You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP登录系统异常:管理员可登录,普通用户无法登录但保留Cookie

Hey there! Let's troubleshoot this login issue you're dealing with—it's strange that admins can log in fine but regular users can't, yet cookies still get set. Let's break this down step by step to find the root cause.

First, Fix That Incomplete SQL Query

Your code snippet cuts off at SELECT cod_usua...—this is a critical red flag. A partial query will either fail silently or return unexpected results, which could explain why only admins (who might match a partial condition) get through.

Make sure your prepared statement is complete, selects all necessary fields (like password hash, user role, and account status), and binds the username parameter correctly. For example:

// Replace your partial query with something like this
$consulta = $con->prepare("SELECT cod_usua, contra, tipo_usuario, estado FROM usuarios WHERE usuario = ?");
$consulta->bind_param("s", $usuario); // Bind the username as a string parameter
$consulta->execute();
$resultado = $consulta->get_result();

Check Your Login Logic for Role Bias

The most likely culprit here is that your code is explicitly only allowing admin accounts to complete the login flow, while still setting cookies regardless. For example, you might have something like this hidden in the code you didn't share:

if ($fila = $resultado->fetch_assoc()) {
    if (password_verify($contra, $fila['contra'])) {
        // Only admins get redirected/logged in
        if ($fila['tipo_usuario'] === 'admin') {
            setcookie("user", $usuario, time()+3600);
            header("Location: admin_panel.php");
            exit;
        }
        // Regular users hit this point and get no feedback, but cookies might be set elsewhere
    }
}

Double-check that you're handling all valid user roles after verifying the password. If you want regular users to log in, add a branch for them too:

if (password_verify($contra, $fila['contra'])) {
    // Set cookie for ALL valid users first
    setcookie("user_id", $fila['cod_usua'], time()+3600, "/", "", true, true); // Secure cookie setup
    // Redirect based on role
    if ($fila['tipo_usuario'] === 'admin') {
        header("Location: admin_dashboard.php");
    } else {
        header("Location: user_dashboard.php");
    }
    exit;
}

Verify Where You're Setting Cookies

If cookies are being created even when regular users can't log in, chances are you're setting the cookie before validating the user's credentials. For example:

// ❌ Bad practice: Cookie set BEFORE checking if user is valid
setcookie("user", $usuario, time()+3600);
if ($resultado->num_rows === 1) {
    // Verify password...
}

Move your setcookie() call inside the block where you confirm the user's password is correct—this way, cookies only get set for legitimate logins, regardless of user role.

Check Regular User Data in the Database

It's also worth confirming your regular user accounts are properly set up:

  • Ensure their passwords are stored with password_hash() (not plain text or outdated hashing methods)
  • Check if there's an estado (status) field that marks accounts as active—if admins are set to activo but regular users aren't, your query might be filtering them out
  • Make sure their username is spelled correctly in the database (case sensitivity could be an issue if your collation is case-sensitive)

Debug with Error Messages

You already enabled error reporting, but add explicit checks for MySQL errors to catch issues with your query:

if (!$consulta->execute()) {
    echo "Query Error: " . $consulta->error;
    exit;
}

This will show you if your query is failing for regular users but passing for admins.


内容的提问来源于stack exchange,提问作者Alejandro Esquivel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 08:15:42