PHP password_verify 返回 false

标签 php mysql

我有 2 个项目 1 只是用于检查用户名和密码是否存在于数据库中,它具有 password_verify() 函数,另一个你可以注册然后登录,但在这个 1 中函数 password_verify总是返回错误,即使我认为我在两者中编写了相同的代码但更改了表名我将发布项目,所以如果有人可以帮助我,请。 我确实检查过它是否正常连接到数据库并返回正确的电子邮件结果,但是在将散列通行证与输入的通行证进行比较时,它总是错误的。

Index.php 是主页面,只包含两行 php:

  1. include("signup.php");
  2. include("login.php");

Connection.php

   <?php
$server="localhost";
$db_username="myusername";
$db_password="mypassword";
$db="test_db";

$conn=mysqli_connect($server,$db_username,$db_password,$db);


if(!$conn)
    die ("Connection Failed: ".mysqli_connect_error());


?>

signup.php

<?php
session_start();
if(isset($_POST['signup']))
{   
     function validateFormData($formData)
    {
        $formData=trim(stripcslashes(htmlspecialchars($formData)));
        return $formData;
    }

    $email=validateFormData($_POST['email']);
    $password=validateFormData($_POST['password']);

    if(!$_POST['email'])
        $error.="Please enter an email<br>";

    else if(!filter_var($_POST['email'],FILTER_VALIDATE_EMAIL))
    {
        $error.="Please enter a valid email<br>";
    }

    if(!$_POST['password'])
        $error.="Please enter a password<br>";

    else
    {
        if(strlen($_POST['password'])<8)
            $error.="Password must contain at least 8 characters<br>";

        if(!preg_match('`[A-Z]`',$_POST['password']))
            $error.="Password must contain at least one capital letter<br>";
    }

    if($error)
    {
        echo "<div class='alert alert-danger text-center lead'><a class='close red' data-dismiss='alert'>&times;</a>".$error."</div>";
    }
    else
    { 
        include('connection.php');

        $query="SELECT * FROM `diary` WHERE email='".mysqli_real_escape_string($conn,$email)."'";

        $result=mysqli_query($conn,$query);
        $results=mysqli_num_rows($result);

        if($results)
            echo "<div class='alert alert-danger text-center lead'>This email already exists, do you want to log in?<a class='close red' data-dismiss='alert'>&times;</a></div>";

        else
        {
         $selectUser=mysqli_real_escape_string($conn,$email);
         $hashedPass=password_hash($password,PASSWORD_DEFAULT);
         $query="INSERT INTO `diary`(`email`, `password`) VALUES ('$selectUser','$hashedPass')";   
         mysqli_query($conn,$query);
         echo "<div class='alert alert-success text-center lead'>You've been signed up!<a class='close green' data-dismiss='alert'>&times;</a></div>";

         $_SESSION['id']=mysqli_insert_id($conn);


        }
 }

}


?>

登录.php

<?php

if(isset($_POST['login']))
{


    function validateFormData($formData)
    {
        $formData=trim(stripcslashes(htmlspecialchars($formData)));
        return $formData;
    }


    $formEmail=validateFormData($_POST['loginEmail']);
    $formPass=validateFormData($_POST['loginPassword']);
    $newPass=password_hash($formPass,PASSWORD_DEFAULT);
    echo $newPass;

    include("connection.php");

    $query="Select * from diary where email='$formEmail' ";

    $result=mysqli_query($conn,$query);

      if(mysqli_num_rows($result)>0)
    {
        while($row=mysqli_fetch_assoc($result))
        { 
            $LogEmail= $row['email'];
            $LogPass= $row['password'];
            echo "<br>".$LogPass;

        }
        if(password_verify($newPass,$LogPass))
        {
            echo "<br>Correct Password";    
        }
          else
              echo "<br>Not Correct"; 
    }


}

?>

output of $newPass is :"$2y$10$dw0AtEExMc41p4nUB3W9kOOWTcNZmQev9jM4emNn7oQNODfu6Ld.q"

output of $LogPass is : "$2y$10$biz6Z5nxsMZXNf7p3ebqw.pksPb1VhWEmoan776rMqOC7VcFRQbrK"

索引

<?php

include("signup.php");
include("login.php");

?>
<!DOCTYPE html>
<html lang="en">
<head>
    <meta charset="UTF-8">
    <meta name="viewport" content="width=device-width, initial-scale=1.0">
    <meta name="description" content="">
    <meta name="author" content="">
    <title>Secret Diary</title>

