password_verify始终返回false求助(已排除常见错误)
password_verify 始终返回 false,已排查常见问题仍未解决
我在项目中使用password_verify函数时遇到问题,该函数始终返回false,尽管之前用同一套逻辑在另一项目(同一机器)上能正常运行。我已经排查了常见问题,但仍未找到原因,以下是详细信息:
有问题的项目代码
case 'Register': $first_name = trim(filter_input(INPUT_POST, 'first_name', FILTER_SANITIZE_FULL_SPECIAL_CHARS)); $middle_name = trim(filter_input(INPUT_POST, 'middle_name', FILTER_SANITIZE_FULL_SPECIAL_CHARS)); $last_name = trim(filter_input(INPUT_POST, 'last_name', FILTER_SANITIZE_FULL_SPECIAL_CHARS)); $email = trim(filter_input(INPUT_POST, 'email', FILTER_SANITIZE_EMAIL)); $password = trim(filter_input(INPUT_POST, 'password', FILTER_SANITIZE_FULL_SPECIAL_CHARS)); $phone = trim(filter_input(INPUT_POST, 'phone', FILTER_SANITIZE_FULL_SPECIAL_CHARS)); $email = checkEmail($email); $password = checkPassword($password); if (checkExistingEmail($email)){ $_SESSION['message'] = '<p class="formErrorMessage">That email address is already in use. Try logging in or using a different email.</p>'; include '../view/register.php'; exit; } if (!empty($phone)){ if (checkExistingPhone($phone)){ $_SESSION['message'] = '<p class="formErrorMessage">That phone number is already in use. Please use a different phone number.</p>'; include '../view/register.php'; exit; } } if (empty($first_name) || empty($last_name) || empty($email) || empty($password)){ $_SESSION['message'] = '<p class="formErrorMessage">Please provide information for all required form fields.</p>'; include '../view/register.php'; exit; } $hashedPassword = password_hash($password, PASSWORD_DEFAULT); $registrationOutcome = registerUser($first_name, $middle_name, $last_name, $email, $hashedPassword, $phone); if($registrationOutcome === 1){ setcookie('first_name', $first_name, strtotime('+1 year'), '/'); $userData = getUser($email); $_SESSION['loggedin'] = TRUE; array_pop($userData); $_SESSION['clientData'] = $clientData; header('Location: /valleymusicclub/accounts/'); exit; } else { $_SESSION['message'] = "<p class='formErrorMessage'>Sorry, $first_name, but the registration failed. Please try again.</p>"; include '../view/login.php'; exit; } break; case 'Login': $email = filter_input(INPUT_POST, 'email', FILTER_SANITIZE_EMAIL); $email = checkEmail($email); $password = filter_input(INPUT_POST, 'password', FILTER_SANITIZE_FULL_SPECIAL_CHARS); $passwordCheck = checkPassword($password); if (empty($email) || empty($passwordCheck)){ $_SESSION['message'] = '<p class="formErrorMessage">Please provide a valid email address and password.</p>'; include '../view/login.php'; exit; } $userData = getUser($email); $passwordHash = $userData['password']; $hashCheck = password_verify($password, $passwordHash); if (!$hashCheck){ $_SESSION['message'] = "<p class='formErrorMessage'>Please provide a valid password. $password</p>"; include '../view/login.php'; exit; } $_SESSION['loggedin'] = TRUE; array_pop($clientData); $_SESSION['clientData'] = $clientData; header('Location: /valleymusicclub/accounts/'); exit;
正常运行的项目代码
