I cannot get my login form to interact with mySQL database correctly

I would like the user to log in with a username and password and if that data matches the data in the database. When I try, I don't get any errors, but it doesn't work. I am using html and php in Dreamweaver and WAM with phpMyAdmin. I will include both the form document and the php document that comes with it:


include('login.php'); // Includes Login Script

header("location: index.php");

<table width="15px" border="0">
<form form action='login.php' method='POST'>
<td><input type="text" name="username" /></td>
<td><input type="password" name="password" /></td>
  <td><input type="submit" name="submit" value="submit"/></td>




    session_start(); // Starting Session
    $error=''; // Variable To Store Error Message
    if (isset($_POST['submit'])) {
    if (empty($_POST['username']) || empty($_POST['password'])) {
    $error = "Username or Password is invalid";
    // Define $username and $password
    // Establishing Connection with Server by passing server_name, user_id   and password as a parameter
    $hostname= "localhost";
    $database = "boost";
    $username = "root";
    $password = "";
    $localhost = mysqli_connect($hostname, $username, $password, $database);
        die("Connection Failed".mysqli_error());
    // SQL query to fetch information of registerd users and finds user match.
    $sql = "SELECT * FROM `users`";
    $query = mysqli_query($localhost,$sql);
        die("Query Failed".mysqli_error($localhost));
    $rows = mysqli_num_rows($query);
    if ($rows == 1) {
    $_SESSION['login_user']=$username; // Initializing Session
    echo "You are now logged on!";
    } else {
    $error = "Username or Password is invalid";
    mysqli_close($localhost); // Closing Connection



source to share

1 answer

This answer is for hashing password_hash () and password_verify () . For both mysqli and pdo. The link below has additional links and some language about salts and the like.

It is imperative not to use user-supplied data directly with selections and inserts. Rather, bind parameters and call prepared statements in Avoid sql injection attacks . Passwords should never be stored in clear (clearartext) in databases. Rather, they must be sent via one-way hashes.

Also notice. It shows hash logging and login authorization. This is not fully functional functionality. I am trying to jump to ten bucks codecanyon ... so that it shows re-registration of the email address (login) already exists, update, mind you, in this case the insert will just fail due to the unique keyset set in the db. I leave this for you, the reader, to search and say "already registered email address".


CREATE TABLE `user_accounts2` (
  `email` varchar(100) NOT NULL,
  `password` varchar(255) NOT NULL,
  PRIMARY KEY (`id`),
  unique key(email) -- that better be the case


After running register.php and saving the user, the data might look like this:

select * from user_accounts2;
| id | email     | password                                                     |
|  1 | d@d.com   | $2y$10$U6.WR.tiOIYNGDWddfT7kevJU8uiz8KAkdxXpda9e1xuplhC/eTJS |


The first part of mysqli


    error_reporting(E_ALL); // report all PHP errors
    ini_set("display_errors", 1); // display them

    if(isset($_SESSION['userid'])!="") {
        // you are already logged in as session has been set
        header("Location: safe.php");   // note that this re-direct will at the top of that page
        // ... and there to verify the session state so no tricks can be performed
        // no tricks and gimmicks

    if(isset($_POST['register'])) {
        $email = $_POST['email'];
        $ctPassword = $_POST['password'];   // cleartext password from user
        $hp=password_hash($ctPassword,PASSWORD_DEFAULT); // hashed password using cleartext one

        // pretend the following is locked in a vault and loaded but hard coded here
        $port=3306; // comes along for the ride so I don't need to look up param order below
        // end pretend

        try {
            $mysqli= new mysqli($host, $user, $pwd, $dbname,$port);
            if ($mysqli->connect_error) {
                die('Connect Error (' . $mysqli->connect_errno . ') ' . $mysqli->connect_error);
            //echo "I am connected and feel happy.<br/>";
            $query = "INSERT INTO user_accounts2(email,password) VALUES (?,?)";
            $stmt = $mysqli->prepare($query);

            // note the 2 s below, s is for string
            $stmt->bind_param("ss", $email,$hp);    // never ever use non-sanitized user supplied data. Bind it
            // password is saved as hashed, will be verified on login page with password_verify()
            $iLastInsertId=$mysqli->insert_id;  // do something special with this (or not)
            // redirect to some login page (for now you just sit here)
        } catch (mysqli_sql_exception $e) { 
            throw $e; 
<title>Register new user</title>
<div id="reg-form">
<form method="post">
        <td><input type="email" name="email" placeholder="Email" required /></td>
        <td><input type="password" name="password" placeholder="Password" required /></td>
        <td><button type="submit" name="register">Register</button></td>
        <td><a href="index.php">Normal Login In Here</a></td>



    error_reporting(E_ALL); // report all PHP errors
    ini_set("display_errors", 1); // display them

    if(isset($_SESSION['userid'])!="") {
        // you are already logged in as session has been set
        header("Location: safe.php");   // note that this re-direct will at the top of that page
        // ... and there to verify the session state so no tricks can be performed
        // no tricks and gimmicks

    if(isset($_POST['login'])) {
        $email = $_POST['email'];
        $ctPassword = $_POST['password'];   // cleartext password from user

        // pretend the following is locked in a vault and loaded but hard coded here
        $port=3306; // comes along for the ride so I don't need to look up param order below
        // end pretend

        try {
            $mysqli= new mysqli($host, $user, $pwd, $dbname,$port);
            if ($mysqli->connect_error) {
                die('Connect Error (' . $mysqli->connect_errno . ') ' . $mysqli->connect_error);
            //echo "I am connected and feel happy.<br/>";
            $query = "select id,email,password from user_accounts2 where email=?";
            $stmt = $mysqli->prepare($query);

            // note the "s" below, s is for string
            $stmt->bind_param("s", $email); // never ever use non-sanitized user supplied data. Bind it
            $result = $stmt->get_result();
            if ($row = $result->fetch_array(MYSQLI_ASSOC)) {
                if (password_verify($ctPassword,$dbHashedPassword)) {
                    echo "right, userid=";
                    echo $_SESSION['userid'];
                    // redirect to safe.php (note safeguards verbiage at top of this file about it)
                else {
                    echo "wrong";
                    // could be overkill here, but in logout.php
                    // clear the $_SESSION['userid']
            else {
                echo 'no such record';
            // remember, there is no iterating through rows, since there is 1 or 0 (email has a unique key)
            // also, hashes are one-way functions in the db. Once you hash and do the insert
            // there is pretty much no coming back to cleartext from the db with it. you just VERIFY it

        } catch (mysqli_sql_exception $e) { 
            throw $e; 
<div id="reg-form">
<form method="post">
        <td><input type="email" name="email" placeholder="Email" required /></td>
        <td><input type="password" name="password" placeholder="Password" required /></td>
        <td><button type="submit" name="login">Login</button></td>


pdo section below

When I have time, maybe tomorrow, but for now I will point you to this answer from mine .



All Articles