I would like to know:
1 - How to create two different middlewares (for ADMIN and STAFF) from SESSION variables to use them later to prevent users who are neither ADMIN nor STAFF from accessing pages I don't want that they have access ???
Here's what I did, but I'm completely unsure and stuck:
FUNCTION PROCESSING ACCESS FOR ADMIN MEMBERS:
function checkAdmin()
{
$_SESSION['hlbank_admin_user'] = array('name' => 'Admin');
// if the session id is not set, redirect to login page
if (!isset($_SESSION['hlbank_admin_user'])) {
header('Location: ' . WEB_ROOT . 'admin/login.php');
exit;
}
// the user want to logout
if (isset($_GET['logout'])) {
doLogout();
}
}
FUNCTION PROCESSING ACCESS FOR STAFF MEMBERS:
function checkStaff()
{
// if the session id is not set, redirect to login page
if(strlen($_SESSION['staff_id'])==0) {
$host = $_SERVER['HTTP_HOST'];
$uri = rtrim(dirname($_SERVER['PHP_SELF']), '/\\');
$extra= WEB_ROOT . "admin/pages_staff_index.php";
$_SESSION["staff_id"]="";
header("Location: http://$host$uri/$extra");
}
// the user want to logout
if (isset($_GET['logout'])) {
doLogout();
}
}
So please help me to correct my two functions above which aim to check via THE
SESSIONif the connected User is anADMINand aSTAFF.How to use both functions at the same time in a Page to check if the User is an ADMIN or a STAFF and thus block access to users who are neither
ADMINnorSTAFF???
Thank you please help me.