You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CodeIgniter登录功能中如何使用password_verify验证哈希密码

Fixing Password Verification with password_verify() in CodeIgniter Login

Hey there! Let's get your login validation sorted out. The core issue here is that you're trying to compare a plain-text password directly to the hashed value stored in your database—since password_hash() creates irreversible, unique hashes, that approach won't work. Instead, we need to fetch the stored hash first, then use password_verify() to check if the input password matches it.

Step 1: Update the Login Model

We'll rewrite the model to safely fetch the user by username, then validate the password with password_verify(). We'll also fix the SQL injection risk from your original string-concatenated WHERE clause.

Here's the revised model code:

public function login($data) {
    // Fetch user record by username only (uses CodeIgniter's safe query binding)
    $this->db->select('*');
    $this->db->from('users');
    $this->db->where('username', $data['username']);
    $this->db->limit(1);
    $query = $this->db->get();

    if ($query->num_rows() == 1) {
        $user = $query->row(); // Get the full user object from the result
        // Verify input password against the stored hash
        if (password_verify($data['password'], $user->password)) {
            return $user; // Return user data if verification succeeds
        } else {
            return false; // Password doesn't match
        }
    } else {
        return false; // No user found with that username
    }
}

Step 2: Update the Login Controller

Your original controller was trying to pull firstname and lastname from the login form, which isn't standard (users don't enter those during login). Instead, we'll grab those values from the user record returned by the model. Here's the corrected controller:

public function login_user() {
    $this->form_validation->set_rules('username', 'Username', 'trim|required|xss_clean');
    $this->form_validation->set_rules('password', 'Password', 'trim|required|xss_clean');

    if ($this->form_validation->run() == FALSE) {
        $this->load->view('login_view');
    } else {
        $data = array(
            'username' => $this->input->post('username'),
            'password' => $this->input->post('password')
            // Removed firstname/lastname—we'll get these from the database
        );

        $result = $this->login_database->login($data);

        if ($result !== FALSE) {
            // Populate session with user data from the database
            $this->session->set_userdata('username', $result->username);
            $this->session->set_userdata('firstname', $result->firstname);
            $this->session->set_userdata('lastname', $result->lastname);

            // Load dashboard views
            $this->load->view('include/sidenavbar');
            $this->load->view('include/topnavbar');
            $this->load->view('dashboard');
        } else {
            $this->session->set_flashdata('message', 'Login is invalid. Please try again!');
            $this->load->view('login_view');
        }
    }
}

Key Things to Note:

  • SQL Injection Safety: Using $this->db->where('username', $data['username']) automatically escapes user input, which is way safer than string concatenation.
  • password_verify() Magic: This function handles all the heavy lifting—It checks that the input password matches the hash, even if the underlying algorithm or cost factor was updated since the hash was created.
  • Trusted User Data: By pulling firstname and lastname from the database instead of the form, you ensure you're storing accurate, verified user details in the session.

内容的提问来源于stack exchange,提问作者user200

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 09:53:03