESSION['lastname'] = $lastname;
$_SESSION['account'] = $account;
header("location: account.php");
exit();
}
else
{
echo "Wrong username/password.";
}
}
else
{
echo "The query is not true.";
}
?>
account.php
PHP Code:
<?php session_start(); ?>
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
<title>Account Dashboard</title>
</head>
<body>
<?php
include('dbsettings.php');
$con = mysql_connect("$host","$user","$password");
if (!$con)
{
die('Could not connect: ' . mysql_error());
}
mysql_select_db("$db_name", $con);
$username= $_SESSION['username']; // Editted
$sql="SELECT * FROM `user` WHERE `username`='{$username}'";
$result = mysql_query("$sql");
while($row = mysql_fetch_array($result))
{
echo "Welcome, ";
// echo $row['firstname'] . " " . $row['lastname'];
echo"$username";
echo "<br />";
echo"$firstname";
echo "<br />";
echo"$lastname";
echo "<br />";
echo"$account";
echo "<br />";
echo"$username";
echo "<br />";
}
mysql_close($con);
?>
<a href="logout.php"> Log Out </a>
</body>
</html>