PHP登录表单异常:输入正确凭证无跳转无错误提示
Let's break down the critical (but easy-to-fix) issues in your code that are causing the login failure:
1. Username/Password Variable Mix-Up
In your username validation block, you accidentally assigned the username input to the $password variable instead of $username:
// Wrong code else{ $password = trim($_POST['username']); }
This leaves $username empty, so your database query will never find a matching user. Fix it by assigning to the correct variable:
// Corrected code else{ $username = trim($_POST['username']); }
2. Typo in Password Error Variable
You have a typo in the password validation error variable ($pasword_err instead of $password_err):
// Wrong code if(empty(trim($_POST["password"]))){ $pasword_err = "Please enter a password!"; }
This means the error message won't reference the correct variable, and your later check empty($password_err) will incorrectly assume no password error exists. Fix the variable name:
// Corrected code if(empty(trim($_POST["password"]))){ $password_err = "Please enter a password!"; }
3. Mismatched Database Connection Variable
Your config.php uses $db for the database connection, but your index.php tries to use $link (which doesn't exist) in mysqli_prepare(). This will silently fail the query. Replace all instances of $link with $db in index.php.
4. Missing Password Retrieval from Database
You never fetch the hashed password from the database after executing the query. The $hashed_password variable is undefined, so password_verify() can't compare the input password to the stored hash. Add code to bind and fetch the result:
// After mysqli_stmt_execute($stmt) mysqli_stmt_bind_result($stmt, $fetched_username, $hashed_password); mysqli_stmt_fetch($stmt);
Full Corrected index.php Code
<?php require_once 'config.php'; $username=$password=''; $username_err=$password_err=''; if($_SERVER["REQUEST_METHOD"] == "POST"){ // Validate username if(empty(trim($_POST["username"]))){ $username_err = 'Please enter an username!'; } else{ $username = trim($_POST['username']); // Fixed variable assignment } // Validate password if(empty(trim($_POST["password"]))){ $password_err = "Please enter a password!"; // Fixed typo } else{ $password = trim($_POST['password']); } // Check input errors before querying database if(empty($username_err) && empty($password_err)){ $sql = "SELECT username,password FROM members WHERE username = ?"; // Use $db instead of $link if($stmt = mysqli_prepare($db, $sql)){ mysqli_stmt_bind_param($stmt, "s", $param_username); $param_username = $username; if(mysqli_stmt_execute($stmt)){ mysqli_stmt_store_result($stmt); // Check if username exists, if yes then verify password if(mysqli_stmt_num_rows($stmt) == 1){ // Bind result variables mysqli_stmt_bind_result($stmt, $fetched_username, $hashed_password); mysqli_stmt_fetch($stmt); if(password_verify($password, $hashed_password)){ session_start(); $_SESSION['username'] = $username; header("location: welcome.php"); exit; // Always exit after header redirect to stop further code execution } else{ $username_err = 'Username/password is wrong!'; } } else{ $username_err = 'Username/password is wrong!'; // Consistent error message } } else{ echo "Oops! Something went wrong. Please try again later."; } mysqli_stmt_close($stmt); } mysqli_close($db); } } ?> <!DOCTYPE html> <html> <head> <!-- Include Bootstrap CSS if you're using its form classes --> <link rel="stylesheet" href="https://maxcdn.bootstrapcdn.com/bootstrap/3.3.7/css/bootstrap.css"> </head> <body> <div class="wrapper"> <h2>Log in</h2> <form action="<?php echo htmlspecialchars($_SERVER["PHP_SELF"]); ?>" method="post"> <div class="form-group <?php echo(!empty($username_err)) ? 'has-error' : ''; ?>"> <input type="text" name="username" class="form-control" placeholder="Username" value="<?php echo $username; ?>"> <span class="help-block"><?php echo $username_err; ?></span> </div> <div class="form-group <?php echo (!empty($password_err)) ? 'has-error' : ''; ?>"> <input type="password" name="password" class="form-control"> <span class="help-block"><?php echo $password_err; ?></span> </div> <div class="form-group"> <input type="submit" class="btn btn-primary" value="Login"> </div> </form> </div> </body> </html>
Bonus Tips
- Always add
exit;afterheader("location: ...")to prevent any unintended code from running after the redirect. - I added
value="<?php echo $username; ?>"to the username input to retain the user's input after a failed login, which improves usability. - Ensure your
memberstable stores hashed passwords (not plain text) usingpassword_hash()during user registration —password_verify()only works with hashes generated by this function.
内容的提问来源于stack exchange,提问作者Kappy223

