tags:

views:

67

answers:

5

Hello. How do i do if i want to keep the username in the field if the users entered incorrect password, so the person doesnt need to retype the username? Should i use sessions for this?

+2  A: 

Just pass the value to the field:

<input name="uid" value="<?php echo (isset($_POST['uid'])) ? $_POST['uid'] : ''?>" />

Never forget to sanitize user input first! (not like in my example but it should give you the right idea).

But be careful with error messages. Don't say that the password is wrong. Say that the password or username is wrong. You don't want to let anyone know that a certain username is register in your system (at least not by trying to login).

Felix Kling
thank you, great idea. what did you mean with "sanitize user input first" ?
Karem
why do you use a ternary operator when it is shorter to write an if statement? I used to use them loads for this type of thing but it clicked one day that I actually write more code if I do.
Luke
@Luke: In this case, the difference are 6 characters... I can live with that ;) I just don't like to use control structures this way, when I mix HTML and PHP. Using the ternary operator, it feels more like one statement.@Karem: It should not contain e.g. script code or broken HTML (or at least escape this stuff, so that it is not interpreted by the browser). The username should be safe to be printed again.
Felix Kling
@Karem You **MUST** run $_POST['uid'] through htmlentities() before sending it back to the user, or you risk XSS vulnerabilites.
fahadsadah
@fahadsadah: Correct me if I'm wrong, but if the user himself as entered the text, then he would only launch a XSS attack on himself, wouldn't he? I am not saying that escaping the user input is not necessary, it is! I am just asking if not escaping the *POST* parameters could be used for a successful XSS attack against *someone else*.
Felix Kling
Luke
If you don't use htmlentities(), I could send someone to your site through a form on my site with a script in $_POST['uid'] that would grab the username and password they type in.
Scott Saunders
@fahadsadah @Scott Saunders How do i run it through htmlentities in the special php code without if statements that Felix kling have posted?
Karem
@Karem <input name="uid" value="<?php echo (isset($_POST['uid'])) ? htmlentities($_POST['uid'],ENT_QUOTES,'utf-8') : ''?>" />
Luke
@felix I can send a user to your site with a POSTed username containing a <script> tag that sends me cookies, and redirects the user back
fahadsadah
@Scott Saunders: Ah I see. Good point. I am just too concentrated on GET requests and sometimes I forget that one can easily build a form himself and redirect to such a page...
Felix Kling
A: 

Yes if you are not posting to the same page but to a php handeling script you would need to use a session variable like $_SESSION['sticky']['username'] = $_POST['username'], then on the page that you return to

<input type="text" value="<?php if isset($_SESSION['sticky']['username']) echo $_SESSION['sticky']['username'] ?>" name="username" />
Luke
-1 no validation
fahadsadah
What do you mean no validation? im not storing the data anywhere and the original poster didnt ask for validation only how to get the username back. Do you have any validation sujestions that I should have performed?
Luke
Oh, sorry, didn't notice $_SESSION. Please can you edit so I can retract my vote?
fahadsadah
A: 

Make sure $_POST['username'] data is not harmful first.

<input name="username" type="text" value="<?php echo $_POST['username'] ?>" />
Johan Olsson
type would be text, text box is <textbox></textbox>
Luke
A: 

try this one

use the session variable

  $_SESSION['username'] = $_POST['username'];


<input type="text" name="username" value="<?php echo $_SESSION['username']; ?>" />
This would generate an error if $_SESSION['username'] is not set which would be the case for the initial visit to the site/session timeout
Luke
A: 

Just print it:

<input name="username" type="text" value="<?php echo htmlspecialchars($_POST['username']) ?>">
Álvaro G. Vicario