You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP登录时基于MySQL的status字段跳转并更新状态的实现求助

解决登录时根据用户status动态跳转修改密码的问题

看起来你已经把核心的更新逻辑跑通了,现在的问题主要是没法根据用户输入的用户名动态获取status值,而且之前的查询硬编码了MyName,导致逻辑没法通用。咱们把这个逻辑整合到你的登录流程里,一步一步来修正:

第一步:修改登录查询,同时获取用户的status值

你原来的登录查询只查了username和password,但我们需要同时拿到status才能判断跳转逻辑。把查询语句改成这样:

$sql = "SELECT username, password, status FROM scorecardusers WHERE username = ?";

然后在绑定结果的时候,加上$status变量:

mysqli_stmt_bind_result($stmt, $username, $hashed_password, $status);

第二步:在密码验证通过后,根据status判断跳转

密码验证正确之后,不要直接跳转到Test.php,先判断$status的值:

  • 如果$status == -1:把用户名存入session(方便后续修改密码时定位用户),然后跳转到修改密码页面
  • 如果$status == 1:正常跳转到主页

这部分的代码替换你原来的跳转逻辑:

if(password_verify($password, $hashed_password)){
    session_start();
    $_SESSION['username'] = $username; // 存用户名,后续改密码用
    
    // 判断status值
    if($status == -1){
        // 第一次登录,跳修改密码
        header("location: ChangePW.php");
        exit; // 一定要加exit,防止后续代码执行
    } else {
        // 正常登录,跳主页
        header("location: Test.php");
        exit;
    }
}

第三步:修正修改密码页面的更新逻辑

在ChangePW.php里,用户提交新密码后,要同时更新密码和把status改成1。这里建议用预处理语句(虽然你说先不管注入,但好习惯提前养成),避免硬拼接用户名:

<?php
require_once 'LoginConn.php';
session_start();

// 先判断用户是否从登录跳转过来,防止直接访问修改密码页面
if(!isset($_SESSION['username'])){
    header("location: login.php");
    exit;
}

$new_password_err = "";
$new_password = "";

if($_SERVER["REQUEST_METHOD"] == "POST"){
    // 验证新密码非空、长度等逻辑,根据你的需求加
    if(empty(trim($_POST["new_password"]))){
        $new_password_err = "请输入新密码";
    } else {
        $new_password = trim($_POST["new_password"]);
    }

    if(empty($new_password_err)){
        // 生成加密密码
        $hashed_password = password_hash($new_password, PASSWORD_DEFAULT);
        
        // 更新密码和status
        $sql = "UPDATE scorecardusers SET password = ?, status = 1 WHERE username = ?";
        if($stmt = mysqli_prepare($link, $sql)){
            mysqli_stmt_bind_param($stmt, "ss", $hashed_password, $_SESSION['username']);
            if(mysqli_stmt_execute($stmt)){
                // 更新成功,销毁session,跳回登录页或者直接进主页
                unset($_SESSION['username']);
                header("location: Test.php");
                exit;
            } else {
                echo "更新失败,请稍后重试";
            }
            mysqli_stmt_close($stmt);
        }
    }
}
?>

第四步:删掉你之前的硬编码查询

你之前写的那个硬查MyName的查询可以删掉了,因为我们已经把status的判断整合到登录的主查询里了,一次查询就能拿到所有需要的信息,更高效。

完整修正后的登录脚本

把上面的修改整合到你的原脚本里,最终的登录代码大概是这样:

<?php
// Include config file
require_once 'LoginConn.php';

// Define variables and initialize with empty values
$username = $password = "";
$username_err = $password_err = "";

// Processing form data when form is submitted
if($_SERVER["REQUEST_METHOD"] == "POST"){

    // Check if username is empty
    if(empty(trim($_POST["username"]))){
        $username_err = 'Please enter username.';
    } else{
        $username = trim($_POST["username"]);
    }

    // Check if password is empty
    if(empty(trim($_POST['password']))){
        $password_err = 'Please enter your password.';
    } else{
        $password = trim($_POST['password']);
    }

    // Validate credentials
    if(empty($username_err) && empty($password_err)){
        // Prepare a select statement - 这里修改了查询,加入status
        $sql = "SELECT username, password, status FROM scorecardusers WHERE username = ?";
        
        if($stmt = mysqli_prepare($link, $sql)){
            // Bind variables to the prepared statement as parameters
            mysqli_stmt_bind_param($stmt, "s", $param_username);

            // Set parameters
            $param_username = $username;

            // Attempt to execute the prepared statement
            if(mysqli_stmt_execute($stmt)){
                // Store result
                mysqli_stmt_store_result($stmt);

                // Check if username exists, if yes then verify password
                if(mysqli_stmt_num_rows($stmt) == 1){
                    // Bind result variables - 加入status变量
                    mysqli_stmt_bind_result($stmt, $username, $hashed_password, $status);
                    
                    if(mysqli_stmt_fetch($stmt)){
                        if(password_verify($password, $hashed_password)){
                            /* Password is correct, so start a new session and save the username to the session */
                            session_start();
                            $_SESSION['username'] = $username;

                            // 根据status判断跳转
                            if($status == -1){
                                header("location: ChangePW.php");
                                exit;
                            } else {
                                header("location: Test.php");
                                exit;
                            }
                        } else{
                            // Display an error message if password is not valid
                            $password_err = 'The password you entered was not valid.';
                        }
                    }
                } else{
                    // Display an error message if username doesn't exist
                    $username_err = 'No account found with that username.';
                }
            } else{
                echo "Oops! Something went wrong. Please try again later.";
            }
        }

        // Close statement
        mysqli_stmt_close($stmt);
    }

    // Close connection
    mysqli_close($link);
}
?>

这样修改后,就能实现:

  1. 用户输入用户名密码,验证正确后
  2. 如果status是-1,自动跳转到修改密码页面
  3. 修改密码完成后,自动把status改成1,然后跳转到主页
  4. 如果status已经是1,直接正常登录

另外提个小建议:虽然你说先不管SQL注入,但预处理语句你已经在登录里用了,后续的更新也尽量用预处理,避免硬拼接字符串,这样后续改PDO也更容易。

内容的提问来源于stack exchange,提问作者Malsum

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 10:18:40