我想检查我的数据库中是否已存在用户名.如果是,我想重定向回我的注册页面.我的代码用于添加用户名,但不检查用户名是否存在.请帮忙!!!这是register.php页面的代码.代码完全跳过检查"用户名"并插入数据库(如果存在或不存在).
<?php
error_reporting (E_ALL ^ E_NOTICE);
include ('dbconn.php');
session_start();
$GLOBALS[$error_message];
$GLOBALS[$username];
if(isset($_POST['submit']))
{
$error = array();
if(empty($_POST['username']))
{
$error[] = 'Please enter a username. ';
}
else
{
$username = mysqli_real_escape_string($connection, $_POST['username']);
}
if(empty($_POST['password']))
{
$error[] = 'Please enter a password. ';
}
else
{
$password = mysqli_real_escape_string($connection,$_POST['password']);
}
if(empty($_POST['cpassword']))
{
$error[] = 'Please confirm password. ';
}
else
{
$cpassword = mysqli_real_escape_string($connection,$_POST['cpassword']);
}
if($password == $cpassword)
{
$mainpassword= $password;
}
else
{
$error[] = 'Your passwords do not match. ';
}
if(empty($error))
{
$query = "SELECT * from User WHERE username=' ".$username." ' ";
$result = mysqli_query($connection, $query) or die
(mysqli_error($connection));
if(mysqli_num_rows($result)> 0)
{
$multi = "Sorry ! This Username is not available...Please choose another";
}
else{ $sql="INSERT INTO user(username,password)VALUES ('$username','$password')";
mysqli_query($connection, $sql) or die(mysqli_error($connection));
header('Location:/MySQLi/confirmation.php'); }
}
else
{
$error_message = '<span class="error">';
foreach($error as $key => $values) {
$error_message.="$values";
}
$error_message.="</span><br/><br/>";
}
}
?>
Run Code Online (Sandbox Code Playgroud)
您正在手动添加用户名周围的空格,以使其看起来不存在:
$query = "SELECT * from User WHERE username=' ".$username." ' ";
^ ^
Run Code Online (Sandbox Code Playgroud)
应该:
$query = "SELECT * from User WHERE username='".$username."' ";
Run Code Online (Sandbox Code Playgroud)
使用准备好的语句可以一次性避免这个问题和潜在的SQL注入问题:
$query = "SELECT * from User WHERE username=?";
Run Code Online (Sandbox Code Playgroud)
还要确保始终使用表名和列名:User不一定相同user.
另请注意,永远不要将纯文本密码存储在数据库中,应该对它们进行加密和散列.
| 归档时间: |
|
| 查看次数: |
5592 次 |
| 最近记录: |