php注册功能实现
数据库准备
创建用户表,包含必要字段如id、username、password、email等。示例SQL:
CREATE TABLE users (
id INT AUTO_INCREMENT PRIMARY KEY,
username VARCHAR(50) NOT NULL UNIQUE,
password VARCHAR(255) NOT NULL,
email VARCHAR(100) NOT NULL UNIQUE,
created_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP
);
表单设计
HTML注册表单需包含用户名、密码、确认密码和邮箱字段:
<form action="register.php" method="post">
<input type="text" name="username" placeholder="用户名" required>
<input type="password" name="password" placeholder="密码" required>
<input type="password" name="confirm_password" placeholder="确认密码" required>
<input type="email" name="email" placeholder="邮箱" required>
<button type="submit">注册</button>
</form>
后端处理
PHP脚本register.php处理表单提交:
<?php
if ($_SERVER["REQUEST_METHOD"] == "POST") {
$username = trim($_POST["username"]);
$password = $_POST["password"];
$confirm_password = $_POST["confirm_password"];
$email = filter_var(trim($_POST["email"]), FILTER_SANITIZE_EMAIL);
// 验证输入
if (empty($username) || empty($password) || empty($email)) {
die("所有字段必须填写");
}
if ($password !== $confirm_password) {
die("两次密码输入不一致");
}
if (!filter_var($email, FILTER_VALIDATE_EMAIL)) {
die("邮箱格式无效");
}
// 密码哈希
$password_hash = password_hash($password, PASSWORD_DEFAULT);
// 数据库连接
$mysqli = new mysqli("localhost", "username", "password", "database");
if ($mysqli->connect_error) {
die("连接失败: " . $mysqli->connect_error);
}
// 检查用户名和邮箱是否已存在
$stmt = $mysqli->prepare("SELECT id FROM users WHERE username = ? OR email = ?");
$stmt->bind_param("ss", $username, $email);
$stmt->execute();
$stmt->store_result();
if ($stmt->num_rows > 0) {
die("用户名或邮箱已被使用");
}
$stmt->close();
// 插入新用户
$stmt = $mysqli->prepare("INSERT INTO users (username, password, email) VALUES (?, ?, ?)");
$stmt->bind_param("sss", $username, $password_hash, $email);
if ($stmt->execute()) {
echo "注册成功";
} else {
echo "注册失败: " . $stmt->error;
}
$stmt->close();
$mysqli->close();
}
?>
安全增强
密码使用password_hash()函数进行哈希存储,防止明文泄露。添加CSRF防护:
session_start();
if (empty($_SESSION['token'])) {
$_SESSION['token'] = bin2hex(random_bytes(32));
}
表单中添加隐藏字段:
<input type="hidden" name="token" value="<?php echo $_SESSION['token']; ?>">
后端验证token:
if (!hash_equals($_SESSION['token'], $_POST['token'])) {
die("无效的CSRF令牌");
}
输入验证
对用户输入进行严格过滤和验证:
$username = htmlspecialchars($username, ENT_QUOTES, 'UTF-8');
$email = filter_var($email, FILTER_SANITIZE_EMAIL);
错误处理
使用try-catch块捕获数据库异常:

try {
$stmt->execute();
} catch (mysqli_sql_exception $e) {
error_log($e->getMessage());
die("注册过程中发生错误");
}






