配置BCRYPT后,登录验证跳转空白页问题求助
Since you've confirmed passwords are being stored correctly in the database with bcrypt, the blank page on form submission to newlogin_check.php is almost certainly due to a silent error or flawed logic in your validation script. Let's break down the most common fixes step by step:
1. Enable Error Reporting First
Blank pages in PHP usually mean a fatal error is occurring but isn't being displayed. Add these lines at the very top of newlogin_check.php to see exactly what's going wrong:
ini_set('display_errors', 1); ini_set('display_startup_errors', 1); error_reporting(E_ALL);
This will surface issues like missing functions, undefined variables, or syntax errors that are currently being hidden.
2. Fix Bcrypt Verification Logic
It’s easy to carry over old MD5 habits here—make sure you’re using the correct bcrypt verification method. Never re-hash the user’s input password; use password_verify() directly with the raw input and the stored hash from your database:
Wrong (MD5-style logic that breaks bcrypt):
// Don't do this! $storedHash = $row['password']; $inputHash = bcrypt($_POST['password']); // Or worse, md5() if ($inputHash === $storedHash) { ... }
Correct Bcrypt Verification:
session_start(); // Don't forget to start the session first if using sessions $userInputPassword = $_POST['password']; $storedHash = // Fetch the bcrypt hash from your database for the user if (password_verify($userInputPassword, $storedHash)) { // Login successful - set session variables and redirect $_SESSION['user_id'] = $user['id']; // Replace with your user ID field header("Location: your-dashboard-page.php"); // Redirect to your desired page exit; // Always exit immediately after a header redirect! } else { // Login failed - redirect back with error header("Location: login.php?error=invalid_credentials"); exit; }
3. Check for Session or Redirect Mistakes
- If you’re using user sessions,
session_start();must be called before any output (including whitespace) innewlogin_check.php. - Always add
exit;ordie();right afterheader("Location: ...");—without this, PHP will continue executing the rest of the script, which can cause unexpected output or prevent the redirect from working properly.
4. Verify Database Fetch Logic
Make sure you’re actually retrieving the correct bcrypt hash from your database. Add error checking to your database query to catch issues like missing users or typos in field names:
// Example using PDO (adjust for your DB library) $stmt = $pdo->prepare("SELECT id, password FROM users WHERE email = ?"); $stmt->execute([$_POST['email']]); $user = $stmt->fetch(PDO::FETCH_ASSOC); if (!$user) { // No user found with that email header("Location: login.php?error=user_not_found"); exit; } // Now use $user['password'] for verification
5. Confirm PHP Version Compatibility
The password_hash() and password_verify() functions required for bcrypt were added in PHP 5.5. If your server is running an older version, these functions won’t exist, causing a fatal error. Check your PHP version with:
echo phpversion();
If it’s below 5.5, you’ll need to upgrade your server or use a bcrypt compatibility library (though upgrading is the better long-term fix).
Start with enabling error reporting—it’ll give you the exact clue you need to fix the blank page issue quickly.
内容的提问来源于stack exchange,提问作者mike437

