ASP.NET登录页连接AWS RDS后无法跳转首页,请求排查问题
Let's walk through the issues in your login code that's stopping the redirect to home.aspx, and fix them up properly:
1. Critical Typo in Password Check Query
In your Btnlogin_Click method, you made a mistake when creating the checkpsw command — you're using the original query (the count query) instead of the checkPasswordQuery you defined. This means you're not actually fetching the user's password from the database, so the password comparison will always fail, and the redirect never happens.
2. Unnecessary Password Recheck & SQL Injection Risk
You already ran a query to verify that the UserID + Password combination exists (the count(*) = 1 check). There's no need to run a second query to fetch the password again. Also, directly concatenating user input into SQL queries is a huge SQL injection vulnerability — always use parameterized queries to protect your database.
3. Poor Connection Management
You're manually opening/closing connections, but not using using statements to ensure connections are properly disposed of if an error occurs. This can lead to connection leaks over time.
4. Broken LoadData Method Logic
Your Page_Load calls LoadData("") on first load, which checks if the User table has any rows — if it does, it immediately redirects to home.aspx! That means users can't even see the login form because they're redirected before they can enter credentials. This method should be removed entirely unless you have a specific use case for it that's not related to login.
Fixed login.aspx.cs Code
using System; using System.Web.UI; using System.Web.UI.WebControls; using MySql.Data.MySqlClient; namespace Aname { public partial class login : System.Web.UI.Page { // RDS connection string (keep this secure — consider using web.config instead!) private static readonly string connectionString = @"Server=rds-mysql.xxxxxxxx.us-west-2.rds.amazonaws.com; Port=xxxx; Database=mydb; User Id=xxxx; password=xxxxx"; protected void Page_Load(object sender, EventArgs e) { // Removed the LoadData call since it was causing immediate redirect } protected void Btnlogin_Click(object sender, EventArgs e) { // Use using statements to auto-dispose connections/commands using (MySqlConnection sqlcon = new MySqlConnection(connectionString)) { sqlcon.Open(); // Parameterized query to avoid SQL injection string query = "SELECT COUNT(*) FROM mydb.User WHERE user_id = @UserId AND pass = @Password"; using (MySqlCommand cmd = new MySqlCommand(query, sqlcon)) { // Add parameters with user input cmd.Parameters.AddWithValue("@UserId", Txtid.Text.Trim()); cmd.Parameters.AddWithValue("@Password", TxtPsw.Text.Trim()); int matchCount = Convert.ToInt32(cmd.ExecuteScalar()); if (matchCount == 1) { // Store user ID in session and redirect Session["user_id"] = Txtid.Text.Trim(); Response.Redirect("~/home.aspx"); } else { // Generic error message (don't reveal if it's UserID or Password that's wrong) Response.Write("<script>alert('Invalid UserID or Password!');</script>"); } } } } } }
Additional Recommendations
- Store Connection String in Web.config: Never hardcode connection strings in your code. Move it to
web.configunder<connectionStrings>for easier management and security. - Use Secure Password Storage: Storing plain-text passwords in your database is a major security risk. Hash passwords using a strong algorithm like BCrypt when users register, and verify the hash during login instead of comparing plain text.
- Improve Error Handling: Instead of
Response.Write, use a label control on your login page to display error messages more cleanly.
内容的提问来源于stack exchange,提问作者Chan Myae Tun

