使用php和mySql进行用户身份验证

时间:2012-05-15 07:44:41

标签: php mysql forms

我在以下代码中面临挑战;请帮忙:

<?php
    session_start();
    $con = mysql_connect("localhost","root","");
    if (!$con){
       die('Could not connect: ' . mysql_error());
    }

    $db_exist = mysql_select_db("seta", $con);

    $myUName = $_POST["username"];
    $myPwd = $_POST["pwd"];
    $loFmUname = strtolower($myUName);

    if($db_exist){
        $sql = "SELECT * FROM Persons WHERE $loFmUname = 'strtolower($db_field['UserName'])' AND $myPwd = '$db_field['UserPwd']'";
        $result = mysql_query($sql);

        if($result){
            $_session['loged'] = '$loFmUname';
            header('location:index.html');
            die();
        }

        else{
            echo"Invalid username and/or password please";
            echo "<a href='login.php'>try again</a>";
        }

    }

    else{
        echo "Sorry Database Not Found";
    }


 mysql_close($con);
 ?>
  

错误发生在第15行。

请注意,strtolower()用于忽略区分大小写的用户名。

2 个答案:

答案 0 :(得分:0)

更改行

$sql = "SELECT * FROM Persons WHERE $loFmUname = 'strtolower($db_field['UserName'])' AND $myPwd = '$db_field['UserPwd']'";

通过这个

$sql = "SELECT * FROM Persons WHERE $loFmUname = '".strtolower($db_field['UserName'])."' AND $myPwd = '".$db_field['UserPwd']."'";

这可能会对你有所帮助。

由于

答案 1 :(得分:0)

在对变量内的变量进行操作时,需要使用点分隔符。

此外,$_SESSION['loged'] = '$loFmUname';应该是那个,还是$_SESSION['logged'] = '$loFmUname';

<?php
session_start();
$con = mysql_connect("localhost","root","");
if (!$con){
   die('Could not connect: ' . mysql_error());
}

$db_exist = mysql_select_db("seta", $con);

$myUName = $_POST["username"];
$myPwd = $_POST["pwd"];
$loFmUname = strtolower($myUName);

if($db_exist){
    $result = mysql_query("SELECT * FROM Persons WHERE $loFmUname='" . strtolower($db_field['UserName']) . "' AND $myPwd='$db_field['UserPwd']' ");

    if($result){
        $_SESSION['loged'] = '$loFmUname';
        header('Location: index.html');
        die();
    } else {
        echo "Invalid username and/or password please";
        echo "<a href='login.php'>try again</a>";
    }
} else {
    echo "Sorry Database Not Found";
}

mysql_close($con);
?>