重置密码链接可重置密码,但新密码无法被login.inc.php识别求助
Hey there! Let's break down why your newly reset password isn't working with the login.inc.php script. Since you confirmed the reset flow handles password reset, token clearing, and hashing, the problem almost certainly lies in a mismatch between how you're handling the password during reset vs. login. Here are the key areas to check:
1. Mismatched Hashing/Verification Methods
The most common culprit here is using inconsistent functions for hashing and verifying passwords.
- In
reset-password.php, make sure you're using PHP's built-inpassword_hash()function (e.g.,$hashedPwd = password_hash($newPassword, PASSWORD_DEFAULT);). - In
login.inc.php, you must usepassword_verify()to check the input password against the stored hash—do not re-hash the login password and compare directly. Sincepassword_hash()generates a unique salt each time, two hashes of the same password will never match. - Example of wrong login logic (avoid this):
// This will fail every time! $hashedLoginPwd = password_hash($_POST['password'], PASSWORD_DEFAULT); if ($hashedLoginPwd === $userHashFromDb) { ... } - Correct login logic:
if (password_verify($_POST['password'], $userHashFromDb)) { // Login successful }
2. Truncated Password Hash in Database
password_hash() (with PASSWORD_DEFAULT) generates a 60-character hash. If your database's password column is shorter than 60 characters (e.g., VARCHAR(50)), the hash will get truncated during storage.
- Check your user table's password column—set it to
VARCHAR(255)to accommodate future hashing algorithm changes and avoid truncation.
3. Inconsistent Input Handling
Double-check if you're processing the password differently in reset vs. login:
- Did you use
trim()on the new password inreset-password.phpbut forget to apply it inlogin.inc.php? If a user accidentally adds a space when resetting, the hashed password will include that space—if login doesn't trim, the verification will fail. - Are you using sanitization functions like
htmlspecialchars()on one side but not the other? For example, if you sanitize the password before hashing it during reset, but use the raw input during login verification, the values won't match.
4. Hidden Errors in Login Script
Your login script might be failing silently due to suppressed errors or incorrect logic:
- Temporarily enable error reporting at the top of
login.inc.phpto catch hidden issues:error_reporting(E_ALL); ini_set('display_errors', 1); - Verify that your database query in
login.inc.phpis correctly fetching the user's hash. Check for typos in column names (e.g.,passwordvs.pwd) or incorrect WHERE clauses (e.g., using the wrong identifier like username instead of email). - Add debug echoes to confirm you're pulling the correct hash from the database. For example:
This will tell you immediately if the verification itself is failing or if the issue is elsewhere.echo "Stored hash: " . $userHashFromDb . "<br>"; echo "Input password: " . $_POST['password'] . "<br>"; echo "Verification result: " . (password_verify($_POST['password'], $userHashFromDb) ? "TRUE" : "FALSE");
5. Incorrect User Targeted During Reset
Double-check that reset-password.php is updating the correct user's password. Confirm that the token you're using to identify the user maps to the right account, then check the database directly to ensure that user's password hash was actually updated to the new value.
Start with these checks—odds are one of them is the root cause!
内容的提问来源于stack exchange,提问作者user9098801

