PHP注册表单无法向PhpMyAdmin插入用户数据求助
Hey there, let's break down why your registration data isn't saving to MySQL even when you get a success message. I've spotted several key issues in your code:
1. Mixed Database Connections (MySQLi + PDO)
Your dbconnect.php creates both a MySQLi connection ($mysqli) and a PDO connection ($DB_con), but your main registration code uses MySQLi functions like mysqli_query() without passing the connection object.
mysqli_query() requires two parameters: the database connection first, then the query string. Your current calls (e.g., mysqli_query($query)) are invalid—they're not using the connection you established, so the SQL never actually runs against your database. That's why you get a success message but no data in PhpMyAdmin.
2. Broken Regex Validation
You have a syntax error in your name validation regex:
!preg_match("/^[a-zA-Z ]+$/".$name)
You're concatenating $name to the regex pattern instead of passing it as the second argument. This will throw a regex syntax error and incorrectly mark valid names as invalid.
3. SQL Injection Vulnerabilities
You're directly inserting user input into your SQL queries (even after sanitizing with htmlspecialchars), which leaves you open to SQL injection attacks. Always use prepared statements instead.
Step-by-Step Fixes
First: Clean Up Your Database Connection (dbconnect.php)
Stick to one connection type—let's use MySQLi since your main code relies on it. Replace your dbconnect.php with this:
<?php $host = 'localhost'; $user = 'root'; $pass = 'password'; $db = 'accounts'; // Create MySQLi connection and check for errors $mysqli = new mysqli($host, $user, $pass, $db); if ($mysqli->connect_error) { die("Connection failed: " . $mysqli->connect_error); } ?>
Second: Fix the mysqli_query() Calls in Your Registration Code
Update every mysqli_query() call to include the $mysqli connection object:
Check for Existing Email:
$query = "SELECT email FROM users WHERE email='$email'"; $result = mysqli_query($mysqli, $query); // Add $mysqli as first parameter if (!$result) { die("Query failed: " . mysqli_error($mysqli)); // Add error checking } $count = mysqli_num_rows($result);
Insert New User (With Security Improvements):
Replace your existing insert block with this prepared statement version to avoid SQL injection:
if( !$error ) { // Use prepared statement to separate user input from SQL logic $stmt = $mysqli->prepare("INSERT INTO users(first_name, email, password) VALUES(?, ?, ?)"); $stmt->bind_param("sss", $name, $email, $pass); // "sss" = 3 string parameters if ($stmt->execute()) { $errTyp = "success"; $errMSG = "Successfully registered, you may login now"; unset($name); unset($email); unset($pass); } else { $errTyp = "danger"; $errMSG = "Something went wrong, try again later... Error: " . $stmt->error; } $stmt->close(); }
Third: Fix the Regex Validation
Correct the regex line to pass $name as the second argument:
else if (!preg_match("/^[a-zA-Z ]+$/", $name)) { $error = true; $nameError = "Name must contain alphabets and space."; }
Why This Works
- By explicitly passing the
$mysqliconnection (or using prepared statements), your SQL now actually executes against your database. - The fixed regex will properly validate names without false errors.
- Prepared statements eliminate SQL injection risks by ensuring user input is never treated as part of the SQL command.
内容的提问来源于stack exchange,提问作者user7915134

