咨询:能否将password_verify算法改为SHA1?如何适配SHA1密码登录
Got it, let’s break down exactly how to tweak your login system to work with SHA1-hashed passwords—since your accounts were created via the game (which uses SHA1) instead of your original register.php script.
Core Idea
Instead of using PHP’s modern password_verify() function (designed for bcrypt/Argon2 hashes), you’ll need to SHA1-encrypt the user’s input password during login and compare it directly to the SHA1 hash stored in your database.
Step 1: Update the Password Validation Logic
The key change is straightforward: when a user submits their password, run it through PHP’s sha1() function, then check if that encrypted string matches the password field in your users table for the given username.
Step 2: Securely Implement the Login Query
While your example uses a direct query, I’ll share a safer version using prepared statements to avoid SQL injection (a critical security best practice). Here’s a complete, working login.php example:
<?php // Include config file require_once 'config.php'; // Define variables and initialize with empty values $username = $password = ""; $username_err = $password_err = $login_err = ""; // Processing form data when form is submitted if($_SERVER["REQUEST_METHOD"] == "POST"){ // Validate username if(empty(trim($_POST["username"]))){ $username_err = "Please enter your username."; } else{ $username = trim($_POST["username"]); } // Validate password if(empty(trim($_POST["password"]))){ $password_err = "Please enter your password."; } else{ $password = trim($_POST["password"]); } // Check credentials if no errors if(empty($username_err) && empty($password_err)){ // Prepare a safe select statement (prevents SQL injection) $sql = "SELECT id, username, password FROM users WHERE username = ?"; if($stmt = mysqli_prepare($link, $sql)){ // Bind username as a parameter mysqli_stmt_bind_param($stmt, "s", $param_username); $param_username = $username; // Execute the query if(mysqli_stmt_execute($stmt)){ // Store the result to check if username exists mysqli_stmt_store_result($stmt); if(mysqli_stmt_num_rows($stmt) == 1){ // Fetch the stored SHA1 hash from the database mysqli_stmt_bind_result($stmt, $id, $username, $stored_sha1_password); mysqli_stmt_fetch($stmt); // Compare the SHA1 of the input password to the stored hash if(sha1($password) === $stored_sha1_password){ // Password matches: start session and redirect session_start(); $_SESSION["loggedin"] = true; $_SESSION["id"] = $id; $_SESSION["username"] = $username; header("location: welcome.php"); exit; } else{ // Invalid password error $login_err = "Invalid username or password."; } } else{ // Username not found error $login_err = "Invalid username or password."; } } else{ echo "Oops! Something went wrong. Please try again later."; } // Close the statement mysqli_stmt_close($stmt); } } // Close database connection mysqli_close($link); } ?>
Key Notes
- Security Warning: SHA1 is no longer considered cryptographically secure for password storage. Once you get this login system working, you should plan to migrate your users’ passwords to a stronger algorithm like bcrypt or Argon2 (you can do this gradually by re-hashing passwords on the next successful login).
- Strict Comparison: Using
===instead of==ensures the comparison is case-sensitive and avoids unexpected type coercion issues. - Error Handling: The example uses generic error messages for invalid credentials to prevent attackers from guessing valid usernames.
内容的提问来源于stack exchange,提问作者please help

