PHP报错求助:Undefined index: password(register.php第91行)
Hey there, let's fix this error step by step! The Notice: Undefined index: password is a straightforward mismatch issue, and we'll also tackle some hidden problems in your code to make it more robust.
1. Core Cause of the Error
Look at your SQL query: you're selecting the field user_password from the database, but on line 91, you're trying to access $results['password']. These two names don't match—there's no password key in your query results, hence the undefined index notice.
2. Step-by-Step Fixes
Fix 1: Align Database Field Names
Update the code to use the exact field name from your query:
- Change
$results['password']to$results['user_password'](line 91) - Also fix the session assignment line:
$_SESSION['username'] = $results['username'];→$_SESSION['username'] = $results['user_name'];(since your query selectsuser_name, notusername)
Fix 2: Correct Password Verification Logic
Your current code uses hash('sha512',$password) then password_verify()—this is wrong. password_verify() only works with hashes generated by password_hash(), not raw SHA-512 hashes. Choose one of these options based on how you stored passwords:
- If your database uses
password_hash()generated hashes: Remove the$hashpass = hash('sha512',$password);line, and verify directly withpassword_verify($password, $results['user_password']) - If your database stores raw SHA-512 hashes: Skip
password_verify()and compare hashes directly:$hashpass === $results['user_password']
Fix 3: Add Safe Parameter Retrieval (Recommended)
To avoid similar undefined index issues from missing POST data, use null coalescing to set default values:
$username = trim($_POST['username'] ?? ''); $password = trim($_POST['password'] ?? '');
Corrected Code Snippet
<?php session_start(); //DB configuration Constants define('_HOST_NAME_', 'localhost'); define('_USER_NAME_', 'user'); define('_DB_PASSWORD', ''); define('_DATABASE_NAME_', 'user'); //PDO Database Connection try { $databaseConnection = new PDO('mysql:host=localhost; dbname=user; ', 'root', ''); $databaseConnection->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION); } catch(PDOException $e) { echo 'ERROR: ' . $e->getMessage(); } if(isset($_POST['login'])){ $errMsg = ''; // Safe parameter retrieval $username = trim($_POST['username'] ?? ''); $password = trim($_POST['password'] ?? ''); if($username == '') $errMsg .= 'You must enter your Username<br>'; if($password == '') $errMsg .= 'You must enter your Password<br>'; if($errMsg == ''){ $records = $databaseConnection->prepare('SELECT user_id,user_name,user_password FROM user WHERE user_name = :username'); $records->bindParam(':username', $username); $records->execute(); $results = $records->fetch(PDO::FETCH_ASSOC); // Using password_verify for password_hash generated hashes if($results && password_verify($password, $results['user_password'])){ $_SESSION['username'] = $results['user_name']; header('location:index.php'); exit; }else{ $errMsg .= 'Username and Password are not found<br>'; } } } ?>
内容的提问来源于stack exchange,提问作者PeanutStick

