You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在CodeIgniter中实现HTTP GET请求?附用户验证场景

看起来你想用CodeIgniter实现一个用户登录验证的API,通过GET请求传递用户名和密码来校验数据库中的用户记录对吧?我帮你完善代码并给出一些关键的安全建议:

基于CodeIgniter的用户登录验证实现

1. 完善控制器代码

你提供的控制器代码不完整,这里补全并优化成符合CodeIgniter规范的写法:

<?php
if(!defined("BASEPATH")) exit("No direct script access allowed");

class Login extends CI_Controller {

    public function __construct() {
        parent::__construct();
        // 提前加载模型和URL助手
        $this->load->model("login_model");
        $this->load->helper('url');
    }

    // 处理用户验证的方法,对应你的get_user请求逻辑
    public function get_user() {
        // 从GET请求中获取参数
        $username = $this->input->get('user');
        $password = $this->input->get('password');

        // 先做基础的参数校验
        if(empty($username) || empty($password)) {
            echo json_encode(['status' => 'error', 'message' => '用户名或密码不能为空']);
            return;
        }

        // 调用模型层的验证方法
        $user_info = $this->login_model->check_user($username, $password);

        // 返回JSON格式的结果
        if($user_info) {
            echo json_encode([
                'status' => 'success',
                'message' => '验证通过',
                'user' => $user_info
            ]);
        } else {
            echo json_encode([
                'status' => 'error',
                'message' => '用户名或密码错误'
            ]);
        }
    }
}
?>

2. 编写对应的模型文件

在application/models/目录下创建login_model.php,实现数据库查询的核心逻辑:

<?php
class Login_model extends CI_Model {

    public function __construct() {
        parent::__construct();
        // 加载数据库连接
        $this->load->database();
    }

    public function check_user($username, $password) {
        // 用CodeIgniter查询构造器,避免SQL注入风险
        $this->db->where('username', $username);
        // 注意:这里如果是明文密码直接匹配(不推荐!),实际项目一定要用加密存储
        $this->db->where('password', $password);
        $query = $this->db->get('user');

        // 返回查询到的用户数组,无匹配则返回false
        return $query->row_array() ?: false;
    }
}
?>

3. 请求访问方式

现在你可以通过这个URL发起请求(CodeIgniter会自动路由到Login控制器的get_user方法,不需要单独的get_user.php文件):
http://my.awesome.server/dev_api/index.php/login/get_user?user=steven&password=12345

关键安全优化建议

  • 密码加密存储:绝对不要在数据库中存明文密码!用户注册时用password_hash()生成加密密码,验证时用password_verify()比对,修改后的模型方法如下:
    public function check_user($username, $password) {
        $this->db->where('username', $username);
        $user = $this->db->get('user')->row_array();
        
        // 验证密码是否匹配
        if($user && password_verify($password, $user['password'])) {
            // 不要返回密码字段给前端
            unset($user['password']);
            return $user;
        }
        return false;
    }
    
  • 改用POST请求:登录请求用GET会把密码暴露在URL里,风险很高。建议改成POST方式,把$this->input->get()替换为$this->input->post(),然后通过表单或AJAX的POST方法传递参数。
  • 开启CSRF防护:如果是Web端登录,记得在CodeIgniter的配置文件config.php中开启CSRF防护,防止跨站请求伪造:
    $config['csrf_protection'] = TRUE;
    

内容的提问来源于stack exchange,提问作者anta40

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 11:46:28