Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To add a button that follows the browser’s Back action, have PHP render a button that calls JavaScript’s history.back(). If a PHP form handler already knows where the user should go next, use a server-side redirect instead. PHP can generate the page or send a redirect response, but it cannot directly change the browser’s history.

Add a browser Back button to a PHP page

Put this HTML in the page your PHP script outputs:

<button type="button" onclick="history.back()">Back</button>

The button runs in the visitor’s browser, where the History API can move back one session-history entry. MDN documents that history.back() has the same effect as history.go(-1). It does nothing if there is no previous entry, and navigation completes asynchronously.

PHP executes on the server; JavaScript executes in the browser. PHP may output HTML and JavaScript, but it does not have direct access to the browser’s session-history stack. The PHP manual describes PHP as server-side scripting that generates responses sent to the browser.

Choose between browser history and a redirect

These options do different jobs. A Back button asks the browser to revisit the prior history entry. A redirect sends the browser to a destination chosen by your application. Use a redirect when a handler has processed a request and knows the right next page; use browser history when the user should return to wherever they came from.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Approach Who chooses the destination? If there is no prior history entry Request behavior
history.back() The browser’s session history It does nothing Traverses an existing history entry
PHP Location redirect Your server-side code Not applicable; it names a destination Sends an HTTP response that directs the browser to a URL

A history action may lead back to an external site or to an earlier page in a new tab’s available history. A redirect instead targets the URL your handler specifies, regardless of the page from which the user arrived.

Redirect after processing a PHP form

For a successful form submission, choose a known destination and send a redirect before producing any output:

<?php
// Validate and choose a local destination; do not copy an arbitrary URL.
header('Location: /account.php', true, 303);
exit;

In this example, the application sends a 303 See Other response so the browser makes a follow-up request to /account.php. PHP’s header() documentation says headers must be sent before output; a Location: header otherwise defaults to status 302 unless a different status has already been set. Stop execution with exit after issuing the redirect so the handler does not continue running.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why not redirect straight to HTTP_REFERER?

$_SERVER['HTTP_REFERER'] contains the HTTP Referer request header when the browser sends one. It may be absent or truncated, and referrer policies control what is sent; it is not a reliable way to determine a safe return destination. See RFC 9110’s Referer definition and MDN’s Referer documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not use an unchecked Referer value as a redirect target. It could send a user somewhere your application did not intend. Prefer a fixed local fallback such as /dashboard.php, or accept only paths from an explicit allowlist. If the application needs to preserve a return destination, store a validated local path in the server-side session or use a signed state value.

Which approach should you use?

  • Return to the browser’s previous page: render a button that calls history.back(), and account for the possibility that it has nowhere to go.
  • Send the user to a known page after a PHP action: issue a validated Location redirect with an appropriate status, before output, then call exit.
  • Return to a requested page safely: validate the destination against an allowlist or use a validated local path; do not trust a raw Referer header.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.