如何修改login.php以添加多组用户名与密码?
How to Add Multiple Username-Password Pairs to Your login.php
Hey there! Let's adjust your login script to support multiple valid user credentials smoothly. The main fix is swapping that single user array with a collection of user entries, then checking against them properly. Here's the revised, working code:
<?php session_start(); // Move this to the top to avoid "headers already sent" errors $error = ""; if(isset($_POST['username'], $_POST['password'])){ // Define all your username-password pairs here $valid_users = [ ["user" => "username1", "pass" => "password1"], ["user" => "username2", "pass" => "password2"], ["user" => "username3", "pass" => "password3"] // Add as many pairs as you need ]; $username = $_POST['username']; $pass = $_POST['password']; $is_valid = false; // Check each user against the submitted credentials foreach($valid_users as $user){ if($username === $user['user'] && $pass === $user['pass']){ $is_valid = true; break; // Stop checking once we find a match } } if($is_valid){ $_SESSION['username'] = $username; // Store the logged-in user in session header("Location: dashboard.php"); // Redirect to your protected page exit; // Prevent further script execution after redirect } else { $error = "Invalid username or password!"; } } ?> <!-- Keep your existing login form, and display errors if needed --> <?php if(!empty($error)): ?> <p style="color: red;"><?php echo $error; ?></p> <?php endif; ?> <form method="post"> Username: <input type="text" name="username" required><br> Password: <input type="password" name="password" required><br> <input type="submit" value="Login"> </form>
Quick Breakdown of Changes:
- Moved
session_start()to the very top: This avoids common "headers already sent" errors, since session headers can't be sent after any output (like HTML or whitespace). $valid_usersarray: This is where you'll add all your user credentials—just insert new["user" => "...", "pass" => "..."]entries as needed.- Loop validation: We check each user in the list until we find a match, then mark the login as valid.
- Redirect on success: After validating, we send the user to a protected page (replace
dashboard.phpwith your actual page) and useexitto stop any extra code from running.
Critical Security Note:
Storing plain-text passwords like this is highly insecure for production use. For a real-world app, you should:
- Hash passwords with
password_hash()when creating user accounts - Verify them using
password_verify()instead of direct string comparison
Example of secure verification:
// When creating a user, store the hashed password: // $hashed_pass = password_hash("password1", PASSWORD_DEFAULT); // In login, replace the direct pass check with: if($username === $user['user'] && password_verify($pass, $user['pass'])){ $is_valid = true; }
内容的提问来源于stack exchange,提问作者Firman
相关产品推荐
相关产品推荐

