You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

咨询:能否将password_verify算法改为SHA1?如何适配SHA1密码登录

How to Adjust Your Login System for SHA1-Hashed Passwords

Got it, let’s break down exactly how to tweak your login system to work with SHA1-hashed passwords—since your accounts were created via the game (which uses SHA1) instead of your original register.php script.

Core Idea

Instead of using PHP’s modern password_verify() function (designed for bcrypt/Argon2 hashes), you’ll need to SHA1-encrypt the user’s input password during login and compare it directly to the SHA1 hash stored in your database.


Step 1: Update the Password Validation Logic

The key change is straightforward: when a user submits their password, run it through PHP’s sha1() function, then check if that encrypted string matches the password field in your users table for the given username.

Step 2: Securely Implement the Login Query

While your example uses a direct query, I’ll share a safer version using prepared statements to avoid SQL injection (a critical security best practice). Here’s a complete, working login.php example:

<?php
// Include config file
require_once 'config.php';

// Define variables and initialize with empty values
$username = $password = "";
$username_err = $password_err = $login_err = "";

// Processing form data when form is submitted
if($_SERVER["REQUEST_METHOD"] == "POST"){

    // Validate username
    if(empty(trim($_POST["username"]))){
        $username_err = "Please enter your username.";
    } else{
        $username = trim($_POST["username"]);
    }

    // Validate password
    if(empty(trim($_POST["password"]))){
        $password_err = "Please enter your password.";
    } else{
        $password = trim($_POST["password"]);
    }

    // Check credentials if no errors
    if(empty($username_err) && empty($password_err)){
        // Prepare a safe select statement (prevents SQL injection)
        $sql = "SELECT id, username, password FROM users WHERE username = ?";

        if($stmt = mysqli_prepare($link, $sql)){
            // Bind username as a parameter
            mysqli_stmt_bind_param($stmt, "s", $param_username);
            $param_username = $username;

            // Execute the query
            if(mysqli_stmt_execute($stmt)){
                // Store the result to check if username exists
                mysqli_stmt_store_result($stmt);

                if(mysqli_stmt_num_rows($stmt) == 1){
                    // Fetch the stored SHA1 hash from the database
                    mysqli_stmt_bind_result($stmt, $id, $username, $stored_sha1_password);
                    mysqli_stmt_fetch($stmt);

                    // Compare the SHA1 of the input password to the stored hash
                    if(sha1($password) === $stored_sha1_password){
                        // Password matches: start session and redirect
                        session_start();
                        $_SESSION["loggedin"] = true;
                        $_SESSION["id"] = $id;
                        $_SESSION["username"] = $username;

                        header("location: welcome.php");
                        exit;
                    } else{
                        // Invalid password error
                        $login_err = "Invalid username or password.";
                    }
                } else{
                    // Username not found error
                    $login_err = "Invalid username or password.";
                }
            } else{
                echo "Oops! Something went wrong. Please try again later.";
            }

            // Close the statement
            mysqli_stmt_close($stmt);
        }
    }

    // Close database connection
    mysqli_close($link);
}
?>

Key Notes

  • Security Warning: SHA1 is no longer considered cryptographically secure for password storage. Once you get this login system working, you should plan to migrate your users’ passwords to a stronger algorithm like bcrypt or Argon2 (you can do this gradually by re-hashing passwords on the next successful login).
  • Strict Comparison: Using === instead of == ensures the comparison is case-sensitive and avoids unexpected type coercion issues.
  • Error Handling: The example uses generic error messages for invalid credentials to prevent attackers from guessing valid usernames.

内容的提问来源于stack exchange,提问作者please help

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 10:36:05