PHP MySQLi简易登录功能报错求助:mysqli_query()警告问题
Hey Dave, let's figure out why that mysqli_query() error is popping up for your login system. That warning usually points to either a messed-up database connection or a wonky SQL query—let's walk through fixing this step by step.
The most common culprit here is a failed or missing database connection. If mysqli_query() doesn't get a valid connection object, it'll throw that error immediately. Let's add proper connection checking to your code:
// Replace these with your actual database credentials $host = 'localhost'; $db_user = 'your_db_username'; $db_pass = 'your_db_password'; $db_name = 'your_database_name'; // Create the connection $conn = mysqli_connect($host, $db_user, $db_pass, $db_name); // Critical: Check if the connection worked if (!$conn) { die("Connection failed hard: " . mysqli_connect_error()); }
If this throws an error, you know the problem is with your DB credentials or server setup—not the login logic itself.
Even though you said you'll handle injection later, directly stuffing variables into your SQL string is probably causing syntax errors (think: if your test password has a single quote, it breaks the query). Let's fix this with prepared statements—they'll fix the syntax issue and get you ahead on security:
// Your test login variables $username = "test_user"; $password = "test_password"; // Prepare the query (replace 'users' with your actual table name) $stmt = mysqli_prepare($conn, "SELECT id FROM users WHERE username = ? AND password = ?"); // Bind your variables to the query (ss = two string values) mysqli_stmt_bind_param($stmt, "ss", $username, $password); // Run the query mysqli_stmt_execute($stmt); // Store the result so we can check for matches mysqli_stmt_store_result($stmt); // Check if we found a matching user if (mysqli_stmt_num_rows($stmt) > 0) { echo "Logged In!"; } else { echo "Invalid username or password"; } // Clean up resources (good practice!) mysqli_stmt_close($stmt); mysqli_close($conn);
Double-check that your table name (users) and column names (username, password) match exactly what's in your database—typos here are super common.
If you're still getting the warning, print the full error message to pinpoint the issue:
// If you're using a raw query (not prepared statements), add this: $query = "SELECT * FROM users WHERE username = '$username' AND password = '$password'"; $result = mysqli_query($conn, $query); if (!$result) { echo "Full Error Details: " . mysqli_error($conn); }
This will tell you if it's a syntax error, missing table, or something else entirely.
- Is the
passwordin your database stored as plain text? If you hashed it (which you should eventually), you'll need to usepassword_verify()instead of direct comparison:// Example for hashed passwords $stmt = mysqli_prepare($conn, "SELECT password FROM users WHERE username = ?"); mysqli_stmt_bind_param($stmt, "s", $username); mysqli_stmt_execute($stmt); mysqli_stmt_bind_result($stmt, $hashed_password); mysqli_stmt_fetch($stmt); if (password_verify($password, $hashed_password)) { echo "Logged In!"; } else { echo "Invalid username or password"; } - Are your test
$usernameand$passwordactually present in the database? It sounds obvious, but we've all been there.
内容的提问来源于stack exchange,提问作者Dave Tops