case 'register': $clientFirstname = trim(filter_input(INPUT_POST, 'clientFirstname', FILTER_SANITIZE_FULL_SPECIAL_CHARS)); $clientLastname = trim(filter_input(INPUT_POST, 'clientLastname', FILTER_SANITIZE_FULL_SPECIAL_CHARS)); $clientEmail = trim(filter_input(INPUT_POST, 'clientEmail', FILTER_SANITIZE_EMAIL)); $clientPassword = trim(filter_input(INPUT_POST, 'clientPassword', FILTER_SANITIZE_FULL_SPECIAL_CHARS)); $clientEmail = checkEmail($clientEmail); $checkPassword = checkPassword($clientPassword); $existingEmail = checkExistingEmail($clientEmail); // Check for existing email address in the table if($existingEmail){ $message = '<p class="formErrorMessage">That email address already exists. Do you want to login instead?</p>'; include '../view/login.php'; exit; } // Check for missing data if(empty($clientFirstname) || empty($clientLastname) || empty($clientEmail) || empty($checkPassword)){ $message = '<p class="formErrorMessage">Please provide information for all empty form fields.</p>'; include '../view/registration.php'; exit; } // Hash the checked password $hashedPassword = password_hash($clientPassword, PASSWORD_DEFAULT); // Send the data to the model $regOutcome = regClient($clientFirstname, $clientLastname, $clientEmail, $hashedPassword); // Check and report the result if($regOutcome === 1){ setcookie('firstname', $clientFirstname, strtotime('+1 year'), '/'); $_SESSION['message'] = "<p class='formSuccessMessage'>Thanks for registering, $clientFirstname. Please use your email and password to login.</p>"; header('Location: /phpmotors/accounts/?action=login'); exit; } else { $_SESSION['message'] = "<p class='formErrorMessage'>Sorry, $clientFirstname, but the registration failed. Please try again.</p>"; include '../view/login.php'; exit; } break; case 'Login': $clientEmail = filter_input(INPUT_POST, 'clientEmail', FILTER_SANITIZE_EMAIL); $clientEmail = checkEmail($clientEmail); $clientPassword = filter_input(INPUT_POST, 'clientPassword', FILTER_SANITIZE_FULL_SPECIAL_CHARS); $passwordCheck = checkPassword($clientPassword); // Run basic checks, return if errors if (empty($clientEmail) || empty($passwordCheck)) { $_SESSION['message'] = '<p class="formErrorMessage">Please provide a valid email address and password.</p>'; include '../view/login.php'; exit; } // A valid password exists, proceed with the login process // Query the client data based on the email address $clientData = getClient($clientEmail); // Compare the password just submitted against // the hashed password for the matching client $hashCheck = password_verify($clientPassword, $clientData['clientPassword']); // If the hashes don't match create an error // and return to the login view if(!$hashCheck) { $_SESSION['message'] = '<p class="formErrorMessage">Please check your password and try again.</p>'; include '../view/login.php'; exit; } // A valid user exists, log them in $_SESSION['loggedin'] = TRUE; // Remove the password from the array // the array_pop function removes the last // element from an array array_pop($clientData); // Store the array into the session $_SESSION['clientData'] = $clientData; // Send them to the admin view header('Location: /phpmotors/accounts/'); exit;
已排查的常见问题
- 数据库密码字段为
VARCHAR(255),足够容纳PASSWORD_DEFAULT生成的60字符哈希 - 密码仅在注册时哈希一次,未重复哈希
$userData['password']确实存储了正确的哈希值- 表单传入的
$password与输入的原始密码一致(已通过var_dump验证) password_verify的参数顺序正确(原始密码在前,哈希值在后)- 尝试移除
trim和FILTER_SANITIZE_FULL_SPECIAL_CHARS过滤器后问题依然存在,且验证过滤后的密码与原密码一致
补充:var_dump 输出对比
正常项目输出:
string(12) "Password123@" string(60) "$2y$10$gPmIdgHMtKEa28EagP4H3.TDZrWwoMY/CABIQleOqXUzh65/fov6W" bool(true)
有问题的项目输出:
string(12) "Password123@" string(60) "$2y$10$8wheUb4qjxl.V1qM5EsKf.nE.MEF5wE8rnfnDApIMRjpIFxhgVt/2" bool(false)
内容的提问来源于stack exchange,提问作者Brandon Lisonbee
相关产品推荐
相关产品推荐

