You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP+MySQL学生登录异常:注册正常但提示学号或密码无效

Hey there! Let's figure out why your login is failing even with valid credentials. Here are the most likely issues and actionable fixes to try:

1. Confirm you're storing hashed passwords during registration

The password_verify() function only works if you used password_hash() when saving passwords to the database. If you stored plain-text passwords (or used outdated hashing like MD5/SHA1), this verification will always fail.

Double-check your registration code to ensure it includes proper hashing, like this:

// Example registration password handling
$plainPassword = $_POST['Password'];
$hashedPassword = password_hash($plainPassword, PASSWORD_DEFAULT);
// Insert $hashedPassword into the `Password` column of your regstudents table

2. Fix your login logic flow

Your current code checks password_verify() before confirming the user exists. If the regnumber isn't found (so $count = 0), $row['Password'] is undefined, and password_verify() will return false—triggering the generic error. Let's reorder the checks to isolate the issue:

$query = $DBcon->query("SELECT Sessionid, Regnumber, Password FROM regstudents WHERE Regnumber='$Regnumber'");
$count = $query->num_rows; 

if ($count == 1) {
    $row = $query->fetch_array();
    if (password_verify($Password, $row['Password'])) {
        $_SESSION['userSession'] = $row['Sessionid'];
        header("Location: home.php");
        exit; // Always exit after a header redirect to stop further code execution!
    } else {
        $msg = "<div class='alert alert-danger'> <span class='glyphicon glyphicon-info-sign'></span> &nbsp; Invalid Password ! </div>";
    }
} else {
    $msg = "<div class='alert alert-danger'> <span class='glyphicon glyphicon-info-sign'></span> &nbsp; Regnumber not found ! </div>";
}

This way, you can tell if the problem is a missing regnumber or a mismatched password, making debugging easier.

3. Check your database Password column length

Hashes generated by password_hash() are exactly 60 characters long. If your Password column is shorter than 60 characters (e.g., VARCHAR(32)), the hash will get truncated when stored—breaking verification.

Fix this by altering your table to use a longer column:

ALTER TABLE regstudents MODIFY COLUMN Password VARCHAR(255) NOT NULL;

4. Ensure strip_tags() isn't altering your Regnumber

If your registration number includes characters that strip_tags() would remove (unlikely, but possible), this could make the stored regnumber different from what's entered during login. Test removing strip_tags() from the regnumber handling:

// Replace this:
// $Regnumber = strip_tags($_POST['Regnumber']);
// With:
$Regnumber = $_POST['Regnumber'];
$Regnumber = $DBcon->real_escape_string($Regnumber);

(Pro tip: For better security against SQL injection, consider switching to prepared statements with PDO or mysqli instead of real_escape_string.)

5. Add debug output to see exactly what's happening

Temporarily add these lines to inspect the values being used during login:

// After processing Regnumber and Password
echo "Entered Regnumber: " . htmlspecialchars($Regnumber) . "<br>";
echo "Entered Password: " . htmlspecialchars($Password) . "<br>";

// After fetching the row
if ($count > 0) {
    echo "Stored Password Hash: " . htmlspecialchars($row['Password']) . "<br>";
    echo "Verification Result: " . (password_verify($Password, $row['Password']) ? "✅ Match" : "❌ No Match") . "<br>";
}

This will show you if the stored hash is truncated, if the regnumber doesn't match, or if the verification is failing for another reason.

内容的提问来源于stack exchange,提问作者Phor

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 09:30:41