无法使用正确的密码和用户名登录.保持虚假


cannot log in with correct password and username. keep false

当我登录时,即使密码和用户名是正确的,它也会出错。

数组([0]=>该用户/密码组合不正确)

用户名和密码处于活动状态并且已存在。login.php

    <?php
include 'init.php';
if(empty($_POST) === false){
    $username = $_POST['username'];
    $password = $_POST['pwd1'];
if(empty($username)|| empty($password)) {
        echo 'You need to enter username and password';
    }
    else if(user_exists($username) === true){
        if(user_active($username) === true){
        $login = login($username, $password);
        if($login === false){
            $errors[] = 'That user/password combination is incorrect' ;
        } else{
            $_SESSION['user_id'] = $login;
            ob_end_clean();
            header('Location:forum.php');
            exit();
        }
    }
    else{$errors[] = 'You haven''t activated your account!';}
    }
    else{$errors[] = 'We can''t find that username. Have you registered?';}
    print_r($errors);
}
?>

users.php

<?php
function logged_in(){
    return (isset($_SESSION['user_id'])) ? true :false;
}
function user_exists($username){
    $username = sanitize($username);
    $sql = "SELECT COUNT(user_id) FROM `user` WHERE username = '$username'";
    $result = mysql_query( $sql);
    return (mysql_result($result,0) ==1) ? true : false;
}
function user_active($username){
    $username = sanitize($username);
    $sql ="SELECT COUNT(user_id) FROM `user` WHERE username = '$username' AND `active` = 1";
    $result = mysql_query( $sql);
    if ($result === false){
        return false;
    }
        return (mysql_result($result,0) ==1) ? true : false;
}
function user_id_from_username($username){
    $username = sanitize($username);
    $sql = "SELECT user_id FROM `user` WHERE username = '$username'";
    $result = mysql_query( $sql);
    if ($result === false){
        return false;
    }
    return mysql_result($result,0, 'user_id');
}
function login($username, $password){
    $username = sanitize($username);
    $password = md5($password);
    $query = mysql_query("SELECT COUNT(user_id) 
        FROM `user`
        WHERE username ='$username' AND pwd1 ='$password'");
    $row = mysql_fetch_row($query); 
    if($row[0]>0){
        return user_id;
        }else{
            return false;
            } 
}
?>

general.php

<?php
function sanitize($data){
    return mysql_real_escape_string($data);}
?>

init.php

<?php
ob_start();
session_start();
require 'connect.php';
require 'general.php';
require 'users.php';

$errors = array();
?>

您不会将$login分配给$_SESSION['user_id'],因为在此之前您调用了die($login);,这与exit相同,之后不会解析任何内容。更改顺序。

祈祷你的消毒功能发挥作用。无论如何,您最好切换到PDO,因为mysql_函数已被弃用并且不安全。即使您清除了$_POST和$_GET,您仍然可以从数据库、解析的XML或其他来源中选择恶意值。