PHP CodeIgniter框架中password_verify验证MySQL哈希密码异常
Hey there! Let's troubleshoot why your password_verify() function isn't playing nice with your CodeIgniter + MySQL setup. I’ve dealt with this exact headache before, so here are the most likely issues to check:
1. Database Field Truncation (The #1 Culprit)
You mentioned setting the password field to VARCHAR(255)—double-check this is actually the case in your MySQL table. If the field was accidentally set to a shorter length (like VARCHAR(100)), the PASSWORD_DEFAULT hash (which is 60 characters for bcrypt, but could grow with future algorithm updates) gets chopped off mid-string. A truncated hash will never validate correctly.
To confirm: Run this SQL query on your database to verify the field definition:
DESCRIBE users;
Make sure the password row shows VARCHAR(255) under the Type column.
2. Missing or Incorrect Password Hashing in insert_user
Let’s make sure you’re actually hashing the password before storing it. It’s easy to overlook this step! Your insert_user method should look something like this:
public function insert_user($emailAddress, $password, $firstName, $lastName){ $data = array( 'email' => $emailAddress, 'password' => password_hash($password, PASSWORD_DEFAULT), // Critical line! 'first_name' => $firstName, 'last_name' => $lastName ); return $this->db->insert('users', $data); }
Double-check that you’re passing the raw user-provided $password to password_hash, not a mistyped variable (like $emailAddress by accident).
3. Botched Password Verification Logic
When verifying, you need to first fetch the stored hash from the database, then pass it to password_verify (not the other way around!). Here’s a correct implementation of a verification method in your User_model:
public function verify_user($emailAddress, $inputPassword){ // Fetch the user by email $user = $this->db->get_where('users', ['email' => $emailAddress])->row(); // Check if user exists AND the password matches if($user && password_verify($inputPassword, $user->password)){ return $user; // Verification successful } return false; // Invalid credentials }
Avoid modifying the stored hash in any way (like trimming or escaping it) before passing it to password_verify—this will break the match.
4. Character Encoding or Auto-Escape Issues
CodeIgniter’s Active Record usually handles escaping correctly, but if your database connection is using a wonky character set (like latin1 instead of utf8mb4), it could corrupt the hash. Check your application/config/database.php file to ensure:
$db['default']['char_set'] = 'utf8mb4'; $db['default']['dbcollat'] = 'utf8mb4_general_ci';
Also, never manually escape the hashed password before inserting it—let CodeIgniter handle that.
5. Accidental Whitespace in Passwords
Users sometimes type extra spaces before/after their password, and if you don’t normalize input during registration and verification, the hash won’t match. Consider trimming the password in both steps:
// During registration $hashedPassword = password_hash(trim($password), PASSWORD_DEFAULT); // During verification $isValid = password_verify(trim($inputPassword), $storedHash);
Start with checking the database field length first—it’s the most common fix. If that’s good, move on to verifying your hashing and verification code line by line.
内容的提问来源于stack exchange,提问作者Java Hermit

