PHP注册表单跳转错误至login.php而非index.php问题排查
Let’s work through your two core problems step by step, with concrete code fixes to get your system working as expected:
1. Signup Button Redirects to login.php Instead of index.php
Root Cause
In your index.php, the signup form’s action attribute is incorrectly set to login.php — this sends your registration data to the login handler instead of the signup script, causing the wrong redirect.
Fix
Update the signup form in index.php to point to signup.php:
// Replace the existing signup form in index.php with this echo "<form action='signup.php' method='POST'> <!-- Corrected action path --> <input type='text' name='name' placeholder='Name'> <input type='text' name='phone' placeholder='phone'> <input type='text' name='email' placeholder='email'> <input type='text' name='zip' placeholder='zip'> <input type='password' name='password' placeholder='password'> <button type='submit' name='submitSignup'>Signup</button> </form>";
2. Registration Success Issues: Blank login.php & Missing Default Avatar
This problem has a few interconnected causes — let’s fix each one:
a. Mismatched Database Field Names in signup.php
Your users table uses prefixed fields like user_name and user_phone, but your signup code uses unprefixed names (e.g., name instead of user_name). This means user data isn’t actually inserted into the database, and the default avatar entry fails too.
b. Unclosed Image Tags in index.php
Your avatar image tags are missing the closing >, which breaks HTML rendering and prevents avatars from displaying.
c. Blank login.php When Accessed Directly
Your login.php only runs code if submitLogin is set — if someone visits the page without submitting the login form, it shows nothing.
d. Incorrect User Name Reference in index.php
You’re trying to echo $row['name'], but your table uses the field name user_name.
Full Fixes for These Issues
Modified signup.php
<?php session_start(); // Add session start for consistency include_once 'dbh.php'; // Sanitize inputs to avoid basic SQL injection risks $name = mysqli_real_escape_string($conn, $_POST['name']); $phone = mysqli_real_escape_string($conn, $_POST['phone']); $email = mysqli_real_escape_string($conn, $_POST['email']); $zip = mysqli_real_escape_string($conn, $_POST['zip']); $password = mysqli_real_escape_string($conn, $_POST['password']); // Use correct table field names (matches your users table structure) $sql = "INSERT INTO users (user_name, user_phone, user_email, user_zip, user_password) VALUES ('$name', '$phone', '$email', '$zip', '$password')"; mysqli_query($conn, $sql); // Fetch the newly created user with correct field names $sql = "SELECT * FROM users WHERE user_name = '$name' AND user_phone='$phone'"; $result = mysqli_query($conn, $sql); if (mysqli_num_rows($result) > 0) { while($row = mysqli_fetch_assoc($result)) { $userid = $row['user_id']; // Insert default profile image entry (status=1 = use default avatar) $sql = "INSERT INTO profileimg (userid, status) VALUES ('$userid', 1)"; mysqli_query($conn, $sql); header("Location: index.php"); exit; // Always exit after header redirect to stop further code execution } } else { echo "Error: Could not create your account. Please try again."; }
Modified Avatar Rendering in index.php
// Replace the avatar display block with this while ($rowImg = mysqli_fetch_assoc($resultImg)) { echo "<div>"; if($rowImg['status'] == 0) { echo "<img src='uploads/profile".$id.".jpg' alt='User Profile Image'>"; // Closed tag + accessibility alt text } else { echo "<img src='uploads/profiledefault.jpg' alt='Default Profile Image'>"; // Closed tag + accessibility alt text } echo $row['user_name']; // Use the correct field name from your users table echo "</div>"; }
Modified login.php to Fix Blank Page
<?php session_start(); if (isset($_POST['submitLogin'])) { // Note: This hardcodes user ID 1 — for a real system, fetch the actual user ID from the database using login credentials $_SESSION['id'] = 1; header("Location: index.php"); exit; } else { // Redirect users who visit login.php directly back to the main page header("Location: index.php"); exit; }
Bonus: Critical Security Note
Your current code uses unsanitized user input directly in SQL queries, which leaves you vulnerable to SQL injection attacks. For production use, switch to prepared statements with parameter binding. Example snippet for signup:
// Prepared statement example (safer alternative to raw SQL) $stmt = mysqli_prepare($conn, "INSERT INTO users (user_name, user_phone, user_email, user_zip, user_password) VALUES (?, ?, ?, ?, ?)"); mysqli_stmt_bind_param($stmt, "sssss", $name, $phone, $email, $zip, $password); mysqli_stmt_execute($stmt);
内容的提问来源于stack exchange,提问作者Christian AH

