PHP7 PDO身份验证脚本异常:存在用户无法通过认证求助
Hey there! Let’s figure out why your existing "test" user isn’t passing authentication and keeps throwing the "User is not found!" error. Since you’re using PHP 7 + MySQL with PDO, here are the key areas to check:
1. Verify Your PDO Query & Parameter Binding
This is the most common culprit for missing user results. Make sure your prepared statement uses correct parameter binding and matches the data you’re passing. For example:
// First, trim the login input to avoid accidental spaces $cleanLogin = trim($data['login_auth']); // Prepare the query with a named placeholder $stmt = $pdo->prepare("SELECT id, login, password FROM users WHERE login = :login"); // Bind the cleaned login value (use PARAM_STR to ensure correct data type) $stmt->bindParam(':login', $cleanLogin, PDO::PARAM_STR); // Execute and fetch the user $stmt->execute(); $user = $stmt->fetch(PDO::FETCH_ASSOC); // Now check if user exists if (!$user) { $errors[] = 'User is not found!'; }
- Double-check that the placeholder (
:login) matches what you’re binding. If you used:usernameinstead of:login, the query will return no results. - Always use trimmed input for usernames—extra spaces in the input vs. the database will break the match.
2. Check Database Table & Data Matching
- Field name accuracy: Confirm your users table uses
loginas the username field. If it’s namedusernameoruser_login, adjust your SQL query to match. - Case sensitivity: MySQL’s default collation (like
utf8_bin) is case-sensitive. If your database has "Test" but you’re inputting "test", the query will fail. Fix this either by:- Using a case-insensitive collation (e.g.,
utf8_general_ci) for theloginfield, or - Modifying the query to ignore case:
WHERE LOWER(login) = LOWER(:login)
- Using a case-insensitive collation (e.g.,
- Manual SQL test: Run this query directly in your MySQL client (phpMyAdmin, Navicat, etc.):
If this returns no results, the issue is in your database (not the PHP code)—double-check the user exists and the field name is correct.SELECT * FROM users WHERE login = 'test';
3. Enable PDO Error Mode to Catch Hidden Issues
By default, PDO doesn’t throw detailed errors, so you might miss syntax mistakes in your query. Enable exception mode when initializing PDO to see exactly what’s wrong:
$pdo = new PDO( 'mysql:host=localhost;dbname=your_database;charset=utf8mb4', 'your_username', 'your_password', [ PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION, // Throw errors as exceptions PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC ] );
This will reveal any SQL syntax errors (like typos in field names) that are silently failing your query.
4. Confirm Your Logic Flow
Make sure you’re checking for the user’s existence before validating the password. A common mistake is reversing this order, leading to misleading error messages. The correct flow should be:
- Validate that login/password inputs aren’t empty
- Fetch the user from the database using the login
- If no user is found, throw "User is not found!"
- If the user exists, verify the password (use
password_verify()for hashed passwords!)
内容的提问来源于stack exchange,提问作者aysee

