微信公众号搜"智元新知"关注
微信扫一扫可直接关注哦!

禁止使用JQuery AJAX 403

我创建了一个使用PHP和JQuery的登录页面.问题是,每次JQuery $.ajax尝试访问user_login.PHP文件时,我都会遇到403 Forbidden错误.

以下是我当前的代码

user_index.PHP

<!DOCTYPE html>
<html>
<head>
    <title>Foot Steps Philippines -- User Log-in</title>
    <link rel="icon" type="image/png" href="images/favicon.png">
    <link rel="stylesheet" type="text/css" href="styles/user_login_style.css">
    <script type="text/javascript" src="jquery.js"></script>
    <script type="text/javascript" src="user_login.js"></script>
</head>

<body>
<div class="login_wrapper">
    <h3>Log-In</h3>
    <form id="fsp_login_form" name="fsp_login_form" action="user_login.PHP" method="POST">
        <input type="email" name="fsp_email" id="fsp_email" placeholder="E-mail Address" />
        <input type="password" name="fsp_password" id="fsp_password" placeholder="Password" />
        <input type="submit" name="fsp_login" id="fsp_login" value="Log-In" />
        <h4 id="login_message"></h4>
    </form>
    <div class="links">
        <a href="">Forgot Password?</a>
    </div>
    <div class="note">*To register, please e-mail us at contact@footsteps.ph</div>
    <div class="footer"></div>
    <div class="logo"></div>
</div>
</body>
</html>

user_login.js

$(document).ready(function(){
    $("#fsp_login_form").submit(function(){
            $('#login_message').html("Please wait...");
            var action = $('#fsp_login_form').attr('action');
            var form_data = {
                fsp_email: $('#fsp_email').val(),
                fsp_password: $('#fsp_password').val(),
                is_ajax: 1
            };

            $.ajax({
                type: "POST",
                url: action,
                data: form_data,
                dataType: "text",
                contentType: "application/x-www-form-urlencoded; charset=UTF-8",
                success: function(response) {
                    if ( response == 'success' ) {
                        $('#login_message').html("Login successful!");
                        setTimeout(function(){ window.location.href = 'user_cpanel.PHP'; }, 2000);
                    }
                    else {
                        $('#login_message').html("Login Failed!");
                    }
                },
                error: function(err) {
                    //$('#login_message').html(err.responseText);
                    alert(err.responseText);
                }
            });
        return false;
    });
});

user_login.PHP

<?PHP
ob_start();
session_start();
include 'conn.PHP';

$is_ajax = $_REQUEST['is_ajax'];
$res = "";

if ( isset($is_ajax) && $is_ajax ) {
    $email_address = $_REQUEST['fsp_email'];
    $password = $_REQUEST['fsp_password'];

    // Protect to MysqL injection.
    $email_address = stripslashes($email_address);
    $email_address = MysqLi_real_escape_string($conn, $email_address);
    $password = stripslashes($password);
    $password = MysqLi_real_escape_string($conn, $password);

    $sql = "SELECT * FROM user_info WHERE email_address = '".$email_address."' AND password = '".$password."'";

    if ( $result = MysqLi_query($conn, $sql) ) {
        if ( MysqLi_num_rows($result) > 0 ) {
            $client_id = 0;
            $premium = 0;
            while ( $row = MysqLi_fetch_array($result) ) {
                $client_id = $row['id'];
                $premium = $row['premium_member'];
            }
            $_SESSION['client'] = $client_id;
            $_SESSION['premium'] = $premium;
            $res = "success";
        }
        else {
            $res = "Failed";
        }
        MysqLi_free_result($result);
    }
    else {
        $res = "Failed";
    }
}
else {
    $res = "Failed";
}
MysqLi_close($conn);
echo $res;
?>

conn.PHP
*注意:我故意使用了本地主机数据库配置.当我将其上传到网络托管服务器时,我已经对其进行了调整.

<?PHP
$conn = MysqLi_connect("localhost", "root", "", "footstep_db");

// Check connection.
if ( MysqLi_connect_errno() ) {
    echo "Failed to connect to MysqL: ".MysqLi_connect_error();
}
else {
    // nothing to do.
}
?>

所有文件都在同一目录中,并且都具有0644权限.
您对如何解决错误有任何想法吗?
顺便说一句,我的登录页面在localhost中运行时运行正常.但是使用我的网络托管服务器上传时,它不起作用.
我无权访问我的虚拟主机的PHP配置文件和Apache配置文件,因此请尽量不要提供需要重新配置PHP和Apache的解决方案.

谢谢 :-)

解决方法:

问题解决了!
我只是要求我的虚拟主机为我的域创建一个例外.
我认为他们服务器的mod_security设置会导致403禁止错误.

版权声明:本文内容由互联网用户自发贡献,该文观点与技术仅代表作者本人。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如发现本站有涉嫌侵权/违法违规的内容, 请发送邮件至 dio@foxmail.com 举报,一经查实,本站将立刻删除。

相关推荐