PHP登录跳转异常:认证用户无法访问profile.php却跳转到index.php
登录跳转问题排查与修复
问题描述
刚接触编程,对PHP不熟悉,开发登录页面时遇到问题:验证通过的用户本该跳转至受保护的profile.php,但实际登录后会被跳转到index.php,完全无法访问profile.php。
现有代码
Profile页面代码
<?php session_start(); require_once 'connect.php'; if(!isset($_SESSION['user'])){ header("Location: index.php"); exit; } $query = "SELECT * FROM people WHERE userid=?"; $stmt = $pdo->prepare($query); $stmt->execute([$_SESSION['user']]); $userRow = $stmt->fetch(PDO::FETCH_ASSOC); ?> <html> <head><title>You are logged in!</title></head> <body> Thanks so much for visiting,<?php echo $userRow['fname']; ?> <p><a href="logout.php">Logout Here</a></p> </body> </html>
登录页面代码
<?php session_start(); if( isset($_SESSION['user'])!="" ){ header("Location: index.php"); } include_once 'connect.php'; if ( isset($_POST['sca']) ) { $username = trim($_POST['username']); $pass = trim($_POST['pass']); $password = hash('sha256', $pass); $query = "select userid, username, pass from people where username=?"; $stmt = $pdo->prepare($query); $stmt->execute([$username]); $count = $stmt->rowCount(); $row = $stmt->fetch(PDO::FETCH_ASSOC); if( $count == 1 && $row['pass']==$password ) { $_SESSION['user'] = $row['userid']; header("Location: profile.php"); } else { $message = "Invalid Login"; } $_SESSION['message'] = $message; } ?> <html> <head> <title>Login Page</title> <style> body { font-family: Arial, sans-serif; background-color: #111111; color: #b2b2b2; display: flex; justify-content: center; align-items: center; min-height: 100vh; flex-direction: column; margin-top: 50px; } h1 { color: #AB8BF2; margin-bottom: 20px; } .menu { background-color: #212121; overflow: hidden; display: flex; justify-content: center; position: fixed; top: 0; width: 100%; } .menu a { display: block; color: #b2b2b2; text-align: center; padding: 14px 16px; text-decoration: none; } .menu a:hover { background-color: #444444; } .menu a.active { background-color: #AB8BF2; color: white; } .dropdown-content { display: none; position: absolute; background-color: #f9f9f9; min-width: 160px; box-shadow: 0px 8px 16px 0px rgba(0,0,0,0.2); z-index: 1; } .dropdown-content a { color: black; padding: 12px 16px; text-decoration: none; display: block; } .dropdown-content a:hover { background-color: #f1f1f1; } .dropdown:hover .dropdown-content { display: block; } .myDiv { border: 2px solid #b2b2b2; background-color: #212121; padding-left: 40px; width: 350px; display: flex; flex-direction: column; align-items: center; padding-bottom: 20px; } form { margin-top: 20px; } label { display: block; margin-bottom: 5px; color: #AB8BF2; } input[type="text"], input[type="password"] { width: 200px; padding: 5px; background-color: #b2b2b2; color: #111111; } input[type="submit"] { padding: 8px 20px; background-color: #AB8BF2; color: #fff; border: none; cursor: pointer; } a { color: #AB8BF2; text-decoration: none; } a:hover { color: #AB8BF2; } </style> </head> <body> <p><h1> <?php if ( isset($message) ) { echo $message; } ?> </h1></p> <h1>Login and Leave a Comment!</h1> <div class="menu"> <a class="active" href="index.php">Home</a> <div class="dropdown"> <a href="#" class="dropbtn">Table of Contents</a> <div class="dropdown-content"> <a href="#section1">Section 1</a> <a href="#section2">Section 2</a> <a href="#section3">Section 3</a> </div> </div> <a href="#blog">Blog Posts</a> <a href="contact.php">Contact</a> <a href="#subscribe">Subscribe</a> <a href="login.php">Login</a> </div> <div class="myDiv"> <form action="profile.php" method="post"> <label for="username">Username:</label> <input type="text" id="username" name="username" required> <label for="password">Password:</label> <input type="password" id="password" name="password" required> <input type="submit" value="Login"> </form> <p>Don't have an account? <a href="registration.php">Create one</a>. </p> </div> </body> </html>
修复步骤
1. 修正表单提交目标
登录表单当前提交到profile.php,但验证逻辑在login.php,导致未设置session时就进入profile的权限检查,被跳转至index.php。修改表单action为login.php:
<form action="login.php" method="post">
2. 匹配表单字段与PHP参数
- 提交按钮缺少
name="sca",导致PHP里的isset($_POST['sca'])不成立,验证逻辑不执行。给按钮添加name:
<input type="submit" name="sca" value="Login">
- 密码输入框的
name是password,但PHP里取的是$_POST['pass'],导致密码为空。修改PHP代码:
$pass = trim($_POST['password']);
3. 修正已登录用户跳转逻辑
原代码判断已登录的逻辑错误(布尔值与空字符串比较),且错误跳转到index.php。修改为:
if(isset($_SESSION['user'])){ header("Location: profile.php"); exit; }
4. 登录成功后终止代码执行
登录成功跳转后未加exit,可能导致后续代码干扰。添加exit:
if( $count == 1 && $row['pass']==$password ) { $_SESSION['user'] = $row['userid']; header("Location: profile.php"); exit; }
5. 修正错误信息赋值逻辑
原代码无论登录成功与否都赋值$_SESSION['message'],成功时$message未定义会报错。将赋值移到else块内:
else { $message = "Invalid Login"; $_SESSION['message'] = $message; }
内容的提问来源于stack exchange,提问作者Samuel Rayne
相关产品推荐
相关产品推荐

