You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

password_verify始终返回false求助(已排除常见错误)

password_verify 始终返回 false,已排查常见问题仍未解决

我在项目中使用password_verify函数时遇到问题,该函数始终返回false,尽管之前用同一套逻辑在另一项目(同一机器)上能正常运行。我已经排查了常见问题,但仍未找到原因,以下是详细信息:

有问题的项目代码

case 'Register':
    $first_name = trim(filter_input(INPUT_POST, 'first_name', FILTER_SANITIZE_FULL_SPECIAL_CHARS));
    $middle_name = trim(filter_input(INPUT_POST, 'middle_name', FILTER_SANITIZE_FULL_SPECIAL_CHARS));
    $last_name = trim(filter_input(INPUT_POST, 'last_name', FILTER_SANITIZE_FULL_SPECIAL_CHARS));
    $email = trim(filter_input(INPUT_POST, 'email', FILTER_SANITIZE_EMAIL));
    $password = trim(filter_input(INPUT_POST, 'password', FILTER_SANITIZE_FULL_SPECIAL_CHARS));
    $phone = trim(filter_input(INPUT_POST, 'phone', FILTER_SANITIZE_FULL_SPECIAL_CHARS));

    $email = checkEmail($email);
    $password = checkPassword($password);

    if (checkExistingEmail($email)){
        $_SESSION['message'] = '<p class="formErrorMessage">That email address is already in use. Try logging in or using a different email.</p>';
        include '../view/register.php';
        exit;
    }

    if (!empty($phone)){
        if (checkExistingPhone($phone)){
            $_SESSION['message'] = '<p class="formErrorMessage">That phone number is already in use. Please use a different phone number.</p>';
            include '../view/register.php';
            exit;
        }
    }

    if (empty($first_name) || empty($last_name) || empty($email) || empty($password)){
        $_SESSION['message'] = '<p class="formErrorMessage">Please provide information for all required form fields.</p>';
        include '../view/register.php';
        exit;
    }

    $hashedPassword = password_hash($password, PASSWORD_DEFAULT);

    $registrationOutcome = registerUser($first_name, $middle_name, $last_name, $email, $hashedPassword, $phone);

    if($registrationOutcome === 1){
        setcookie('first_name', $first_name, strtotime('+1 year'), '/');
        $userData = getUser($email);

        $_SESSION['loggedin'] = TRUE;

        array_pop($userData);

        $_SESSION['clientData'] = $clientData;

        header('Location: /valleymusicclub/accounts/');
        exit;
    } else {
        $_SESSION['message'] = "<p class='formErrorMessage'>Sorry, $first_name, but the registration failed. Please try again.</p>";
        include '../view/login.php';
        exit;
    }
    break;
case 'Login':
    $email = filter_input(INPUT_POST, 'email', FILTER_SANITIZE_EMAIL);
    $email = checkEmail($email);
    $password = filter_input(INPUT_POST, 'password', FILTER_SANITIZE_FULL_SPECIAL_CHARS);
    $passwordCheck = checkPassword($password);

    if (empty($email) || empty($passwordCheck)){
        $_SESSION['message'] = '<p class="formErrorMessage">Please provide a valid email address and password.</p>';
        include '../view/login.php';
        exit;
    }

    $userData = getUser($email);

    $passwordHash = $userData['password'];

    $hashCheck = password_verify($password, $passwordHash);

    if (!$hashCheck){
        $_SESSION['message'] = "<p class='formErrorMessage'>Please provide a valid password. $password</p>";
        include '../view/login.php';
        exit;
    }

    $_SESSION['loggedin'] = TRUE;

    array_pop($clientData);

    $_SESSION['clientData'] = $clientData;

    header('Location: /valleymusicclub/accounts/');
    exit;

正常运行的项目代码

case 'register':
    $clientFirstname = trim(filter_input(INPUT_POST, 'clientFirstname', FILTER_SANITIZE_FULL_SPECIAL_CHARS));
    $clientLastname = trim(filter_input(INPUT_POST, 'clientLastname', FILTER_SANITIZE_FULL_SPECIAL_CHARS));
    $clientEmail = trim(filter_input(INPUT_POST, 'clientEmail', FILTER_SANITIZE_EMAIL));
    $clientPassword = trim(filter_input(INPUT_POST, 'clientPassword', FILTER_SANITIZE_FULL_SPECIAL_CHARS));

