how to get query results to show only from logged in record?

I’ve got a working login, however I’m not sure how to restrict results on subsequent pages to the logged in record. For example, I have a record update page that pulls up the name and contact info of the organization member - it always pulls up the first record though because it’s not restricted to only the record that’s logged in.

Here’s my code for the login page:
[php]<?php require_once('[connection]'); ?>

<?php if (!function_exists("GetSQLValueString")) { function GetSQLValueString($theValue, $theType, $theDefinedValue = "", $theNotDefinedValue = "") { if (PHP_VERSION < 6) { $theValue = get_magic_quotes_gpc() ? stripslashes($theValue) : $theValue; } $theValue = function_exists("mysql_real_escape_string") ? mysql_real_escape_string($theValue) : mysql_escape_string($theValue); switch ($theType) { case "text": $theValue = ($theValue != "") ? "'" . $theValue . "'" : "NULL"; break; case "long": case "int": $theValue = ($theValue != "") ? intval($theValue) : "NULL"; break; case "double": $theValue = ($theValue != "") ? doubleval($theValue) : "NULL"; break; case "date": $theValue = ($theValue != "") ? "'" . $theValue . "'" : "NULL"; break; case "defined": $theValue = ($theValue != "") ? $theDefinedValue : $theNotDefinedValue; break; } return $theValue; } } ?> <?php // *** Validate request to login to this site. if (!isset($_SESSION)) { session_start(); } $loginFormAction = $_SERVER['PHP_SELF']; if (isset($_GET['accesscheck'])) { $_SESSION['PrevUrl'] = $_GET['accesscheck']; } if (isset($_POST['Username'])) { $loginUsername=$_POST['Username']; $password=$_POST['Password']; $MM_fldUserAuthorization = "Admin"; $MM_redirectLoginSuccess = "update_record.php"; $MM_redirectLoginFailed = "login_failed.php"; $MM_redirecttoReferrer = true; mysql_select_db($database_qchba, $qchba); $LoginRS__query=sprintf("SELECT loginID, Password, Admin FROM membership WHERE loginID=%s AND Password=%s", GetSQLValueString($loginUsername, "int"), GetSQLValueString($password, "text")); $LoginRS = mysql_query($LoginRS__query, $qchba) or die(mysql_error()); $loginFoundUser = mysql_num_rows($LoginRS); if ($loginFoundUser) { $loginStrGroup = mysql_result($LoginRS,0,'Admin'); if (PHP_VERSION >= 5.1) {session_regenerate_id(true);} else {session_regenerate_id();} //declare two session variables and assign them $_SESSION['MM_Username'] = $loginUsername; $_SESSION['MM_UserGroup'] = $loginStrGroup; if (isset($_SESSION['PrevUrl']) && true) { $MM_redirectLoginSuccess = $_SESSION['PrevUrl']; } header("Location: " . $MM_redirectLoginSuccess ); } else { header("Location: ". $MM_redirectLoginFailed ); } } ?>[/php]

Please help? I used to know how to do this using cfparam in ColdFusion but had to switch to PHP.

Thank you!

Is that what you are looking for ?

[php]
if($loginStrGroup == ‘ADMIN’){
if is a admin show this code

}else{

if not admin show this code maybe redirect to index
}
[/php]

Sponsor our Newsletter | Privacy Policy | Terms of Service