login.php浏览器加载失败及Undefined index报错问题求助
Hey there, let's work through your login issues together—those undefined index errors and the "Invalid credentials" message are pretty common, and we can fix them with some targeted tweaks. Plus, we'll address broader security and code structure issues that are causing these problems in the first place.
1. Fixing the "Undefined Index" Errors
The notices you're seeing happen because when you first load login_code.php (either directly or via your login page), it's a GET request—there's no email or password data being sent via POST yet. Your code tries to access $_POST['email'] and $_POST['password'] regardless of the request method, which throws those errors.
Solution:
First, check if the request is actually a POST request before accessing those variables. You can also use isset() to safely retrieve the values:
<?php session_start(); // Move this to the VERY TOP (critical for sessions and redirects) require_once('connection.php'); $email = $pwd = ''; // Only process if it's a POST request (i.e., user submitted the login form) if ($_SERVER['REQUEST_METHOD'] === 'POST') { $email = isset($_POST['email']) ? trim($_POST['email']) : ''; $pwd = isset($_POST['password']) ? trim($_POST['password']) : ''; } else { // If someone visits this page directly via GET, send them back to the login form header("Location: login.php"); exit; // Always exit after a header redirect }
2. Fixing the "Invalid Email or Password" Message (and Security Issues)
Your current code has two big problems that cause this false (or true) error, plus major security risks:
- MD5 is extremely insecure: It's outdated and easy to crack. Never use it for password storage.
- SQL Injection Vulnerability: You're directly inserting user input into your SQL query, which lets attackers take over your database.
- Session start is in the wrong place:
session_start()needs to be before any output (including HTML comments or whitespace) to work properly.
Solution:
First, make sure when you register users, you store hashed passwords using password_hash() (not MD5). For example, in your registration code:
$hashed_password = password_hash($user_password, PASSWORD_DEFAULT); // Store $hashed_password in the Password column of your register table
Then, update your login code to use prepared statements (to prevent SQL injection) and password_verify() to check the password:
// Inside the POST request check from above... if (!empty($email) && !empty($pwd)) { // Use a prepared statement to avoid SQL injection $sql = "SELECT ID, Email, Password FROM register WHERE Email = ?"; $stmt = mysqli_prepare($conn, $sql); mysqli_stmt_bind_param($stmt, "s", $email); mysqli_stmt_execute($stmt); $result = mysqli_stmt_get_result($stmt); if (mysqli_num_rows($result) > 0) { $row = mysqli_fetch_assoc($result); // Verify the password against the stored hash if (password_verify($pwd, $row['Password'])) { // Set session variables $_SESSION['id'] = $row["ID"]; $_SESSION['email'] = $row["Email"]; // Redirect to welcome page header("Location: welcome.php"); exit; } else { echo "Invalid email or password"; } } else { echo "Invalid email or password"; } } else { echo "Please enter both email and password"; }
3. Fixing login.php Not Loading
If login.php won't load at all, check these common issues:
- File Path & Spelling: Make sure
login.phpexists in your server's root directory (same folder aslogin_code.phpandconnection.php). Double-check for typos (e.g.,Login.phpvslogin.php—some servers are case-sensitive). - Server Configuration: Confirm USBWebserver is running correctly, and its root directory is set to
USBWebserver v8.6\root(your path looks correct, but it's worth verifying). - Login Form Setup: Ensure
login.phphas a valid form that points tologin_code.phpwith the POST method. Example form code:
<!-- Inside login.php --> <form action="login_code.php" method="POST"> <div> <label for="email">Email:</label> <input type="email" id="email" name="email" required> </div> <div> <label for="password">Password:</label> <input type="password" id="password" name="password" required> </div> <button type="submit">Log In</button> </form>
Full Fixed Login Code
Putting it all together, your login_code.php should look like this:
<?php session_start(); require_once('connection.php'); $email = $pwd = ''; if ($_SERVER['REQUEST_METHOD'] === 'POST') { $email = isset($_POST['email']) ? trim($_POST['email']) : ''; $pwd = isset($_POST['password']) ? trim($_POST['password']) : ''; if (!empty($email) && !empty($pwd)) { $sql = "SELECT ID, Email, Password FROM register WHERE Email = ?"; $stmt = mysqli_prepare($conn, $sql); mysqli_stmt_bind_param($stmt, "s", $email); mysqli_stmt_execute($stmt); $result = mysqli_stmt_get_result($stmt); if (mysqli_num_rows($result) > 0) { $row = mysqli_fetch_assoc($result); if (password_verify($pwd, $row['Password'])) { $_SESSION['id'] = $row["ID"]; $_SESSION['email'] = $row["Email"]; header("Location: welcome.php"); exit; } else { echo "Invalid email or password"; } } else { echo "Invalid email or password"; } } else { echo "Please fill in both fields"; } } else { header("Location: login.php"); exit; } ?>
内容的提问来源于stack exchange,提问作者Nadia Rashid

