You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP登录表单异常:输入正确凭证无跳转无错误提示

Let's break down the critical (but easy-to-fix) issues in your code that are causing the login failure:

1. Username/Password Variable Mix-Up

In your username validation block, you accidentally assigned the username input to the $password variable instead of $username:

// Wrong code
else{
    $password = trim($_POST['username']); 
}

This leaves $username empty, so your database query will never find a matching user. Fix it by assigning to the correct variable:

// Corrected code
else{
    $username = trim($_POST['username']); 
}

2. Typo in Password Error Variable

You have a typo in the password validation error variable ($pasword_err instead of $password_err):

// Wrong code
if(empty(trim($_POST["password"]))){
    $pasword_err = "Please enter a password!"; 
}

This means the error message won't reference the correct variable, and your later check empty($password_err) will incorrectly assume no password error exists. Fix the variable name:

// Corrected code
if(empty(trim($_POST["password"]))){
    $password_err = "Please enter a password!"; 
}

3. Mismatched Database Connection Variable

Your config.php uses $db for the database connection, but your index.php tries to use $link (which doesn't exist) in mysqli_prepare(). This will silently fail the query. Replace all instances of $link with $db in index.php.

4. Missing Password Retrieval from Database

You never fetch the hashed password from the database after executing the query. The $hashed_password variable is undefined, so password_verify() can't compare the input password to the stored hash. Add code to bind and fetch the result:

// After mysqli_stmt_execute($stmt)
mysqli_stmt_bind_result($stmt, $fetched_username, $hashed_password);
mysqli_stmt_fetch($stmt);

Full Corrected index.php Code

<?php
require_once 'config.php';
$username=$password='';
$username_err=$password_err='';

if($_SERVER["REQUEST_METHOD"] == "POST"){
    // Validate username
    if(empty(trim($_POST["username"]))){
        $username_err = 'Please enter an username!';
    } else{
        $username = trim($_POST['username']); // Fixed variable assignment
    }

    // Validate password
    if(empty(trim($_POST["password"]))){
        $password_err = "Please enter a password!"; // Fixed typo
    } else{
        $password = trim($_POST['password']);
    }

    // Check input errors before querying database
    if(empty($username_err) && empty($password_err)){
        $sql = "SELECT username,password FROM members WHERE username = ?";
        // Use $db instead of $link
        if($stmt = mysqli_prepare($db, $sql)){
            mysqli_stmt_bind_param($stmt, "s", $param_username);
            $param_username = $username;

            if(mysqli_stmt_execute($stmt)){
                mysqli_stmt_store_result($stmt);
                // Check if username exists, if yes then verify password
                if(mysqli_stmt_num_rows($stmt) == 1){
                    // Bind result variables
                    mysqli_stmt_bind_result($stmt, $fetched_username, $hashed_password);
                    mysqli_stmt_fetch($stmt);
                    if(password_verify($password, $hashed_password)){
                        session_start();
                        $_SESSION['username'] = $username;
                        header("location: welcome.php");
                        exit; // Always exit after header redirect to stop further code execution
                    } else{
                        $username_err = 'Username/password is wrong!';
                    }
                } else{
                    $username_err = 'Username/password is wrong!'; // Consistent error message
                }
            } else{
                echo "Oops! Something went wrong. Please try again later.";
            }
            mysqli_stmt_close($stmt);
        }
        mysqli_close($db);
    }
}
?>
<!DOCTYPE html>
<html>
<head>
    <!-- Include Bootstrap CSS if you're using its form classes -->
    <link rel="stylesheet" href="https://maxcdn.bootstrapcdn.com/bootstrap/3.3.7/css/bootstrap.css">
</head>
<body>
    <div class="wrapper">
        <h2>Log in</h2>
        <form action="<?php echo htmlspecialchars($_SERVER["PHP_SELF"]); ?>" method="post">
            <div class="form-group <?php echo(!empty($username_err)) ? 'has-error' : ''; ?>">
                <input type="text" name="username" class="form-control" placeholder="Username" value="<?php echo $username; ?>">
                <span class="help-block"><?php echo $username_err; ?></span>
            </div>
            <div class="form-group <?php echo (!empty($password_err)) ? 'has-error' : ''; ?>">
                <input type="password" name="password" class="form-control">
                <span class="help-block"><?php echo $password_err; ?></span>
            </div>
            <div class="form-group">
                <input type="submit" class="btn btn-primary" value="Login">
            </div>
        </form>
    </div>
</body>
</html>

Bonus Tips

  • Always add exit; after header("location: ...") to prevent any unintended code from running after the redirect.
  • I added value="<?php echo $username; ?>" to the username input to retain the user's input after a failed login, which improves usability.
  • Ensure your members table stores hashed passwords (not plain text) using password_hash() during user registration — password_verify() only works with hashes generated by this function.

内容的提问来源于stack exchange,提问作者Kappy223

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 07:17:01