已登录用户数据库数据提取:如何获取姓名与头像信息
Hey there! Let's get that user profile display working for you. The core issue right now is two-fold: you're only storing the user's email in the session, and you tried using a deprecated MySQL function that doesn't play nice with MySQLi. Let's break this down step by step.
1. Why Your Previous Attempt Crashed
The line $row = mysql_fetch_array($result); caused your site to break because:
- You're using MySQLi for your database connections, but
mysql_fetch_array()belongs to the old, deprecatedmysql_*extension. These two systems aren't compatible—you need to use MySQLi-specific functions likemysqli_fetch_assoc()instead.
2. Modify Your Login Page to Store Full User Data in Session
Right now, you're only saving the user's email to the session. We need to fetch their full row from the database and store the name/avatar (and any other data you need) in the session when they log in successfully.
Update your login page code where you handle the successful login:
if($rows==1){ // Fetch the full user data from the query result $user = mysqli_fetch_assoc($result); // Store critical user data in the session $_SESSION['user_email'] = $email; $_SESSION['user_name'] = $user['user_name']; // Replace with your actual database field name for the user's name $_SESSION['user_avatar'] = $user['user_avatar']; // Replace with your field name for avatar (e.g., file path or URL) // Redirect and exit to prevent further code execution header("Location: ../index.php"); exit(); }else{ echo "<div class='form'><h3>Username/password is incorrect.</h3><br/>Click here to <a href='login.php'>Login</a></div>"; }
Important Notes Here:
- Double-check your
userstable schema: make sure you have columns for the user's name (e.g.,user_name,full_name) and avatar (e.g.,user_avatar—this could be a relative file path like../avatars/jdoe.jpgor a URL). - If your field names are different (like
nameinstead ofuser_name), adjust the array keys in$user['your_field_name']to match.
3. Display the User Name & Avatar on Your Pages
Now that the data is stored in the session, you can display it anywhere on your secure pages (after including auth.php, which you already do):
<!-- Display Welcome Message with Name --> <p>Welcome <?php echo $_SESSION['user_name']; ?></p> <!-- Display User Avatar (adjust styling as needed) --> <?php if (!empty($_SESSION['user_avatar'])): ?> <img src="<?php echo $_SESSION['user_avatar']; ?>" alt="User Avatar" style="width: 50px; height: 50px; border-radius: 50%;"> <?php else: ?> <!-- Fallback placeholder if no avatar exists --> <div style="width:50px;height:50px;border-radius:50%;background:#ccc;display:flex;align-items:center;justify-content:center;"> <?php echo strtoupper(substr($_SESSION['user_name'], 0, 1)); ?> </div> <?php endif; ?>
4. Quick Security & Best Practice Checks
- Always add
exit();immediately afterheader("Location: ...");to prevent the rest of your script from running (this avoids potential bugs or security issues). - Make sure your
auth.phpstarts the session withsession_start();before any output is sent to the browser (which it looks like you already do). - Consider using prepared statements for your login query instead of directly inserting user input into the SQL string—this prevents SQL injection attacks. Here's a quick example of how to adjust that query:
// Replace your current query and result with this $query = "SELECT * FROM `users` WHERE user_email = ? AND user_pwd = ?"; $stmt = mysqli_prepare($con, $query); mysqli_stmt_bind_param($stmt, "ss", $email, md5($password)); mysqli_stmt_execute($stmt); $result = mysqli_stmt_get_result($stmt); $rows = mysqli_num_rows($result);
That's it! Follow these steps, and you should see the user's name and avatar showing up in your site's header or profile section.
内容的提问来源于stack exchange,提问作者Bigsease30

