如何在PHP代码中实现密码强度检查?出现ArgumentCountError参数数量错误
解决PHP密码强度检查的ArgumentCountError错误及功能完善
一、先搞定直接触发的参数错误
你看到的ArgumentCountError原因非常明确:你的strongpass::check()方法定义时要求2个参数($password和$user),但调用时只传了1个$password,导致参数不匹配。
修复调用代码
首先得确保从表单里拿到用户名(假设你的登录/注册表单有name="user"的输入框),然后调用方法时补上$user参数:
$user = $_POST["user"] ?? ""; // 从POST取用户名,为空时默认空字符串 if(isset($_POST["password"])){ $password = $_POST["password"]; include_once("strongpass.php"); $strongpass = new strongpass(); $response = $strongpass->check($password, $user); // 这里补上缺失的$user参数 if($response != "OK"){ $status = $response; } else { $status = "Password is strong so parsing can continue here."; } }
二、修复strongpass类里的语法&逻辑问题
你的类代码还有几个隐藏问题,不修复的话就算参数传对了也会报错:
1. 移除多余的else关键字
第一个条件判断前直接用了else if,但前面没有对应的if语句,会触发语法错误。把else删掉,改成普通的if:
// 错误代码 else if (($user == $password) || ($password == strrev($user))|| (denum_pass == $user) || ($denum_pass == strrev($user))){ // 修复后 if (($user == $password) || ($password == strrev($user))|| ($denum_pass == $user) || ($denum_pass == strrev($user))){
2. 补上变量名的美元符号
判断里的denum_pass少了$,PHP会把它当成常量处理,导致逻辑失效:
// 错误代码 || (denum_pass == $user) // 修复后 || ($denum_pass == $user)
3. 适配Windows系统的字典路径
你用的/usr/share/dict/words是Linux/macOS的默认字典路径,Windows下根本不存在。可以自己创建一个字典文件(每行一个单词),放在项目目录里,比如dict/words.txt,然后修改路径:
$word_file = __DIR__ . '/dict/words.txt'; // 用__DIR__确保路径是当前脚本的绝对路径
三、完善密码强度检查规则(可选但推荐)
目前你的检查规则太基础,建议补充行业通用的强度要求,比如长度、字符类型组合:
public function check($password,$user){ $denum_pass = strtr($password,'5301!','seoll'); $word_file = __DIR__ . '/dict/words.txt'; $lc_user = strtolower($user); $lc_pass = strtolower($password); $response = "OK"; // 规则1:密码至少8位 if (strlen($password) < 8) { return "Password must be at least 8 characters long."; } // 规则2:至少包含3种字符类型(大写、小写、数字、特殊符号) $hasUpper = preg_match('/[A-Z]/', $password); $hasLower = preg_match('/[a-z]/', $password); $hasNumber = preg_match('/[0-9]/', $password); $hasSpecial = preg_match('/[!@#$%^&*(),.?":{}|<>]/', $password); if (($hasUpper + $hasLower + $hasNumber + $hasSpecial) < 3) { return "Password must include at least 3 of these: uppercase letters, lowercase letters, numbers, special characters."; } // 规则3:不能和用户名(或变形)重复 if (!empty($user)) { if ($user == $password || $password == strrev($user) || $denum_pass == $user || $denum_pass == strrev($user)) { return "Password cannot match your username (or its reversed/obfuscated version)."; } } // 规则4:不能包含字典单词 if (is_readable($word_file)){ $fh = fopen($word_file,'r'); if ($fh) { $found = false; while (!($found || feof($fh))) { $word = trim(strtolower(fgets($fh,1024))); $word = preg_quote($word, '/'); if (!empty($word) && (preg_match("/$word/", $lc_pass) || preg_match("/$word/", $denum_pass))) { $found = true; } } fclose($fh); if ($found){ return 'Password is based on a dictionary word.'; } } } return $response; }
最终完整代码示例
strongpass.php
class strongpass{ public function check($password,$user){ $denum_pass = strtr($password,'5301!','seoll'); $word_file = __DIR__ . '/dict/words.txt'; $lc_user = strtolower($user); $lc_pass = strtolower($password); $response = "OK"; if (strlen($password) < 8) { return "Password must be at least 8 characters long."; } $hasUpper = preg_match('/[A-Z]/', $password); $hasLower = preg_match('/[a-z]/', $password); $hasNumber = preg_match('/[0-9]/', $password); $hasSpecial = preg_match('/[!@#$%^&*(),.?":{}|<>]/', $password); if (($hasUpper + $hasLower + $hasNumber + $hasSpecial) < 3) { return "Password must include at least 3 of these: uppercase letters, lowercase letters, numbers, special characters."; } if (!empty($user)) { if ($user == $password || $password == strrev($user) || $denum_pass == $user || $denum_pass == strrev($user)) { return "Password cannot match your username (or its reversed/obfuscated version)."; } } if (is_readable($word_file)){ $fh = fopen($word_file,'r'); if ($fh) { $found = false; while (!($found || feof($fh))) { $word = trim(strtolower(fgets($fh,1024))); $word = preg_quote($word, '/'); if (!empty($word) && (preg_match("/$word/", $lc_pass) || preg_match("/$word/", $denum_pass))) { $found = true; } } fclose($fh); if ($found){ return 'Password is based on a dictionary word.'; } } } return $response; } }
调用代码(index.php)
<?php $status = ""; $user = $_POST["user"] ?? ""; if(isset($_POST["password"])){ $password = $_POST["password"]; include_once("strongpass.php"); $strongpass = new strongpass(); $response = $strongpass->check($password, $user); if($response != "OK"){ $status = $response; } else { $status = "Password is strong so parsing can continue here."; } } ?> <form method="post"> <label>Username: <input type="text" name="user" value="<?php echo htmlspecialchars($user); ?>"></label><br> <label>Password: <input type="password" name="password"></label><br> <button type="submit">Check Password Strength</button> </form> <?php if (!empty($status)): ?> <p><?php echo htmlspecialchars($status); ?></p> <?php endif; ?>
内容的提问来源于stack exchange,提问作者JuN Yee
相关产品推荐
相关产品推荐

