PHP登录表单SQL语法错误求助:新手开发遇数据库查询失败
Hey there! Let's break down the problems with your code and fix them one by one:
1. Immediate SQL Syntax Errors
The error message points directly to two easy-to-fix mistakes in your query:
- You wrote
select * forminstead ofselect * from(typo with "form" instead of "from") - Your table name
signup-formhas a hyphen, which MySQL/MariaDB interprets as a subtraction operator. You need to wrap it in backticks`to treat it as a valid table name.
Here's the corrected query line (before addressing bigger security and functionality issues):
$query = mysql_query("select * from `signup-form` where email = '$email' AND psw = '$psw'") or die ("Failed to query database".mysql_error());
2. Stop Using Deprecated mysql_* Functions
The mysql_* functions were removed entirely in PHP 7—they're insecure, unsupported, and will break your code on modern PHP versions. You should switch to MySQLi (the improved MySQL extension) or PDO instead. We'll use MySQLi in the fixed code below, and also add protection against SQL injection (a critical security flaw in your current code).
3. Never Store Plain Text Passwords
Storing passwords as plain text is a massive security risk. You should hash passwords when users sign up using password_hash(), then verify the hash with password_verify() during login. I've included this in the corrected code.
4. Fix the Broken Login Logic
Your current check if($email=="$email" && $psw=="$psw") is completely useless—it will always be true, even if no matching user exists in the database. We need to check if the query actually returned a valid user row instead.
Full Corrected Code
<?php // Use MySQLi instead of deprecated mysql_* functions $con = mysqli_connect("localhost", "root", "", "jobportal"); // Check database connection if (mysqli_connect_errno()) { echo "Failed to connect to MySQL: " . mysqli_connect_error(); exit(); } if(isset($_POST['login'])) { $email = $_POST['email']; $psw = $_POST['psw']; // Use prepared statements to block SQL injection attacks $stmt = mysqli_prepare($con, "select psw from `signup-form` where email = ?"); mysqli_stmt_bind_param($stmt, "s", $email); mysqli_stmt_execute($stmt); mysqli_stmt_store_result($stmt); // Check if a user with this email exists if(mysqli_stmt_num_rows($stmt) > 0) { mysqli_stmt_bind_result($stmt, $hashed_password); mysqli_stmt_fetch($stmt); // Verify the submitted password against the stored hash if(password_verify($psw, $hashed_password)) { // Login successful - redirect to homepage header('location:index.php'); exit(); // Always exit after a header redirect to stop further code execution } else { echo "Invalid email or password"; } } else { echo "Invalid email or password"; } mysqli_stmt_close($stmt); } mysqli_close($con); ?>
Key Notes:
- Prepared Statements: The
?placeholder prevents attackers from using SQL injection to steal or modify your database data. - Password Hashing: When users sign up, make sure you store
password_hash($_POST['psw'], PASSWORD_DEFAULT)instead of the plain text password—this matches the verification step in the login code. - Redirect Best Practice: Adding
exit()afterheader()ensures no extra code runs after the redirect, which can prevent unexpected bugs.
内容的提问来源于stack exchange,提问作者Umar

