You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP登录脚本提交时触发500错误,新手开发者求助

Hey there! Let's break down what's causing that HTTP 500 error and fix your login code step by step.

Core Issue: Mixing MySQLi and Deprecated MySQL Extensions

Your code uses mysqli_connect() to establish a database connection, but then tries to use old, deprecated mysql_query() and mysql_num_rows() functions. These two extension families don't work together—this mismatch triggers a fatal PHP error that's causing the HTTP 500 response.

First: Enable Error Debugging

To see exactly what's going wrong (instead of just a generic 500 error), add these lines at the very top of your login.php file (this is for development only—remove it when you go live):

ini_set('display_errors', 1);
ini_set('display_startup_errors', 1);
error_reporting(E_ALL);

Fixed Login PHP Code

Here's your code updated to use consistent MySQLi functions, plus critical security improvements to prevent SQL injection:

<?php
// Enable debug errors (remove in production)
ini_set('display_errors', 1);
ini_set('display_startup_errors', 1);
error_reporting(E_ALL);

DEFINE ('DB_USER', 'hiddenforsecurity'); 
DEFINE ('DB_PSWD', 'hiddenforsecurity'); 
DEFINE ('DB_HOST', 'hiddenforsecurity'); 
DEFINE ('DB_NAME', 'hiddenforsecurity'); 

// Use null coalescing to avoid "undefined index" warnings
$email = $_POST['email'] ?? '';
$password = $_POST['password'] ?? '';

if($email && $password){
    $dbcon = mysqli_connect(DB_HOST, DB_USER, DB_PSWD, DB_NAME) or die("Can't connect: " . mysqli_connect_error());
    
    // Use prepared statements to prevent SQL injection (critical!)
    $stmt = mysqli_prepare($dbcon, "SELECT * FROM users WHERE email = ?");
    mysqli_stmt_bind_param($stmt, "s", $email);
    mysqli_stmt_execute($stmt);
    $result = mysqli_stmt_get_result($stmt);
    $numrows = mysqli_num_rows($result);

    if($numrows != 0){
        echo "Account Located";
        // Add password verification here (see note below!)
    } else {
        die("That user doesn't exist");
    }

    // Clean up connections
    mysqli_stmt_close($stmt);
    mysqli_close($dbcon);
} else {
    die("Please enter an email and a password.");
}
?>

Critical Additional Notes for New PHP Developers

  • Never store plain-text passwords: Your current code only checks if the account exists. For full login functionality, you need to verify the password. Always store hashed passwords using password_hash() when creating accounts, then use password_verify() to check them at login:
    // Example password verification (add after fetching user data)
    $user = mysqli_fetch_assoc($result);
    if(password_verify($password, $user['password'])){
        echo "Login successful!";
        // Start a session, redirect to dashboard, etc.
    } else {
        die("Incorrect password");
    }
    
  • SQL injection is a huge risk: Directly inserting user input into your SQL query (like your original WHERE email='$email') lets attackers manipulate your database. Prepared statements (used in the fixed code) eliminate this risk.
  • MAMP-specific checks: Ensure your MAMP MySQL server is running, and that your database credentials (DB_USER, DB_PSWD, etc.) match what's set in MAMP's MySQL settings.

内容的提问来源于stack exchange,提问作者chaserobbins

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 03:33:26