I have been having some problem getting the header() to initialize with this code. It seems that the if statement doesn't work with query variables?
In init.php the function $user_data is defined. $url is the $_GET code in the url-bar of the browser (in this case a 6 digit random code). The variables seem to work, since I tried to output them already. The problem seems to be the if statement though. I do not get an error message. The header() just does not initiate, even though I am not logged in and the url is set to public === 0 in MySQL. Where am I going wrong?
include 'core/init.php';
include 'includes/head.php';
$url = $_SERVER['QUERY_STRING'];
$url = sanitize($url);
$public_arr = mysql_query("SELECT `public` FROM `uploads` WHERE `url` = '$url' AND `active` = 1") or die(mysql_error());
$public_arr = mysql_fetch_assoc($public_arr);
$public = $public_arr['public'];
$owner_arr = mysql_query("SELECT `owner` FROM `uploads` WHERE `url` = '$url' AND `active` = 1") or die(mysql_error());
$owner_arr = mysql_fetch_assoc($owner_arr);
$owner = $owner_arr['owner'];
global $user_data;
if ($public === 0 AND $owner !== $user_data['username'] || logged_in() === false) {
header('Location: mainpage.php');
exit();
}
$name_arr = mysql_query("SELECT `name` FROM `uploads` WHERE `url` = '$url' AND `active` = 1") or die(mysql_error());
$name_arr = mysql_fetch_assoc($name_arr);
$name = $name_arr['name'];
if ($public === 0 AND $owner !== $user_data['username'] || logged_in() === false)failed you, and/or you're outputting before header.if ($public === 0 AND ($owner !== $user_data['username'] || logged_in() === false)) {orif (($public === 0 AND $owner !== $user_data['username']) || logged_in() === false) {, depending on what you're after. You should clarify in the code, to avoid issues, on how you want the||parameter to behave. Can you also edit your question to clarify what values$publicand$ownerhave? Also, usedie('this works');to check this clause is being caught. (sorry for the long comment!).mysql_*functions. These extensions have been removed in PHP 7. Learn about prepared statements for PDO and MySQLi and consider using PDO, it's really pretty easy.