PDA

View Full Version : Private Message


Tiger
09-26-2015, 07:01 PM
Hi, I've created private message system on dreamwaver / php, I'm just wondering weather there is a way to stop users from accessing other private messages?

I'm doing this buy URL Paramaters, So For Example, Site.com/Message.php?TOID=34993

If you change the numbers you can access other messages, Is there a way to stop this? I can't find much info! thanks

edbr
09-26-2015, 11:52 PM
Do you have a membership system on your site.im guessing yes but just asking. That will use sessions and you can restrict access to messages through those

Tiger
09-27-2015, 07:55 PM
Do you have a membership system on your site.im guessing yes but just asking. That will use sessions and you can restrict access to messages through those

Yes i do, but how would i go around restricting access? as the members table and pm table is set, So MM_Username Session wouldn't stop another user from reading another users messages as the only way i could display messages would be URL paramaters via ID?=233 ect...

edbr
09-28-2015, 02:26 AM
sorry i didnt answer well, i was on my phone and i get a bit short wityh replies.
i wouldnt use $_get to retrieve messages.
beter to put in database and rtrieve by $_post based on correct criteria of membership (session) and matching value of members id and messages sent to that member in a message table joined in a message table linked by members uniqhe ID and mathching that ID in a sent to field