无法使用正确的密码和用户名登录。保持虚假

时间:2015-03-23 13:51:43

标签: php login

当我登录时,即使密码和用户名都是正确的,也会出现错误。

数组([0] =>该用户/密码组合不正确)

用户名和密码已激活且已存在。 的的login.php

    <?php
include 'init.php';

if(empty($_POST) === false){
    $username = $_POST['username'];
    $password = $_POST['pwd1'];

if(empty($username)|| empty($password)) {
        echo 'You need to enter username and password';
    }
    else if(user_exists($username) === true){
        if(user_active($username) === true){

        $login = login($username, $password);
        if($login === false){
            $errors[] = 'That user/password combination is incorrect' ;

        } else{

            $_SESSION['user_id'] = $login;
            ob_end_clean();
            header('Location:forum.php');
            exit();
        }
    }
    else{$errors[] = 'You haven\'t activated your account!';}
    }
    else{$errors[] = 'We can\'t find that username. Have you registered?';}

    print_r($errors);

}
?>

users.php

<?php
function logged_in(){
    return (isset($_SESSION['user_id'])) ? true :false;
}
function user_exists($username){
    $username = sanitize($username);
    $sql = "SELECT COUNT(user_id) FROM `user` WHERE username = '$username'";
    $result = mysql_query( $sql);

    return (mysql_result($result,0) ==1) ? true : false;
}
function user_active($username){
    $username = sanitize($username);
    $sql ="SELECT COUNT(user_id) FROM `user` WHERE username = '$username' AND `active` = 1";
    $result = mysql_query( $sql);
    if ($result === false){
        return false;

    }
        return (mysql_result($result,0) ==1) ? true : false;
}
function user_id_from_username($username){
    $username = sanitize($username);
    $sql = "SELECT user_id FROM `user` WHERE username = '$username'";
    $result = mysql_query( $sql);
    if ($result === false){
        return false;

    }
    return mysql_result($result,0, 'user_id');
}
function login($username, $password){

    $username = sanitize($username);
    $password = md5($password);
    $query = mysql_query("SELECT COUNT(user_id) 
        FROM `user`
        WHERE username ='$username' AND pwd1 ='$password'");

    $row = mysql_fetch_row($query); 
    if($row[0]>0){
        return user_id;
        }else{
            return false;
            } 

}

?>

general.php

<?php
function sanitize($data){
    return mysql_real_escape_string($data);}
?>

的init.php

<?php
ob_start();
session_start();

require 'connect.php';
require 'general.php';
require 'users.php';


$errors = array();
?>

1 个答案:

答案 0 :(得分:2)

您不能将$login分配给$_SESSION['user_id'],因为您之前会调用die($login);,这与exit相同,之后不会解析任何内容。改变顺序。

并祈祷你的消毒功能有效。无论如何,你最好切换到PDO,因为mysql_函数已被弃用且不安全。即使您清理$ _POST和$ _GET,您仍然可以从数据库或您解析的XML或其他来源中选择恶意值。