点击注册按钮触发URL未找到错误,求PHP注册功能排查帮助
Hey there, let's tackle your problems one by one—starting with that frustrating 404 error, then fixing the underlying code issues to get your registration working smoothly.
1. The 404 "URL Not Found" Error (Immediate Fix)
The first problem is straightforward: your registration form in login.php points to validation.php via the action attribute, but either:
- You haven't saved your registration processing code as
validation.php(double-check your filename spelling and case—case matters on Linux/Mac systems), or - The
validation.phpfile isn't in the same directory aslogin.phpwithin your XAMPPhtdocsfolder.
Quick check: Make sure your file structure looks like this in htdocs:
htdocs/ ├─ login.php └─ validation.php <-- This is where your registration PHP code lives
2. Fixing the PHP Code Issues
Even once the 404 is fixed, your code has several bugs that will break registration. Here's the corrected version with explanations:
Corrected validation.php Code
<?php // Enable error display for debugging (turn off in production!) ini_set('display_errors', 1); ini_set('log_errors', 1); error_reporting(E_ALL); mysqli_report(MYSQLI_REPORT_ERROR | MYSQLI_REPORT_STRICT); session_start(); // Connect to database (use mysqli_connect with error handling) $con = mysqli_connect('localhost', 'root', 'ocr2020', 'login'); if (!$con) { die("Connection failed: " . mysqli_connect_error()); } // Get form data (match the name attributes from your form!) $name = $_POST['user']; // Form uses "password" as the input name, not "pass" $pass = $_POST['password']; $fname = $_POST['forename']; $sname = $_POST['surname']; $mobile = $_POST['mobile']; $email = $_POST['email']; // Fix variable name consistency (no camelCase mismatch) $dateOfB = $_POST['dateB']; // Check if username already exists (use prepared statement to avoid SQL injection!) $stmt = $con->prepare("SELECT * FROM usertable WHERE Username = ?"); $stmt->bind_param("s", $name); $stmt->execute(); $result = $stmt->get_result(); $num = $result->num_rows; if ($num > 0) { echo "Username Is No Longer Available"; } else { // Use prepared statement for insertion (critical for security!) // Note: If patientID is set to AUTO_INCREMENT in your database, omit it from the query $stmt = $con->prepare("INSERT INTO usertable (Forename, Surname, Username, Password, Email, Mobile, DateOfBirth) VALUES (?, ?, ?, ?, ?, ?, ?)"); $stmt->bind_param("sssssss", $fname, $sname, $name, $pass, $email, $mobile, $dateOfB); if ($stmt->execute()) { echo "Registration Successful"; } else { echo "Error: " . $stmt->error; } } // Clean up $stmt->close(); mysqli_close($con); ?>
Key Fixes in the Code:
- Form field mismatch: Your form uses
name="password"but your original code tried to get$_POST['pass']—this would have caused an undefined variable error. - Variable name typo: You had
$dateofBin one place and$dateOfBin another (PHP is case-sensitive!). - Removed manual
patientIDgeneration: Instead of calculating$idfrom row counts (which is unreliable), set yourpatientIDcolumn in MySQL toINT AUTO_INCREMENT PRIMARY KEY—the database will handle assigning unique IDs automatically. - SQL Injection Protection: Swapped direct SQL string concatenation with prepared statements—this is non-negotiable for security, as your original code was wide open to attacks.
- Better error handling: Added connection error checking and proper statement cleanup.
3. Database Table Recommendation
Make sure your usertable has the correct structure (adjust if needed):
CREATE TABLE usertable ( patientID INT AUTO_INCREMENT PRIMARY KEY, Forename VARCHAR(50) NOT NULL, Surname VARCHAR(50) NOT NULL, Username VARCHAR(50) NOT NULL UNIQUE, Password VARCHAR(255) NOT NULL, -- Store hashed passwords, not plain text! Email VARCHAR(100) NOT NULL, Mobile VARCHAR(20) NOT NULL, DateOfBirth DATE NOT NULL );
Important: Never store plain-text passwords! Use password_hash() when saving passwords and password_verify() when logging in. For example:
// When registering: $hashed_pass = password_hash($pass, PASSWORD_DEFAULT); // Then use $hashed_pass in the INSERT statement // When logging in: // Fetch the hashed password from the database, then verify: if (password_verify($_POST['password'], $hashed_pass_from_db)) { // Login successful }
Final Checklist
- Confirm
validation.phpexists in the same directory aslogin.phpwith the correct filename. - Double-check that all form input
nameattributes match the$_POSTkeys in your PHP code. - Ensure your
usertablehaspatientIDset as an auto-incrementing primary key. - Test the registration flow again—you should no longer get the 404, and the form data should save correctly to your database.
内容的提问来源于stack exchange,提问作者Pintsize21

