CodeIgniter登录功能中如何使用password_verify验证哈希密码
password_verify() in CodeIgniter Login Hey there! Let's get your login validation sorted out. The core issue here is that you're trying to compare a plain-text password directly to the hashed value stored in your database—since password_hash() creates irreversible, unique hashes, that approach won't work. Instead, we need to fetch the stored hash first, then use password_verify() to check if the input password matches it.
Step 1: Update the Login Model
We'll rewrite the model to safely fetch the user by username, then validate the password with password_verify(). We'll also fix the SQL injection risk from your original string-concatenated WHERE clause.
Here's the revised model code:
public function login($data) { // Fetch user record by username only (uses CodeIgniter's safe query binding) $this->db->select('*'); $this->db->from('users'); $this->db->where('username', $data['username']); $this->db->limit(1); $query = $this->db->get(); if ($query->num_rows() == 1) { $user = $query->row(); // Get the full user object from the result // Verify input password against the stored hash if (password_verify($data['password'], $user->password)) { return $user; // Return user data if verification succeeds } else { return false; // Password doesn't match } } else { return false; // No user found with that username } }
Step 2: Update the Login Controller
Your original controller was trying to pull firstname and lastname from the login form, which isn't standard (users don't enter those during login). Instead, we'll grab those values from the user record returned by the model. Here's the corrected controller:
public function login_user() { $this->form_validation->set_rules('username', 'Username', 'trim|required|xss_clean'); $this->form_validation->set_rules('password', 'Password', 'trim|required|xss_clean'); if ($this->form_validation->run() == FALSE) { $this->load->view('login_view'); } else { $data = array( 'username' => $this->input->post('username'), 'password' => $this->input->post('password') // Removed firstname/lastname—we'll get these from the database ); $result = $this->login_database->login($data); if ($result !== FALSE) { // Populate session with user data from the database $this->session->set_userdata('username', $result->username); $this->session->set_userdata('firstname', $result->firstname); $this->session->set_userdata('lastname', $result->lastname); // Load dashboard views $this->load->view('include/sidenavbar'); $this->load->view('include/topnavbar'); $this->load->view('dashboard'); } else { $this->session->set_flashdata('message', 'Login is invalid. Please try again!'); $this->load->view('login_view'); } } }
Key Things to Note:
- SQL Injection Safety: Using
$this->db->where('username', $data['username'])automatically escapes user input, which is way safer than string concatenation. password_verify()Magic: This function handles all the heavy lifting—It checks that the input password matches the hash, even if the underlying algorithm or cost factor was updated since the hash was created.- Trusted User Data: By pulling
firstnameandlastnamefrom the database instead of the form, you ensure you're storing accurate, verified user details in the session.
内容的提问来源于stack exchange,提问作者user200

