You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

开发PHP浏览器游戏时遇Session问题:页面空白且登录后不跳转

PHP浏览器游戏Session问题排查与修复

问题概述

  • 在header中引入Session相关文件后,页面直接空白
  • 用户通过表单登录后,无法跳转到membersarea.php

相关代码

header.php

<?php 
include 'inc/conf.php';
?>

<!DOCTYPE html>
<head>
  <title>Mineshaft Online | Free to play Browser MMORPG</title>
  <link rel="stylesheet" href="style/style.css">
</head>
<body>
<?php
if(isset($_SESSION['username'])) {
?>

<div class="navigation">
    <ul>
        <li><a href="membersarea.php">Dashboard</a></li>
        <li><a href="ms_game.php">Mineshaft</a></li>
        <li><a href="smeltery.php">Smeltery</a></li>
         <li><a href="blacksmith.php">Blacksmith</a></li>
          <li><a href="edit-profile.php">Settings</a></li>
          <li><a href="logout.php">Logout</a></li>
    </ul>
</div>

<?php 
} else {
?>

<div class="navigation">
    <ul>
        <li><a href="index.php">Home</a></li>
        <li><a href="login.php">Login</a></li>
        <li><a href="register.php">Register</a></li>
    </ul>
</div>

<?php
}
?>

<div class="main-content">

login.php

<?php
include 'inc/conf.php';
include 'header.php';

if(isset($_POST['submit'])){
            // Escape special characters in a string
                $username = mysqli_real_escape_string($conn, $_POST['username']);
                $password = mysqli_real_escape_string($conn, $_POST['password']);
            // If username and password are not empty
                if ($username != "" && $password != ""){
                // Query database to find user with matching username and password
                    $query = "select count(*) as cntUser from users where username='".$username."' and password='".$password."'";
                    $result = mysqli_query($conn, $query); // Store query result
                    $row = mysqli_fetch_array($result); // Fetch row as associative array
                    $count = $row['cntUser']; // Get number of rows
                    if($count > 0){
                        $_SESSION['username'] = $username;
                        header('location: membersarea.php');
                    } else {
                            echo "Error! Invalid username and password.";
                    }
                }
        }
?>

            <form method="post" action="">
                <div id="div_login">
                        <h1>Login</h1>
                        <div>
                            <input type="text" class="textbox" id="username" name="username" placeholder="Username" />
                        </div>
                        <div>
                            <input type="password" class="textbox" id="password" name="password" placeholder="Password"/>
                        </div>
                        <div>
                            <input type="submit" value="Submit" name="submit" id="submit" />
                        </div>
                </div>
            </form>

inc/session.php

<?php
    session_start();
    if(!isset($_SESSION["username"])) {
        header("Location: login.php");
        exit();
    }
?>

问题原因与修复方案

1. 页面空白问题

  • 原因:session_start()必须在任何输出(包括HTML标签、空格、PHP标签前的空白)之前调用。如果在header.php中引入session.php,此时页面已经输出了DOCTYPE和HTML头部内容,触发"headers already sent"错误,导致页面空白。
  • 修复:
    • 在inc/conf.php的最开头添加session_start();,确保所有页面加载时优先启动Session;
    • 确保所有PHP文件的开头没有多余的空白字符,避免意外输出。

2. 登录后无法跳转问题

  • 原因:
    • 登录代码中设置$_SESSION['username']前未启动Session,$_SESSION数组未初始化,导致Session未被正确设置;
    • 调用header('location: membersarea.php');后未终止脚本执行,后续输出内容会干扰跳转逻辑。
  • 修复:
    • 确保session_start();在login.php的最开始执行(可放在inc/conf.php中统一处理);
    • 在header('location: membersarea.php');后添加exit();,终止脚本运行,避免后续输出。

额外优化建议

  • 不要存储明文密码,使用password_hash()加密密码,登录时用password_verify()验证,提升安全性;
  • 登录查询可直接获取用户信息并验证密码,减少数据库查询次数,同时避免SQL注入风险。

内容的提问来源于stack exchange,提问作者Dan Boyden

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 07:01:01