使用更新 md5 密码重置密码时出现问题


Issue With Resetting Password using a update md5 password

我想使用 html 表单将密码重置为散列的 md5 密码。我将包括我的所有代码。提交表单时出现空白屏幕。我是初学者,所以请记住这一点。我检查了myphpadmin,散列密码没有改变。

<html>
<head><title> Administrator reset password page</title></head>
<body>
<form action="forgotpass.php" method="post">
<table>
<tr><td>User Name:</td><td><input type="text" name="password" /></td></tr> 
<tr><td>Password:</td><td><input type="text" name="user" /></td></tr> 
<tr><td colspan="2" align="center"><input type="submit" value="Reset Password"/></td>      </tr> 
</table>
</form>
</body>
</html>
<?php
include "connect.php"
$tmpPass = $_POST['password'];
$tmpuser= $_POST['user'];

$tmpPass = md5($tmpPass);

$sql = mysql_query("UPDATE employee set pass = $tmpPass WHERE usr = $tmpuser");
// Performs the $sql query on the server to insert the values
if ($conn->query($sql) === TRUE) {
  echo 'Password Has Been Reset Successfully';

/*
$email_message.= "Hello  ";
$email_message.= "User with username: " .$tmpUser. "'n";
$email_message.= "Your New password:  " .$_POST['password']. "'n";
$email_to = "registration@joshuamoorehead.com";
$email_subject = "Registration";
*/
else {
 echo 'Error: '. $conn->error;
}
$conn->close();
?>

字符串值周围缺少引号:

$sql = mysql_query("UPDATE employee set pass = '$tmpPass' WHERE usr = '$tmpuser'");

另外,为什么要再次运行查询?

// Performs the $sql query on the server to insert the values
if ($conn->query($sql) === TRUE) { // <-- HERE
  echo 'Password Has Been Reset Successfully';

您的$sql变量将包含查询的布尔结果,您需要检查变量是否为真,而不是再次运行查询:

if($sql === true) {
  echo 'Password Has Been Reset Successfully';