PHP简易登录系统无法匹配数据库条目问题求助
Let’s walk through the most likely reasons your login system is failing even when the user exists in the database, and fix them step by step:
1. Password Encryption Mismatch (Most Common Culprit)
Your login code encrypts the submitted password with md5($password), but if your registration logic doesn’t do the exact same thing, the stored password in the database won’t match the encrypted value you’re querying with.
- For example: If you saved the password as plain text during registration, comparing it to an MD5-hashed value will always fail.
- Fix: Check your registration code to ensure it runs
md5($password)before storing the password in the database.
Pro Tip: MD5 is no longer secure—switch to PHP’s built-inpassword_hash()andpassword_verify()for safer authentication:// Registration: Store this hashed password in your database $hashed_password = password_hash($_POST['passwordR'], PASSWORD_DEFAULT); // Login: Verify without rehashing the input $sql = "SELECT password FROM MyGuests WHERE username='$login_username'"; $result = mysqli_query($conn, $sql); $row = mysqli_fetch_array($result, MYSQLI_ASSOC); if (password_verify($_POST['passwordL'], $row['password'])) { // Login successful }
2. Variable Overwriting Confusion
You’re reusing the $username and $password variables—first for database connection credentials, then for login form input. While this doesn’t break the current connection, it’s messy and can lead to unexpected behavior if you reuse these variables later.
- Fix: Rename your login-specific variables to avoid overlap:
// Use distinct variable names for login input $login_username = $_POST['usernameL']; $login_password = $_POST['passwordL']; // Update all references in your query $sql = "SELECT id FROM MyGuests WHERE username='$login_username' and password='$login_password'";
3. Case Sensitivity in Table/Field Names
MySQL is case-sensitive on Linux/Unix servers (but not Windows). If your database table is named myguests (lowercase) but your SQL uses MyGuests, or your password field is Password instead of password, the query will return no results.
- Fix: Double-check your database structure (via phpMyAdmin or a database client) to ensure your SQL matches the exact table and field names, including capitalization.
4. Debug the Actual SQL Query
Sometimes the generated SQL isn’t what you expect. Print the query before executing it to see if variables are being escaped or replaced incorrectly:
$login_username = mysqli_real_escape_string($conn, $login_username); $login_password = md5($login_password); $sql = "SELECT id FROM MyGuests WHERE username='$login_username' and password='$login_password'"; // Debug line: Copy this query and run it directly in your database echo "Executing query: " . $sql; $result = mysqli_query($conn, $sql);
If running the printed query directly in your database returns a row, the issue is in your PHP logic; if not, your variables don’t match the stored data.
5. Check for SQL Errors
A malformed SQL query will return false instead of a result set, which triggers your "Incorrect credentials" error. Add error handling to catch this:
$result = mysqli_query($conn, $sql); if (!$result) { die("SQL Error: " . mysqli_error($conn)); }
This will show you exactly what’s wrong with your query (like a missing quote or misspelled field name).
内容的提问来源于stack exchange,提问作者Jason Smith

