网站登录无法读取数据库用户数据,存在用户却提示无用户求协助
Hey there, let's break down why your login system isn't pulling the user data even though the user exists in your database. I spot a few key issues in your code that are likely causing this problem:
1. Missing Database Connection in mysqli_query
This is the biggest red flag! The mysqli_query() function requires two arguments: first your database connection object (from connect.php), then your SQL query. Your current code only passes the query, so the database doesn't know which connection to use—meaning your query never actually runs successfully.
Fix:
Replace this line:
$result=mysqli_query($sql);
With this (use the actual connection variable name from your connect.php—common names are $conn, $db, or $link):
$result=mysqli_query($conn, $sql);
2. No Error Checking for the Query
Without checking if the query succeeded, you're flying blind. If there's a syntax error in your SQL or a column name mismatch, you'll never know. Add this right after your query to debug:
$result = mysqli_query($conn, $sql); if (!$result) { die("Query failed with error: " . mysqli_error($conn)); }
This will print the exact database error, which could confirm if your column names (officer_username, officer_password) are actually correct in your officers table.
3. Session Isn't Initialized
You're trying to set $_SESSION variables, but you never started the session! Add this line at the very top of your script (before any output):
session_start();
Without this, the session won't work, and your redirect logic will fail even if the login succeeds.
4. Password Handling Risks (and Potential Mismatch)
Right now, you're comparing passwords directly as plain text. If you ever hashed the password in the database (which you should for security), this comparison will fail. Even if you're using plain text, here's a more secure approach going forward:
- When creating a user, store the password with
password_hash():$hashed_pw = password_hash($user_password, PASSWORD_DEFAULT); // Insert $hashed_pw into officer_password column - When logging in, fetch the user by username first, then verify the password with
password_verify():// Only query by username first $sql = "SELECT * FROM officers WHERE officer_username = '$username'"; $result = mysqli_query($conn, $sql); if (mysqli_num_rows($result) == 1) { $userinfo = mysqli_fetch_assoc($result); // Verify password instead of comparing plain text if (password_verify($password, $userinfo['officer_password'])) { $_SESSION['login_user'] = $username; $_SESSION['role'] = $userinfo['role']; // Add exit() after header to stop script execution if ($userinfo['role'] == 'admin') { header('location:admin.php'); exit; } elseif ($userinfo['role'] == 'user') { header('location:user.php'); exit; } } else { echo "Incorrect password"; } } else { echo "No User Found by Given Information"; }
5. Minor: Redirects Need exit()
After using header('location:...'), always add exit; to prevent the rest of the script from running. This avoids unexpected behavior if the redirect doesn't happen immediately.
Putting it all together, your corrected script should look something like this (adjusting the connection variable to match your connect.php):
<?php session_start(); // Add this first include("connect.php"); if(isset($_POST['submit'])){ $username = $_POST['username']; $password = $_POST['password']; // Protect against SQL injection (note: mysqli_real_escape_string needs the connection too!) $username = mysqli_real_escape_string($conn, $username); $password = mysqli_real_escape_string($conn, $password); // stripcslashes and htmlspecialchars are unnecessary here if you're using prepared statements (even better security!) // Query only by username first (safer for password verification) $sql = "SELECT * FROM officers WHERE officer_username = '$username'"; $result = mysqli_query($conn, $sql); if (!$result) { die("Query failed: " . mysqli_error($conn)); } $row = mysqli_num_rows($result); if($row == 1){ $userinfo = mysqli_fetch_assoc($result); $role = $userinfo['role']; // Verify password if (password_verify($password, $userinfo['officer_password'])) { $_SESSION['login_user'] = $username; $_SESSION['role'] = $role; if($role == 'admin'){ header('location:admin.php'); exit; } elseif($role == 'user'){ header('location:user.php'); exit; } } else { echo "Incorrect password"; } } else { echo "No User Found by Given Information"; } } ?>
Start with fixing the mysqli_query connection issue first—that's almost certainly the main reason your query isn't returning any rows. Then add the error checking to confirm everything else is working.
内容的提问来源于stack exchange,提问作者natstv

