Skip to main content
GameDev.net gamedev.net
🔒 Locked 🤖 Godot

[web] PHP Global Variable

Started by Haptic May 9, 2009 at 5:48 AM 7 replies 2.1k views
Original Post
Haptic
Haptic
Hey everybody. I'm dabbling in web-game creation for the first time. I've been able to figure most stuff out but this, I can't. I have a file, 'main.php' which displays many links designed to run a PHP function. They do this by sending variables in the link, ie 'www..../main.php?screen=1'. Now this is a two part question, Firstly, because I reload the PHP file everytime a link is clicked, I don't want to define the global variable at the beginning, I just want to DECLARE it so that it retains whatever value it had before the reload. Make sense? I've tried 'global $variable;' and strange things like '$variable = $variable;'. I want it to know the variable exists, without resetting its value. Secondly, would it reset the variable anyway when I reload the file. Thankyou very much, help is greatly appreciated.
Haptic
Hodgman
Hodgman
Quote:
Original post by Haptic
Firstly, because I reload the PHP file everytime a link is clicked, I don't want to define the global variable at the beginning, I just want to DECLARE it so that it retains whatever value it had before the reload. Make sense?

Secondly, would it reset the variable anyway when I reload the file.
When you load a PHP page, it's like starting a new program from scratch - when the page is finished loading, the program quits.
It doesn't make sense for globals to stick around after a program quits -- what if two people are visiting the page, do they both share the same global?

Fortunately, PHP does provide a solution for you though!
PHP has the concept of a "session", where each user of your site is given a unique ID in a cookie. When they load your page, this cookie is used to store data on the disk associated with that particular user - so every time that user loads any page on your site, all of the "session variables" (similar to "global variables") still exist with their old values.

http://au.php.net/manual/en/features.sessions.php
http://www.w3schools.com/PHP/php_sessions.asp


If you want to store data that isn't specific to a particular user, then you will have to read/write it from/to a file or database.
Haptic
Haptic
Thankyou for the reply Hodgman!

I had heard of sessions, but also heard that they have some security loopholes, and that 'plugging these holes' is usually beyond a beginner's capabilities.

I will definitely read up some more and try them out though.

I do have a quick question, based on the links you supplied.

It seems that the actual data is stored on the server, and that the cookie simply supplies the index to this data. Sounds good. What, though, is to stop somebody altering the cookie to index somebody else's data?

Thanks again,
Haptic
Hodgman
Hodgman
Quote:
Original post by Haptic
What, though, is to stop somebody altering the cookie to index somebody else's data?
That's a hole for you to plug ;)

The cookie is just a 'key'/'index'. To make this safe, you have to implement:
Authentication - so you know *who* is giving you the key.
Authorisation - so you know if that user is allowed to use that key.

A very simple approach is to just store the users IP address in the session (on the server). If the IP of the request doesn't match the one stored in the session, then you know that they're stealing someone elses session (or they have a dynamic IP address...)
Haptic
Haptic
Thanks again buddy, you've been a big help.

Much appreciated,
Haptic
silent_hill_webdev
silent_hill_webdev
Just a note: Storing the user's IP on the session to check if the session's ID was stolen has a drawback. Some ISP's change your IP at any time without letting you know about that. In this case, if your IP changes while you're logged on the site, your session would be lost, even if you're a legitimate user.

A better approach is to store the user agent of the user and check that to validate his session.

Sorry for my poor english.

Cheers.
ID Merlin
ID Merlin
The approach that vBulletin uses is to store a special hash in the cookie, and verify that against the logged-in user. I don't recall what it is a hash of, but it adds a level of security, preventing session hijacking. You can probably find an explanation of that technique using google.
Sander
Sander
Quote:
Original post by silent_hill_webdev
Just a note: Storing the user's IP on the session to check if the session's ID was stolen has a drawback. Some ISP's change your IP at any time without letting you know about that. In this case, if your IP changes while you're logged on the site, your session would be lost, even if you're a legitimate user.


That's easy to fix. Just use the first three octets of the IP address instead of the entire IP address.

Haptic
Haptic
Sorry, I haven't checked the post in a few days.

Thankyou for all of the extra feedback, you've given me a lot to read about!

Cheers,
Haptic

Topic Locked

This topic has been locked by a moderator. New replies are not allowed.

Sign in to reply to this topic.