一体式PHP/MySQL注册/登录表单isn';行不通
我正在制作一个多合一的注册/登录脚本,如果未设置$\u POST,它将首先显示注册表单。如果是,但必填字段未填充,则会再次重定向到页面,重新设置$\u POST。如果填写了所有字段,那么如果设置了提交按钮$u POST[“login”]的名称,则表单将确认登录并设置一个文本块,这是一个页面,用于将用户重定向到购物篮或返回商店。如果设置了提交按钮$\u POST[“register”],则用户希望注册,并生成并提交插入查询。如果此查询未返回受影响的行,则脚本将检查用户是否已注册。如果是这样,请让他们登录,并按照正常登录方式向他们显示重定向页面。否则,如果脚本返回1个受影响的行,则我假设插入成功(如果查询失败,则脚本中断) 如果点击login,登录就可以工作,如果错过了必填字段,重定向就可以工作,但仅此而已。我看不出问题所在,也没有错误——我只是在其他情况下得到一个空白屏幕。恐怕这是一大块代码一体式PHP/MySQL注册/登录表单isn';行不通,php,login,mysqli,registration,Php,Login,Mysqli,Registration,我正在制作一个多合一的注册/登录脚本,如果未设置$\u POST,它将首先显示注册表单。如果是,但必填字段未填充,则会再次重定向到页面,重新设置$\u POST。如果填写了所有字段,那么如果设置了提交按钮$u POST[“login”]的名称,则表单将确认登录并设置一个文本块,这是一个页面,用于将用户重定向到购物篮或返回商店。如果设置了提交按钮$\u POST[“register”],则用户希望注册,并生成并提交插入查询。如果此查询未返回受影响的行,则脚本将检查用户是否已注册。如果是这样,请让他
<?php
if(!$_POST) {
//hasn't seen the registration form
//display registration form
$display_block = "
<form method=\"POST\" action=\"".$_SERVER["PHP_SELF"]."\">
<p>Please fill in the registration field (required fields marked with <span class=\"req\"><</span>)<br />
First name: <input type=\"text\" name=\"f_name\" size=\"25\" maxlength=\"50\" /><span class=\"req\"><</span><br />
Last name: <input type=\"text\" name=\"l_name\" size=\"25\" maxlength=\"50\" /><span class=\"req\"><</span><br />
Address: <input type=\"text\" name=\"address\" size=\"50\" maxlength=\"150\" /><br />
Town: <input type=\"text\" name=\"town\" size=\"50\" maxlength=\"150\" /><br />
City: <input type=\"text\" name=\"city\" size=\"50\" maxlength=\"150\" /><br />
Post Code: <input type=\"text\" name=\"postcode\" size=\"10\" maxlength=\"10\" /><br />
Username: <input type=\"text\" name=\"username\" size=\"25\" maxlength=\"25\" /><span class=\"req\"><</span><br />
Confirm username: <input type=\"text\" name=\"usernameConfirm\" size=\"25\" maxlength=\"25\" /><span class=\"req\"><</span><br />
Password: <input type=\"password\" name=\"password\" size=\"25\" maxlength=\"25\" /><span class=\"req\"><</span><br />
Confirm password: <input type=\"password\" name=\"passwordConfirm\" size=\"25\" maxlength=\"25\" /><span class=\"req\"><</span><br />
<br />
<input type=\"submit\" name=\"register\" value=\"Register\" /><br /><br />
Already a member? <input type=\"submit\" name=\"login\" value=\"Login\" />
</p>";
} else if ((!isset($_POST["username"])) || (!isset($_POST["usernameConfirm"])) || (!isset($_POST["password"])) || (!isset($_POST["passwordConfirm"]))) {
//hasn't filled out all the fields
header("Location: ".$_SERVER["PHP_SELF"]."");
exit;
} else if($_POST["login"]) {
//user is logging in, so connect to server and select database, check they are registered and their details are right
$mysqli = mysqli_connect(hostname,username,pass,dbname);
//create and issue the query
$sql = "SELECT f_name, l_name FROM auth_users WHERE username='".$_POST["username"]."' AND password=PASSWORD('".$_POST["password"]."')";
$sql_res =mysqli_query($mysqli, $sql) or die(mysqli_error($mysqli));
//get the number of rows in the result set; should be 1 if a match
if(mysqli_num_rows($sql_res) == 1) {
//if authorized, get the values of f_name, l_name
while($info = mysqli_fetch_array($sql_res)) {
$f_name = stripslashes($info["f_name"]);
$l_name = stripslashes($info["l_name"]);
}
//set authorization cookie
setcookie("auth", "1", 0, "/", "sinaesthesia.co.uk", 0);
//create display string
$display_block = "<p>".$f_name." ".$l_name." is authorized.</p>
<p>You are now logged in.</p>
<a href=\"basket.php5\">View Basket</a> | <a href=\"home.php5\">Continue Shopping</a>";
} else if($_POST["register"]) {
//connect to db and issue registration query
$mysqli = mysqli_connect(hostname,username,pass,dbname);
$register_sql = "INSERT INTO aromaMaster (username, password, date_registered) VALUES ('".$_POST["username"]."',PASSWORD('".$_POST["password"]."'),now())";
$register_res = mysqli_query($mysqli, $register_sql) or die(mysqli_error($mysqli));
if (mysqli_num_rows($register_res) != 1) {
//registration failed - perhaps duplicate account
$check_sql = "SELECT username, password FROM aromaMaster WHERE username='".$_POST["username"]."' AND password=PASSWORD('".$_POST["password"]."')";
$check_res = mysqli_query($mysqli, $check_sql) or die(mysqli_error($mysqli));
if(mysqli_num_rows($check_res) == 1) {
//already a member
//set cookie
//set authorization cookie
setcookie("auth", "1", 0, "/", "sinaesthesia.co.uk", 0);
$display_block = "
<p>You are already registered.</p>
<a href=\"basket.php5\">View Basket</a> | <a href=\"home.php5\">Continue Shopping</a>";
}
} else {
//success
$display_block = "
<p>You are registered!</p>
<a href=\"basket.php5\">View Basket</a> | <a href=\"home.php5\">Continue Shopping</a>";
}
}
mysqli_close($mysqli);
}
?>
<html>
<head>
<title>Login / Register</title>
</head>
<body>
<?php echo "$display_block"; ?>
</body>
</html>
您不想将用户的字符串直接放入查询中。
Hai,我知道,但这只是在开发阶段——在我考虑恶意用户之前,我需要工作机制。“安全性,就像正确性,不是附加功能。”--Andrew Tanenbaum。这不是对你问题的回答,但你的代码将从尽可能多地将HTML布局与代码分离中受益。这就是为什么这么多人认为PHP是一种可怕的语言。我已经完全放弃了这一点,它是一个完全独立的脚本!