基于PHP+jQuery实现管理员与用户角色登录:如何在现有login2函数中添加管理员登录逻辑?
Hey there! Let's walk through modifying your existing login2 function to support admin role-based login. First, I’ll assume your user_info table has a role column (with values like 'user' for regular users and 'admin' for admins)—if that’s not the case, you’ll need to add this column first.
Step-by-Step Modifications & Fixes
1. Address Existing Issues First
Your current code has a small typo ('passwors' instead of 'password') and critical security gaps (direct SQL concatenation is a huge injection risk, plus MD5 is unsafe for password storage). We’ll fix these while adding the role logic.
2. Retrieve & Store User Role
When fetching user data, we’ll capture the role value and store it in the session. This lets you check the user’s role anywhere in your app later.
3. Role-Specific Return Values
We’ll adjust the function’s return value to differentiate between admin and regular user logins, so your frontend can redirect appropriately.
Modified Code
function login2(){ // Sanitize input to reduce SQL injection risk (prepared statements are even better!) $email = $this->db->real_escape_string($_POST['email']); $password = $_POST['password']; // Fetch user by email first $qry = $this->db->query("SELECT * FROM user_info WHERE email = '$email'"); if($qry->num_rows > 0){ $user = $qry->fetch_array(); // Verify password (note: MD5 is insecure—replace with password_hash/password_verify ASAP!) if(md5($password) === $user['password']){ // Reset login attempts on success $this->db->query("UPDATE user_info SET attempts = '0' WHERE user_id = '" . $user['user_id'] . "' "); // Store user data in session, including role foreach ($user as $key => $value) { if($key != 'password' && !is_numeric($key)){ $_SESSION['login_' . $key] = $value; } } // Link cart to logged-in user $ip = isset($_SERVER['HTTP_CLIENT_IP']) ? $_SERVER['HTTP_CLIENT_IP'] : isset($_SERVER['HTTP_X_FORWARDED_FOR']) ? $_SERVER['HTTP_X_FORWARDED_FOR'] : $_SERVER['REMOTE_ADDR']; $this->db->query("UPDATE cart SET user_id = '" . $user['user_id'] . "' WHERE client_ip = '$ip' "); // Return 2 for admins, 1 for regular users (for frontend redirection) return $user['role'] === 'admin' ? 2 : 1; } else { // Invalid password: increment attempts $_SESSION['attempts'] = isset($_SESSION['attempts']) ? $_SESSION['attempts'] + 1 : 1; $this->db->query("UPDATE user_info SET attempts = '" . $_SESSION['attempts'] . "' WHERE email = '$email' "); // Lock account after 3 failed attempts if($_SESSION['attempts'] >= 3){ $this->db->query("UPDATE user_info SET password = 'sfsdfsdfdsfsdf435345435j3k5h35498f7dsf' WHERE email = '$email' "); } return 3; } }else{ // User doesn't exist: increment attempts $_SESSION['attempts'] = isset($_SESSION['attempts']) ? $_SESSION['attempts'] + 1 : 1; return 3; } }
How to Use the Role Logic
Once the user logs in, you can check their role to restrict access or redirect:
// Example: Redirect admin to dashboard, regular user to profile $loginResult = login2(); if($loginResult == 2){ header('Location: admin/dashboard.php'); }elseif($loginResult == 1){ header('Location: user/profile.php'); }else{ // Handle login failure echo "Invalid credentials or locked account!"; } // Example: Protect admin-only pages if($_SESSION['login_role'] !== 'admin'){ header('Location: login.php'); exit; }
Critical Security Notes
- Replace MD5: MD5 is easily cracked. Use PHP’s
password_hash()when creating user accounts andpassword_verify()instead of comparing MD5 hashes. - Use Prepared Statements: Direct SQL concatenation leaves you vulnerable to injection attacks. Here’s how to rewrite the user query with MySQLi prepared statements:
$stmt = $this->db->prepare("SELECT * FROM user_info WHERE email = ?"); $stmt->bind_param("s", $email); $stmt->execute(); $result = $stmt->get_result(); $user = $result->fetch_array();
内容的提问来源于stack exchange,提问作者KA trending

