Web应用登录异常:输入正确凭证却提示‘Sorry, those credentials do not match’
Hey there, let’s figure out why your login is failing even with the correct username and password. Looking at your PHP code, here are the most common culprits and how to fix them:
1. Ensure Passwords Were Hashed Correctly During Registration
The password_verify() function only works if the password was stored using PHP’s password_hash() method. If your registration code saved plain text passwords or used an older hashing algorithm (like MD5/SHA1), verification will always fail.
Double-check your registration logic— it should look something like this:
$hashed_password = password_hash($_POST['password'], PASSWORD_DEFAULT); // Insert $hashed_password into the `password` column of your users table
If you previously stored passwords without password_hash(), you’ll need to update existing user passwords to use the proper hashing format.
2. Check Database Column Configuration
- Password field length:
password_hash()generates a 60-character hash by default. Make sure yourusers.passwordcolumn is set toVARCHAR(255)(not a shorter length orTEXT). A truncated hash will causepassword_verify()to fail. - Username case sensitivity: If your database is case-sensitive (like MySQL with a
binarycollation), a username input ofJaneDoewon’t matchjanedoestored in the database. To fix this, normalize the case in your query:$records = $conn->prepare('SELECT id, policajt_id, username, password FROM users WHERE LOWER(username) = LOWER(:username)');
3. Debug the Query and Verification Steps
Add temporary debug output to see exactly what’s happening in your code (remove this after troubleshooting for security):
$records->execute(); $results = $records->fetch(PDO::FETCH_ASSOC); // Debug lines var_dump($results); // Check if the user record is being retrieved echo "<br>Stored hash: " . ($results['password'] ?? 'No hash found') . "<br>"; echo "Input password: " . $_POST['password'] . "<br>"; echo "Verification result: " . (password_verify($_POST['password'], $results['password'] ?? '') ? 'SUCCESS' : 'FAILURE');
This will tell you if:
- The query isn’t finding any user matching the username
- The stored hash is valid (not truncated or missing)
- The password verification itself is failing
4. Trim Whitespace from Inputs
Users might accidentally add leading/trailing spaces to their username or password. Clean up the input values before using them:
$username = trim($_POST['username']); $password = trim($_POST['password']); // Use $username and $password for binding and verification $records->bindParam(':username', $username);
5. Fix Redirect and Session Handling
After setting the session and redirecting, always add exit; or die(); to stop further code execution. This prevents unexpected behavior that might interfere with the login flow:
if(count($results) > 0 && password_verify($password, $results['password']) ){ $_SESSION['user_id'] = $results['id']; header("Location: /"); exit; // Critical to add this! }
Start with the first two checks— incorrect password hashing and database column issues are the most frequent causes of this problem.
内容的提问来源于stack exchange,提问作者vonston

