You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

简易PHP用户认证系统开发求助:数据存储与登录验证问题

Hey there! Let's work through your two issues one by one to get your minimal PHP auth system up and running.

Issue 1: Form Data Not Saving to Database (FORM.php)

Looking at your FORM.php code, there are a few small bugs blocking the data from being inserted correctly:

  • You’re hardcoding 'id' in the INSERT statement. If your users table’s id column is an auto-incrementing primary key (which it should be), you don’t need to include it at all — MySQL will handle assigning the ID automatically.
  • You used mysql_error($con) but rely on mysqli functions everywhere else. This should be mysqli_error($con) instead.
  • You access $_POST values without checking if they exist first, which can throw errors if the form is submitted improperly.
  • I assume you have database connection code above what you shared, but if not, make sure to include mysqli_connect() with your actual DB credentials.

Here’s the corrected FORM.php:

<?php
// Replace with your actual database credentials
$host = 'localhost';
$dbname = 'your_database_name';
$dbuser = 'your_db_username';
$dbpass = 'your_db_password';

$con = mysqli_connect($host, $dbuser, $dbpass, $dbname);
if (!$con) {
    die("Failed to connect to MySQL: " . mysqli_connect_error());
}

// Check if form was submitted properly
if (isset($_POST['register'], $_POST['username'], $_POST['password'])) {
    $var_user = $_POST['username'];
    $var_pass = $_POST['password'];
    
    // Encrypt the password
    $encPassword = password_hash($var_pass, PASSWORD_DEFAULT);
    
    // Omit the id column (auto-increment handles it)
    $query = "INSERT INTO users(username, password) VALUES ('$var_user', '$encPassword')";
    
    if (mysqli_query($con, $query)) {
        echo "User created<br>";
    } else {
        die('SQL Error: ' . mysqli_error($con));
    }
} else {
    echo "Please submit the registration form properly.";
}

mysqli_close($con);
?>

Issue 2: Missing Password Matching Logic in verify.php

Your current verify.php doesn’t fetch the hashed password from the database for the submitted username. We need to add that lookup step to compare the input password with the stored hash, plus handle the redirect on success.

Here’s the corrected verify.php:

<?php
// Replace with your actual database credentials
$host = 'localhost';
$dbname = 'your_database_name';
$dbuser = 'your_db_username';
$dbpass = 'your_db_password';

$con = mysqli_connect($host, $dbuser, $dbpass, $dbname);
if (!$con) {
    die("Failed to connect to MySQL: " . mysqli_connect_error());
}

// Check if login form was submitted
if (isset($_POST['Login'], $_POST['username'], $_POST['password'])) {
    $username = $_POST['username'];
    $postPassword = $_POST['password'];
    
    // Fetch the hashed password for the submitted username
    $query = "SELECT password FROM users WHERE username = '$username'";
    $result = mysqli_query($con, $query);
    
    if (mysqli_num_rows($result) === 1) {
        // Get the stored hash from the database
        $row = mysqli_fetch_assoc($result);
        $encPassword = $row['password'];
        
        // Verify the password match
        if (password_verify($postPassword, $encPassword)) {
            // Password is valid — redirect to your target page
            header("Location: your-target-page.php");
            exit(); // Always exit after a redirect to stop further code execution
        } else {
            echo 'Invalid password.';
        }
    } else {
        echo 'Username not found.';
    }
} else {
    echo "Please submit the login form properly.";
}

mysqli_close($con);
?>

Quick Notes

  • Since you mentioned this is a minimal system without security considerations, I kept queries simple. If you ever want to harden this later, use prepared statements to prevent SQL injection attacks.
  • Ensure your users table has the right structure: id (INT, auto-increment, primary key), username (VARCHAR, unique), password (VARCHAR(255) — password_hash generates long strings that need enough space).

内容的提问来源于stack exchange,提问作者user9791078

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 04:15:31