    <link rel="stylesheet" href="css/Normalize.css">
    <link rel="stylesheet" href="bootstrap/css/bootstrap.min.css">
    <link rel="stylesheet" href="css/style.css">

    <!--[if IE]>
        <script src="https://cdnjs.cloudflare.com/ajax/libs/html5shiv/3.7.3/html5shiv.min.js"></script>
        <script src="https://cdnjs.cloudflare.com/ajax/libs/respond.js/1.4.2/respond.min.js"></script>
    <![endif]-->

</head>

<body>
    <div class="container">
      <form class="form-horizontal emailForm" role="form" method="post" action="<?php echo htmlspecialchars($_SERVER['PHP_SELF']);?>">
          <legend><h1 class="text-center">Sign Up</h1></legend>
        <div class="form-group">
          <label class="control-label col-sm-2" for="email" >Email:</label>
          <div class="col-sm-10">
             <input type="email" class="form-control" style="width:90%" id="email" placeholder="Enter Email"  name="email" value="<?php echo addslashes($_POST['email']);?>">   
          </div>
        </div>
        <div class="form-group">
          <label class="control-label col-sm-2" for="pwd">Password:</label>
          <div class="col-sm-10">
            <input type="password" class="form-control" style="width:90%" id="pwd" placeholder="Password" name="password">
          </div>
        </div>
        <div class="form-group">
          <div class="col-sm-offset-2 col-sm-10">
            <button type="submit" class="btn btn-success " id="btnClick" name="signup">Sign Up</button>
          </div>
        </div>
      </form><!--SIGN UP-->

         <form class="form-horizontal emailForm" role="form" method="post" action="<?php echo htmlspecialchars($_SERVER['PHP_SELF']);?>">
          <legend><h1 class="text-center">Log In</h1></legend>
        <div class="form-group">
          <label class="control-label col-sm-2" for="LogInEmail" >Email:</label>
          <div class="col-sm-10">
             <input type="email" class="form-control" style="width:90%" id="LogInEmail" placeholder="Enter Email"  name="loginEmail" value="<?php echo addslashes($_POST['loginEmail']);?>">   
          </div>
        </div>
        <div class="form-group">
          <label class="control-label col-sm-2" for="LogInPassword">Password:</label>
          <div class="col-sm-10">
            <input type="password" class="form-control" style="width:90%" id="LogInPassword" placeholder="Password" name="loginPassword">
          </div>
        </div>
        <div class="form-group">
          <div class="col-sm-offset-2 col-sm-10">
            <button type="submit" class="btn btn-success " id="btnClick" name="login">Log In</button>
          </div>
        </div>
      </form><!--LOG IN-->
</div>
    <script src="js/JQuery.min.js"></script>
    <script src="bootstrap/js/bootstrap.min.js" type="text/javascript"></script>
    <script src="js/script.js" type="text/javascript"></script>
</body>
</html>

最佳答案

当您包含数据库连接时,您将覆盖您的$password

include('connection.php');

有:

$password="mypassword";

之前你设置:

$password=validateFormData($_POST['password']);

因此您的散列密码不是用户密码,而是您的数据库密码。

我会在所有数据库凭证变量前加上 db_。因此您的数据库密码变量将是 $db_password。这将允许您在整个项目中拥有不同的变量(我认为)。

此外,您应该使用 $formPass,而不是 $newpass$newpass 将在 verify 函数中进行双重哈希处理。

$formEmail=validateFormData($_POST['loginEmail']);
$formPass=validateFormData($_POST['loginPassword']);
$newPass=password_hash($formPass,PASSWORD_DEFAULT);

所以改变:

if(password_verify($newPass,$LogPass))

到:

if(password_verify($formPass, $LogPass))

关于PHP password_verify 返回 false,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/38689634/

相关文章:

mysql - 是否可以从另一个 View 创建 View ?

php - 将行中的数据放入无 php 站点进行编辑

mysql - 为 GCP CloudSQL 实例永久设置 utf8mb4

php - 翻译月份名称的最佳方法

php - jQuery mobile 在 Opera Mini 浏览器中失败。如何获得错误输出?

php - 如何在新创建的对象上链接方法?

php - 在线和本地MySQL数据库需要同步时如何创建主键

mysql - SQL 更改名称 - 枚举数据类型..?

php - 如何使用来自 php 网页的 expect 脚本?

javascript - 如何将选项保存在文本文件中而不干扰电子邮件通知