A member-only page checks authenticated session state before displaying private content. Redirect unauthenticated visitors to login and escape member data before placing it in HTML.
session_start();
if (
!isset(
$_SESSION['mem_id'],
$_SESSION['userid']
)
) {
header(
'Location: mem-login.php'
);
exit;
}
This corrects the older malformed isset() example and makes the access rule explicit.
$safeUserid = htmlspecialchars(
(string)$_SESSION['userid'],
ENT_QUOTES,
'UTF-8'
);
echo 'Welcome ' . $safeUserid;
Keep only the server-side identity/state your application needs, such as a numeric member ID and user ID. Avoid displaying the raw session ID and avoid putting passwords, verification tokens or other secrets into the session.
Authentication answers “who is the user?”; authorization answers “may this user perform this action?”. Check authorization on every protected operation, not only when the user first logs in.
Use the logout flow to clear the session when the member signs out.
session_start();if (isset($_SESSION['userid']&& !empty($_SESSION['userid']))) {
// Welcome message
}else {
// Ask the user to login
}
Author & Instructor at plus2net
I write and maintain practical tutorials on Python, PHP, SQL, JavaScript, HTML, jQuery, and web development at plus2net. The tutorials focus on clear explanations, working examples, and code that readers can test and adapt while learning.