You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP登录表单SQL语法错误求助:新手开发遇数据库查询失败

Fixing Your Login Form SQL & Security Issues

Hey there! Let's break down the problems with your code and fix them one by one:

1. Immediate SQL Syntax Errors

The error message points directly to two easy-to-fix mistakes in your query:

  • You wrote select * form instead of select * from (typo with "form" instead of "from")
  • Your table name signup-form has a hyphen, which MySQL/MariaDB interprets as a subtraction operator. You need to wrap it in backticks ` to treat it as a valid table name.

Here's the corrected query line (before addressing bigger security and functionality issues):

$query = mysql_query("select * from `signup-form` where email = '$email' AND psw = '$psw'") or die ("Failed to query database".mysql_error());

2. Stop Using Deprecated mysql_* Functions

The mysql_* functions were removed entirely in PHP 7—they're insecure, unsupported, and will break your code on modern PHP versions. You should switch to MySQLi (the improved MySQL extension) or PDO instead. We'll use MySQLi in the fixed code below, and also add protection against SQL injection (a critical security flaw in your current code).

3. Never Store Plain Text Passwords

Storing passwords as plain text is a massive security risk. You should hash passwords when users sign up using password_hash(), then verify the hash with password_verify() during login. I've included this in the corrected code.

4. Fix the Broken Login Logic

Your current check if($email=="$email" && $psw=="$psw") is completely useless—it will always be true, even if no matching user exists in the database. We need to check if the query actually returned a valid user row instead.

Full Corrected Code

<?php
// Use MySQLi instead of deprecated mysql_* functions
$con = mysqli_connect("localhost", "root", "", "jobportal");

// Check database connection
if (mysqli_connect_errno()) {
    echo "Failed to connect to MySQL: " . mysqli_connect_error();
    exit();
}

if(isset($_POST['login'])) {
    $email = $_POST['email'];
    $psw = $_POST['psw'];

    // Use prepared statements to block SQL injection attacks
    $stmt = mysqli_prepare($con, "select psw from `signup-form` where email = ?");
    mysqli_stmt_bind_param($stmt, "s", $email);
    mysqli_stmt_execute($stmt);
    mysqli_stmt_store_result($stmt);

    // Check if a user with this email exists
    if(mysqli_stmt_num_rows($stmt) > 0) {
        mysqli_stmt_bind_result($stmt, $hashed_password);
        mysqli_stmt_fetch($stmt);
        
        // Verify the submitted password against the stored hash
        if(password_verify($psw, $hashed_password)) {
            // Login successful - redirect to homepage
            header('location:index.php');
            exit(); // Always exit after a header redirect to stop further code execution
        } else {
            echo "Invalid email or password";
        }
    } else {
        echo "Invalid email or password";
    }

    mysqli_stmt_close($stmt);
}

mysqli_close($con);
?>

Key Notes:

  • Prepared Statements: The ? placeholder prevents attackers from using SQL injection to steal or modify your database data.
  • Password Hashing: When users sign up, make sure you store password_hash($_POST['psw'], PASSWORD_DEFAULT) instead of the plain text password—this matches the verification step in the login code.
  • Redirect Best Practice: Adding exit() after header() ensures no extra code runs after the redirect, which can prevent unexpected bugs.

内容的提问来源于stack exchange,提问作者Umar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 07:50:49