php password_php – 在现有密码上使用password_verify

这篇博客解决了在PHP中使用password_hash和password_verify进行密码验证时遇到的问题。代码中展示了如何正确地从数据库查询用户信息,并使用password_verify函数来检查输入的密码是否与存储的哈希密码匹配。修复了原来在查询后直接使用password_verify的错误做法。
摘要由CSDN通过智能技术生成

我想在他们登录我的网站之前检查某人的密码和用户名.密码全部存储在password_hash($password1,PASSWORD_BCRYPT);我不确定我做错了什么.目前,无论我输入什么,它总是说不正确.

require 'privstuff/dbinfo.php';

$username = $_POST["username"];

$password1 = $_POST["password1"];

$mysqli = new mysqli(DB_SERVER, DB_USER, DB_PASSWORD, DB_DATABASE);

if(mysqli_connect_errno()) {

echo "Connection Failed. Please send an email to owner@othertxt.com regarding this problem.";

exit();

}

if ($stmt = $mysqli->prepare("SELECT `username`, `password` FROM `accounts` WHERE username = ? AND password = ?")) {

$result = mysqli_query($mysqli,"SELECT `password` FROM `accounts` WHERE username = $username");

$stmt->bind_param("ss", $username, password_verify($password1, $result);

$stmt->execute();

$stmt->store_result();

if ($stmt->num_rows) {

echo("Success");

}

else {

echo("Incorrect");

}

}

$mysqli->close();

?>

这是register.php

require 'privstuff/dbinfo.php';

$firstname = $_POST["firstname"];

$password1 = $_POST["password1"];

$email = $_POST["email"];

$ip = $_SERVER['REMOTE_ADDR'];

$username = $_POST["username"];

$mysqli = new mysqli(DB_SERVER, DB_USER, DB_PASSWORD, DB_DATABASE);

if(mysqli_connect_errno()) {

echo "Connection Failed. Please send an email to owner@othertxt.com regarding this problem.";

exit();

}

if ($stmt = $mysqli->prepare("INSERT INTO `accounts`(`firstname`, `username`, `password`, `email`, `ip`) VALUES (?,?,?,?,?)")) {

$db_pw = password_hash($password1, PASSWORD_BCRYPT);

$stmt->bind_param("sssss", $firstname, $username, $db_pw, $email, $ip);

$stmt->execute();

if ($stmt->affected_rows > 0) {

echo "Account successfuly created";

}

$stmt->close();

}

$stmt->close();

$mysqli->close();

?>

解决方法:

我修复了这个问题..我错误地使用了password_verify.

require 'privstuff/dbinfo.php';

$username = $_POST["username"];

$password1 = $_POST["password1"];

$mysqli = new mysqli(DB_SERVER, DB_USER, DB_PASSWORD, DB_DATABASE);

// Check connection

if(mysqli_connect_errno()) {

echo "Connection Failed: " . mysqli_connect_errno();

exit();

}

/* create a prepared statement */

if ($stmt = $mysqli->prepare("SELECT `password` FROM `accounts` WHERE username = ?")) {

/* Bind parameters: s - string, b - blob, i - int, etc */

$stmt -> bind_param("s", $username);

/* Execute it */

$stmt -> execute();

/* Bind results */

$stmt -> bind_result($result);

/* Fetch the value */

$stmt -> fetch();

/* Close statement */

$stmt -> close();

}

if(password_verify($password1, $result))

{

session_start();

$_SESSION['loggedin'] = true;

$_SESSION['username'] = $username;

echo '';

}else{

echo '';

}

$mysqli->close();

?>

标签:php,hash,database,mysqli

来源: https://codeday.me/bug/20191009/1876612.html

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值