    $clientEmail = checkEmail($clientEmail);
    $checkPassword = checkPassword($clientPassword);

    $existingEmail = checkExistingEmail($clientEmail);

    // Check for existing email address in the table
    if($existingEmail){
        $message = '<p class="formErrorMessage">That email address already exists. Do you want to login instead?</p>';
        include '../view/login.php';
        exit;
    }

    // Check for missing data
    if(empty($clientFirstname) || empty($clientLastname) || empty($clientEmail) || empty($checkPassword)){
        $message = '<p class="formErrorMessage">Please provide information for all empty form fields.</p>';
        include '../view/registration.php';
        exit;
    }

    // Hash the checked password
    $hashedPassword = password_hash($clientPassword, PASSWORD_DEFAULT);

    // Send the data to the model
    $regOutcome = regClient($clientFirstname, $clientLastname, $clientEmail, $hashedPassword);

    // Check and report the result
    if($regOutcome === 1){
        setcookie('firstname', $clientFirstname, strtotime('+1 year'), '/');
        $_SESSION['message'] = "<p class='formSuccessMessage'>Thanks for registering, $clientFirstname. Please use your email and password to login.</p>";
        header('Location: /phpmotors/accounts/?action=login');
        exit;
    } else {
        $_SESSION['message'] = "<p class='formErrorMessage'>Sorry, $clientFirstname, but the registration failed. Please try again.</p>";
        include '../view/login.php';
        exit;
    }
    break;
case 'Login':
    $clientEmail = filter_input(INPUT_POST, 'clientEmail', FILTER_SANITIZE_EMAIL);
    $clientEmail = checkEmail($clientEmail);
    $clientPassword = filter_input(INPUT_POST, 'clientPassword', FILTER_SANITIZE_FULL_SPECIAL_CHARS);
    $passwordCheck = checkPassword($clientPassword);

    // Run basic checks, return if errors
    if (empty($clientEmail) || empty($passwordCheck)) {
        $_SESSION['message'] = '<p class="formErrorMessage">Please provide a valid email address and password.</p>';
        include '../view/login.php';
        exit;
    }
    
    // A valid password exists, proceed with the login process
    // Query the client data based on the email address
    $clientData = getClient($clientEmail);
    // Compare the password just submitted against
    // the hashed password for the matching client
    $hashCheck = password_verify($clientPassword, $clientData['clientPassword']);
    // If the hashes don't match create an error
    // and return to the login view
    if(!$hashCheck) {
        $_SESSION['message'] = '<p class="formErrorMessage">Please check your password and try again.</p>';
        include '../view/login.php';
        exit;
    }
    // A valid user exists, log them in
    $_SESSION['loggedin'] = TRUE;
    // Remove the password from the array
    // the array_pop function removes the last
    // element from an array
    array_pop($clientData);
    // Store the array into the session
    $_SESSION['clientData'] = $clientData;
    // Send them to the admin view
    header('Location: /phpmotors/accounts/');
    exit;

已排查的常见问题

  • 数据库密码字段为VARCHAR(255),足够容纳PASSWORD_DEFAULT生成的60字符哈希
  • 密码仅在注册时哈希一次,未重复哈希
  • $userData['password']确实存储了正确的哈希值
  • 表单传入的$password与输入的原始密码一致(已通过var_dump验证)
  • password_verify的参数顺序正确(原始密码在前,哈希值在后)
  • 尝试移除trim和FILTER_SANITIZE_FULL_SPECIAL_CHARS过滤器后问题依然存在,且验证过滤后的密码与原密码一致

补充:var_dump 输出对比

正常项目输出:

string(12) "Password123@" string(60) "$2y$10$gPmIdgHMtKEa28EagP4H3.TDZrWwoMY/CABIQleOqXUzh65/fov6W" bool(true)

有问题的项目输出:

string(12) "Password123@" string(60) "$2y$10$8wheUb4qjxl.V1qM5EsKf.nE.MEF5wE8rnfnDApIMRjpIFxhgVt/2" bool(false)

内容的提问来源于stack exchange,提问作者Brandon Lisonbee

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 21:17:03