« Project home page
my little forum
Log in
Register
Search:
Back to the entry by Micha
Post reply
Reply to the message by
Micha
Name:
E-mail:
(optional, won't be displayed directly)
Leave this field empty:
Homepage:
(optional)
Leave this field empty:
Location:
(optional)
Remember me (cookie)
Category:
General
Project organisation
Technics
Design/Themes
Features
Development
Todo
Bugs
German / Deutsch
Spanish / Español
French / Français
Accessibility/UX
Subject:
Formatting help
skip to input
format text bold
[b]bold text[/b]
format text italic
[i]italic text[/i]
insert hyperlink
[link=http://example.com/]link text[/link] / [link]http://example.com/[/link]
set text color
[color=#rgb]colored text[/color]
font size
[size=small]small text[/size]
[size=large]large text[/size]
insert list
[list][*]list item[/list]
insert image
[img]http://example.com/image.jpg[/img]
left: [img=left]http://example.com/image.jpg[/img]
right: [img=right]http://example.com/image.jpg[/img]
thumbnail: [img=thumbnail]http://example.com/image.jpg[/img]
thumbnail left: [img=thumbnail-left]http://example.com/image.jpg[/img]
thumbnail right: [img=thumbnail-right]http://example.com/image.jpg[/img]
upload image
upload image ...
insert TeX code
[tex]TeX code[/tex]
insert code
[inlinecode]code[/inlinecode]
[code]code[/code]
[code=css]code[/code]
[code=html]code[/code]
[code=javascript]code[/code]
[code=perl]code[/code]
[code=php]code[/code]
[code=sql]code[/code]
[code=xml]code[/code]
:-)
;-)
:-P
:-D
:-|
:-(
:yes:
:no:
:ok:
:lol:
:lol2:
:lol3:
:cool:
:surprised:
:angry:
:crying:
:waving:
:confused:
:lookaround:
:clap:
:love:
:tick:
Message:
> Hello, > > the [link=https://github.com/ilosuna/mylittleforum/blob/master/includes/login.inc.php#L49]SQL statement[/link] selects the users by the names - see [inlinecode]where[/inlinecode]-condition at the end of this statement: > > [code=sql]SELECT user_id, user_name, user_pw, user_type, > UNIX_TIMESTAMP(last_login) AS last_login, > UNIX_TIMESTAMP(last_logout) AS last_logout, > thread_order, user_view, sidebar, fold_threads, > thread_display, category_selection, auto_login_code, > activate_code, language, time_zone, time_difference, > theme, tou_accepted, dps_accepted > FROM ".$db_settings['userdata_table']." > > WHERE > lower(user_name) = '". mysqli_real_escape_string($connid, my_strtolower($request_username, $lang['charset'])) ."'") [/code] > > Maybe(!), it is possible to add a further condition to the email field [inlinecode]user_email[/inlinecode], i.e., > > [code=sql]WHERE > lower(user_name) = '". mysqli_real_escape_string($connid, my_strtolower($request_username, $lang['charset'])) ."'") > OR > lower(user_email) = '". mysqli_real_escape_string($connid, my_strtolower($request_username, $lang['charset'])) ."'") [/code] > > [b]Please note:[/b] There is a negative side effect (security issue). Currently, the email filed is [i]NOT[/i] a unique field. Different users can have identical mail addresses. This is critical, because the email-password combination is not bijective. > > /Micha
E-mail notification on reply of this posting
OK - Submit
Preview