求助:这段PHP注册代码无法将用户数据插入SQL数据库
Hey there, let's break down exactly why your user registration code isn't adding data to your SQL database—there are several key issues preventing it from working correctly:
1. Your InsertUser() Function Is Never Executed
You've written all the registration logic inside the InsertUser() function, but nowhere in your code do you actually call InsertUser();. That means when a user submits the sign-up form, none of the code inside the function runs at all.
2. SQL Syntax Error: Spaced Column Name Needs Backticks
Looking at your INSERT query, you're trying to insert into a column named last login. MySQL requires any column name with a space (or reserved keyword) to be wrapped in backticks (`), otherwise it'll misinterpret the space as a separator between two different keywords, throwing a syntax error that stops the insert.
3. No Error Feedback for Failed Queries
Right now, you only have a success message if the INSERT works, but if it fails, you have no way to see why. Adding mysqli_error($con) will print the exact database error message, which is essential for debugging issues like this.
4. Redundant Variable Assignment
You've assigned $name = $_POST['u_name']; twice in your code—this doesn't break the functionality, but it's unnecessary and makes your code messier than it needs to be.
Bonus: Critical Security Flaws (Important for User Data Safety)
While not directly causing the insert failure, these are huge issues you should fix immediately:
- Plaintext Password Storage: You're saving passwords as plain text, which is a massive security risk. Always hash passwords with
password_hash()before storing them. - SQL Injection Vulnerability: Directly inserting user input into SQL queries leaves your database wide open to attacks. Use prepared statements with parameter binding instead of concatenating variables into your queries.
Fixed Version of Your Code
Here's the updated code with all the above issues resolved:
<?php $con = mysqli_connect("localhost","root","","social_network") or die("Connection was not established"); function InsertUser(){ global $con; if(isset($_POST['sign_up'])){ $name = $_POST['u_name']; // Hash password securely $pass = password_hash($_POST['u_pass'], PASSWORD_DEFAULT); $email = $_POST['u_email']; $country = $_POST['u_country']; $gender = $_POST['u_gender']; $b_day = $_POST['u_birthday']; $date = date("d-m-y"); $status = "unverified"; $posts = "No"; // Check for existing email using prepared statement (prevents injection) $get_email = "SELECT * FROM users WHERE user_email = ?"; $stmt = mysqli_prepare($con, $get_email); mysqli_stmt_bind_param($stmt, "s", $email); mysqli_stmt_execute($stmt); mysqli_stmt_store_result($stmt); $check = mysqli_stmt_num_rows($stmt); if ($check == 1) { echo "<script>alert('This email is already registered!, Try another one')</script>"; exit(); } if(strlen($_POST['u_pass']) < 8){ echo "<script>alert('Password should be minimum 8 characters')</script>"; exit(); } // Fixed INSERT query with backticks for spaced column, using prepared statement $insert = "INSERT INTO users (user_name, user_pass, user_email, user_country, user_gender, user_dob, user_image, register_date, `last login`, status, posts) VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)"; $stmt_insert = mysqli_prepare($con, $insert); mysqli_stmt_bind_param($stmt_insert, "sssssssssss", $name, $pass, $email, $country, $gender, $b_day, "default.jpg", $date, $date, $status, $posts); $run_insert = mysqli_stmt_execute($stmt_insert); if($run_insert){ echo "<script>alert('Registration Successfull!')</script>"; } else { // Show error message if insertion fails echo "<script>alert('Registration failed: " . mysqli_error($con) . "')</script>"; } } } // Call the function to execute registration logic InsertUser(); ?>
Key Fixes Explained:
- Added
InsertUser();at the end to trigger the registration logic when the form is submitted. - Wrapped
last loginin backticks`last login`to fix the SQL syntax error. - Added error output using
mysqli_error($con)to debug failed inserts. - Switched to
password_hash()for secure password storage. - Replaced vulnerable query concatenation with prepared statements to prevent SQL injection.
- Removed the redundant
$nameassignment.
内容的提问来源于stack exchange,提问作者Ynot

