PHP密码更新功能失效求助:哈希用户密码无法写入数据库
Hey there, let's figure out why your admin password update feature isn't writing to the database. I’ve dealt with tons of similar PHP/DB issues, so let’s walk through the most likely problems and fixes step by step:
1. First: Verify Form Data is Being Received
Before anything else, make sure your script is actually getting the new password and target user ID from the form. Add this debug code at the top of edit-accounts-process.php:
// Debug: Print all submitted POST data var_dump($_POST); exit;
If you don’t see values for your new password field (e.g., new_password) or user ID (e.g., user_id), double-check your form’s name attributes—they need to match exactly what you’re trying to pull from $_POST.
2. Check Password Hashing Implementation
You’re using password hashing (great call!), but make sure you’re using PHP’s secure, recommended function correctly. Avoid outdated methods like md5() or sha1(). The right approach is:
// Make sure the new password isn't empty before hashing if (!empty($_POST['new_password'])) { $hashed_password = password_hash($_POST['new_password'], PASSWORD_DEFAULT); } else { // Handle empty password error die("Error: New password cannot be empty"); }
If you’re hashing an empty string or misusing password_hash(), it could generate invalid values that fail to write to the database.
3. Fix Your Database Update Query
This is where most issues happen:
Ensure Your SQL Has a WHERE Clause
Without a WHERE condition, you’ll update every user’s password (super dangerous!) or your database might block the query entirely. A correct UPDATE statement should look like:
$sql = "UPDATE users SET password = ? WHERE id = ?";
Use Prepared Statements (Critical for Security & Syntax)
Always use prepared statements to avoid SQL injection and syntax errors. Here’s how to execute it properly with PDO:
// Assuming you have a PDO connection set up $stmt = $pdo->prepare($sql); // Bind the hashed password and user ID to the query $success = $stmt->execute([$hashed_password, $_POST['user_id']]); // Debug: Check if the query ran and affected rows if ($success) { $rows_updated = $stmt->rowCount(); if ($rows_updated > 0) { echo "Password updated successfully!"; } else { echo "No rows updated—either the user ID doesn't exist, or the new password is identical to the old one."; } } else { // Print SQL error details print_r($stmt->errorInfo()); }
If rowCount() returns 0, either the user ID is invalid, or the database skipped the update because the password value didn’t change (some DBs do this to save resources).
4. Confirm Database Connection & Permissions
Make sure your database user has UPDATE permissions for the users table. Also, add error handling to your connection to catch issues early:
try { $pdo = new PDO("mysql:host=localhost;dbname=your_database_name", "db_user", "db_password"); $pdo->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); } catch(PDOException $e) { die("Database connection failed: " . $e->getMessage()); }
If the connection fails, this will tell you exactly why.
5. Check Form Submission Method & Redirects
Ensure your form uses method="POST" (not GET). Also, if you’re redirecting immediately after the update, you might miss error messages—comment out the redirect temporarily to see the debug output.
If you’ve tried all this and still can’t get it working, share your full edit-accounts-process.php code and the corresponding form HTML, and I’ll help you spot the exact issue.
内容的提问来源于stack exchange,提问作者Mark Lim

