技术求助:售货机验证失败仍可进入Admin面板问题排查
Hey there! Let's work through this issue where invalid usernames or passwords are still letting folks into your vending machine's Admin panel. First, let's break down what you've shared and where things might be going wrong.
- You've built a vending machine with two modes: Admin (restricted) and User (unrestricted)
- Access to the Admin panel requires username/password verification via the
Loginclass'sLoginUser(User &u)method - Right now, even with invalid credentials, users can still access the Admin panel—so the verification logic isn't working as intended
Here's the code snippets you provided for context:
// Login类 class Login { public: Login(); // 构造函数初始化数据成员 bool LoginUser(User &u); // 尝试验证用户 }; // LoginInfo类 class LoginInfo { private: string userID; string password; // ... 其他未展示的成员 };
From what I can see, there are a few likely culprits:
- The
LoginUsermethod isn't correctly returningfalsewhen credentials don't match valid admin values - The code that calls
LoginUserisn't actually checking its return value to restrict Admin panel access - The
LoginInfoclass isn't properly storing or retrieving valid admin credentials for comparison
1. Ensure LoginUser Validates Credentials Correctly
First, let's make sure the LoginUser method does its job: it should check if the provided user's credentials match a valid admin, set the user's admin status accordingly, and return true only if validation passes.
bool Login::LoginUser(User &u) { // Fetch valid admin credentials (in production, don't hardcode this! Use encrypted storage) LoginInfo validAdmin; validAdmin.userID = "admin"; // Example valid admin ID validAdmin.password = "secure_admin_pass"; // Example valid password // Compare provided credentials to valid admin credentials if (u.getUserID() == validAdmin.userID && u.getPassword() == validAdmin.password) { u.setIsAdmin(true); // Mark user as admin if valid return true; } else { u.setIsAdmin(false); // Ensure user isn't marked as admin if invalid return false; } }
(Note: Replace the hardcoded credentials with a secure retrieval method—like loading from an encrypted config file—for production use.)
2. Check the LoginUser Result Before Allowing Admin Access
Even if LoginUser works correctly, you need to make sure your access control logic uses its return value to block invalid attempts:
// Example workflow when a user tries to access the Admin panel User currentUser; Login loginSystem; // Get user input for credentials cout << "Enter Admin User ID: "; cin >> currentUser.userID; cout << "Enter Admin Password: "; cin >> currentUser.password; // Verify credentials and restrict access if (loginSystem.LoginUser(currentUser)) { // Only proceed to Admin panel if validation succeeded cout << "Access granted! Loading Admin Panel..." << endl; // Your Admin panel logic goes here } else { // Block access and redirect to User mode or show error cout << "Invalid username or password! Access denied." << endl; // Redirect to User mode interface here }
3. Add Input Validation (Bonus)
To avoid edge cases (like empty credentials), add a quick check before running the validation:
bool Login::LoginUser(User &u) { // First, make sure credentials aren't empty if (u.getUserID().empty() || u.getPassword().empty()) { u.setIsAdmin(false); return false; } // ... rest of the validation logic from above }
- Secure Credential Storage: Never hardcode credentials in your source code. Use encrypted files or a lightweight database to store valid admin accounts.
- Rate Limiting: Add a counter to block repeated failed login attempts and prevent brute-force attacks.
- Clear Feedback: Tell users why login failed (e.g., "Invalid username" vs "Invalid password")—but be careful not to give too much info to potential attackers.
内容的提问来源于stack exchange,提问作者user7716102

