Hi all
use this code
<?php
session_start();
unset($_SESSION['username']);
header('location:index.php');
?>
Hi all
use this code
<?php
session_start();
unset($_SESSION['username']);
header('location:index.php');
?>
Hi all
Use this code
//userhome.php
<!DOCTYPE html>
<html lang="en">
<?php
session_start();
echo 'Welcome '.$_SESSION['username'];
if(!isset($_SESSION['username']))
{
header('location:index.php');
}
?>
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>User Home</title>
<style>
body {
font-family: Arial, sans-serif;
background-color: #f4f4f4;
margin: 0;
padding: 0;
display: flex;
justify-content: center;
align-items: center;
height: 100vh;
}
.container {
text-align: center;
background-color: #fff;
padding: 30px;
border-radius: 8px;
box-shadow: 0 2px 10px rgba(0, 0, 0, 0.1);
}
h1 {
color: #333;
}
a {
display: inline-block;
margin: 10px;
padding: 10px 20px;
background-color: #007BFF;
color: #fff;
text-decoration: none;
border-radius: 4px;
transition: background-color 0.3s ease;
}
a:hover {
background-color: #0056b3;
}
</style>
</head>
<body>
<div class="container">
<h1>Welcome to User Home</h1>
<p>Please select an option:</p>
<a href="profile.php">Go to Profile</a>
<a href="settings.php">Go to Settings</a>
<a href="viewpatient.php">View Patients</a>
<a href="logout.php">Logout</a>
</div>
</body>
</html>
Hi all,
Use this code
<?php
$username = $_POST['username'];
$password = $_POST['password'];
$count1 = substr_count($username, "'");
$count2 = substr_count($password, "'");
$err = 0;
if ($count1 > 0 || $count2 > 0) {
$err = 1;
}
// Create connection using MySQLi
include('dbconnect.php');
if (!$con) {
die('Could not connect: ' . mysqli_connect_error());
}
// Use prepared statements to avoid SQL injection
$sql = "SELECT * FROM tbl_login WHERE lg_username = '$username' AND lg_password = '$password' AND lg_status = '1'";
echo $sql;
$result = mysqli_query($con, $sql);
$flag = 0;
$type = '';
while ($row = mysqli_fetch_assoc($result)) {
$flag = 1;
$type = $row['lg_type'];
session_start();
$_SESSION['user'] = $type; // store session data
$_SESSION['username'] = $username;
}
echo $flag;
echo $type;
if ($err > 0) {
echo "<script>location.href='index.php?msg=Invalid Username or Password'</script>";
} else if ($flag == 1 && $type == "admin") {
echo "<script>location.href='adminhome.php'</script>";
} else if ($flag == 1 && $type == "user") {
echo "<script>location.href='userhome.php'</script>";
} else if ($flag == 1 && $type == "faculty") {
echo "<script>location.href='facultyhome.php'</script>";
} else {
echo "<script>location.href='index.php?msg=Invalid Username or Password'</script>";
}
// Close the connection
mysqli_close($con);
?>
Hi all,
Use this code
...............................
<?php
include('dbconnect.php');
// Use prepared statements to avoid SQL injection
$query = "delete FROM tbl_patient where id='$_GET[id]'";
mysqli_query($con, $query);
header('location:viewdoctor.php');
?>
Hi all
Use this code
-----------------------
<?php
include('dbconnect.php');
// Use prepared statements to avoid SQL injection
$query = 'SELECT * FROM tbl_patient';
$result = mysqli_query($con, $query); // mysqli_query replaces mysql_query
if (!$result) {
$message = 'ERROR: ' . mysqli_error($con); // mysqli_error replaces mysql_error
echo $message;
return;
} else {
echo '
<html>
<head>
<style>
table {
width: 80%;
border-collapse: collapse;
margin: 50px auto;
font-family: Arial, sans-serif;
background-color: #f2f2f2;
}
th, td {
border: 1px solid #ddd;
padding: 12px;
text-align: center;
}
th {
background-color: #4CAF50;
color: white;
}
tr:nth-child(even) {
background-color: #f9f9f9;
}
tr:hover {
background-color: #d1e0e0;
}
a {
color: red;
text-decoration: none;
}
a:hover {
text-decoration: underline;
}
</style>
</head>
<body>
<table>
<tr>';
// Fetch field names dynamically and create table headers
$fields = mysqli_fetch_fields($result); // mysqli_fetch_fields replaces mysql_fetch_field
foreach ($fields as $field) {
echo '<th>' . ucfirst($field->name) . '</th>';
}
echo '<th>Delete</th></tr>';
// Fetch table rows
while ($row = mysqli_fetch_row($result)) { // mysqli_fetch_row replaces mysql_fetch_row
echo '<tr>';
$idval = $row[0]; // Assume the first column is the id
foreach ($row as $cell) {
echo '<td>' . htmlspecialchars($cell) . '</td>'; // Use htmlspecialchars to prevent XSS
}
echo '<td><a href="delpatient.php?id=' . $idval . '">Delete</a></td>';
echo '</tr>';
}
echo '</table>
</body>
</html>';
mysqli_free_result($result); // mysqli_free_result replaces mysql_free_result
}
mysqli_close($con); // mysqli_close replaces mysql_close
?>