2 回答

TA貢獻(xiàn)1934條經(jīng)驗(yàn) 獲得超2個(gè)贊
經(jīng)過上述評(píng)論的建議后,我得出了這個(gè)有效的結(jié)論。
<?php
if(isset($_POST['login'])){
$user = mysqli_real_escape_string($conn,$_POST['email']);
$pass = mysqli_real_escape_string($conn,$_POST['password']); //input entered
$query = mysqli_query($conn, "SELECT * FROM users WHERE `email` = '$user'");
$numrows = mysqli_num_rows($query);
if($numrows !=0)
{
while($row = mysqli_fetch_assoc($query))
{
$dbemail=$row['email'];
$dbpassword=$row['password'];
}
if(password_verify($pass, $dbpassword))
{
session_start();
$_SESSION['email'] = $username;
//Redirect Browser
}
}
else
{
echo "<div class='alert alert-danger alert-dismissible'>
<a href='#' class='close' data-dismiss='alert' aria-label='close'>×</a>
<strong>Warning!</strong> Invalid credentials.
</div>";
}
}?>

TA貢獻(xiàn)1946條經(jīng)驗(yàn) 獲得超3個(gè)贊
不確定,但你嘗試過嗎
password_verify(mysqli_real_escape_string($_POST['password']), $dbpassword)
我的意思是比較未加密的密碼與哈希值。在 Laravel 中
Hash::check()
還需要非哈希密碼作為參數(shù)。
- 2 回答
- 0 關(guān)注
- 221 瀏覽
添加回答
舉報(bào)