PHP登录脚本提交时触发500错误,新手开发者求助
Hey there! Let's break down what's causing that HTTP 500 error and fix your login code step by step.
Core Issue: Mixing MySQLi and Deprecated MySQL Extensions
Your code uses mysqli_connect() to establish a database connection, but then tries to use old, deprecated mysql_query() and mysql_num_rows() functions. These two extension families don't work together—this mismatch triggers a fatal PHP error that's causing the HTTP 500 response.
First: Enable Error Debugging
To see exactly what's going wrong (instead of just a generic 500 error), add these lines at the very top of your login.php file (this is for development only—remove it when you go live):
ini_set('display_errors', 1); ini_set('display_startup_errors', 1); error_reporting(E_ALL);
Fixed Login PHP Code
Here's your code updated to use consistent MySQLi functions, plus critical security improvements to prevent SQL injection:
<?php // Enable debug errors (remove in production) ini_set('display_errors', 1); ini_set('display_startup_errors', 1); error_reporting(E_ALL); DEFINE ('DB_USER', 'hiddenforsecurity'); DEFINE ('DB_PSWD', 'hiddenforsecurity'); DEFINE ('DB_HOST', 'hiddenforsecurity'); DEFINE ('DB_NAME', 'hiddenforsecurity'); // Use null coalescing to avoid "undefined index" warnings $email = $_POST['email'] ?? ''; $password = $_POST['password'] ?? ''; if($email && $password){ $dbcon = mysqli_connect(DB_HOST, DB_USER, DB_PSWD, DB_NAME) or die("Can't connect: " . mysqli_connect_error()); // Use prepared statements to prevent SQL injection (critical!) $stmt = mysqli_prepare($dbcon, "SELECT * FROM users WHERE email = ?"); mysqli_stmt_bind_param($stmt, "s", $email); mysqli_stmt_execute($stmt); $result = mysqli_stmt_get_result($stmt); $numrows = mysqli_num_rows($result); if($numrows != 0){ echo "Account Located"; // Add password verification here (see note below!) } else { die("That user doesn't exist"); } // Clean up connections mysqli_stmt_close($stmt); mysqli_close($dbcon); } else { die("Please enter an email and a password."); } ?>
Critical Additional Notes for New PHP Developers
- Never store plain-text passwords: Your current code only checks if the account exists. For full login functionality, you need to verify the password. Always store hashed passwords using
password_hash()when creating accounts, then usepassword_verify()to check them at login:// Example password verification (add after fetching user data) $user = mysqli_fetch_assoc($result); if(password_verify($password, $user['password'])){ echo "Login successful!"; // Start a session, redirect to dashboard, etc. } else { die("Incorrect password"); } - SQL injection is a huge risk: Directly inserting user input into your SQL query (like your original
WHERE email='$email') lets attackers manipulate your database. Prepared statements (used in the fixed code) eliminate this risk. - MAMP-specific checks: Ensure your MAMP MySQL server is running, and that your database credentials (DB_USER, DB_PSWD, etc.) match what's set in MAMP's MySQL settings.
内容的提问来源于stack exchange,提问作者chaserobbins

