网站登录失败排查:疑似elseif语句代码错误求助
Hey there! Let's break down your login error issue and fix those missing error prompts step by step.
First, looking at your code snippet, there are several clear issues that explain why you're not seeing any error feedback for empty fields, wrong credentials, etc.:
1. Incomplete Redirect Path
Your empty field check uses header("Location: ../index."); — the path is missing a file extension (like .php), which will cause the redirect to fail silently. Users won't be sent back to the login page at all, let alone see an error message.
2. No Error Messaging Mechanism
Even if the redirect worked, you're not passing any parameters to tell the frontend what went wrong. You need to add a query string to the redirect URL so your login page can display the right prompt. For example:
header("Location: ../index.php?error=emptyfields"); exit(); // Always exit after a header redirect to stop script execution
3. Unfinished Conditional Logic
Your code cuts off after the empty field check — there's no elseif or else block to handle valid credentials, missing users, or wrong passwords. The logic is incomplete, so those error cases never get triggered.
Here's a complete, secure version of your login logic to fill in the gaps:
<?php session_start(); if (isset($_POST['submit'])) { include 'dbh.inc.php'; $uid = mysqli_real_escape_string($conn, $_POST['uid']); $pwd = mysqli_real_escape_string($conn, $_POST['pwd']); // Check for empty fields if (empty($uid) || empty($pwd)) { header("Location: ../index.php?error=emptyfields"); exit(); } else { // Prepare SQL to find user (prevents SQL injection) $sql = "SELECT * FROM users WHERE user_uid=? OR user_email=?;"; $stmt = mysqli_stmt_init($conn); if (!mysqli_stmt_prepare($stmt, $sql)) { header("Location: ../index.php?error=sqlerror"); exit(); } else { // Bind user input to the prepared statement mysqli_stmt_bind_param($stmt, "ss", $uid, $uid); mysqli_stmt_execute($stmt); $result = mysqli_stmt_get_result($stmt); // Check if user exists if ($row = mysqli_fetch_assoc($result)) { // Verify hashed password (never store plain text passwords!) $pwdCheck = password_verify($pwd, $row['user_pwd']); if (!$pwdCheck) { header("Location: ../index.php?error=wrongpwd"); exit(); } elseif ($pwdCheck) { // Set session variables for logged-in user $_SESSION['userId'] = $row['user_id']; $_SESSION['userUid'] = $row['user_uid']; header("Location: ../index.php?login=success"); exit(); } else { header("Location: ../index.php?error=wrongpwd"); exit(); } } else { header("Location: ../index.php?error=nouser"); exit(); } } } } else { // Redirect if someone accesses this script directly (not via form submit) header("Location: ../index.php"); exit(); }
Key Takeaways to Fix Your Issue:
- Always add
exit();afterheader()redirects to stop the script from running further - Use prepared statements (like
mysqli_stmt_*functions) to avoid SQL injection - Store passwords with
password_hash()and verify withpassword_verify()(never compare plain text!) - Add query parameters to redirect URLs so your frontend can display specific error messages (e.g., check
$_GET['error']on your login page and show a message like "Please fill in all fields")
With these changes, you'll start seeing the proper error prompts for empty fields, wrong passwords, and non-existent users.
内容的提问来源于stack exchange,提问作者Šarūnas Zakarevičius

