php实现注册登录
PHP 注册功能实现
创建注册表单页面(register.php),包含用户名、密码、邮箱等字段
<form action="register_process.php" method="post">
<input type="text" name="username" placeholder="用户名" required>
<input type="password" name="password" placeholder="密码" required>
<input type="email" name="email" placeholder="邮箱" required>
<button type="submit">注册</button>
</form>
处理注册逻辑(register_process.php)
<?php
// 连接数据库
$db = new PDO('mysql:host=localhost;dbname=test', 'username', 'password');
// 获取表单数据
$username = $_POST['username'];
$password = password_hash($_POST['password'], PASSWORD_DEFAULT);
$email = $_POST['email'];
// 检查用户名是否已存在
$stmt = $db->prepare("SELECT id FROM users WHERE username = ?");
$stmt->execute([$username]);
if($stmt->fetch()) {
die("用户名已存在");
}
// 插入新用户
$stmt = $db->prepare("INSERT INTO users (username, password, email) VALUES (?, ?, ?)");
if($stmt->execute([$username, $password, $email])) {
header("Location: login.php");
} else {
echo "注册失败";
}
?>
PHP 登录功能实现
创建登录表单页面(login.php)
<form action="login_process.php" method="post">
<input type="text" name="username" placeholder="用户名" required>
<input type="password" name="password" placeholder="密码" required>
<button type="submit">登录</button>
</form>
处理登录逻辑(login_process.php)
<?php
session_start();
// 连接数据库
$db = new PDO('mysql:host=localhost;dbname=test', 'username', 'password');
// 获取表单数据
$username = $_POST['username'];
$password = $_POST['password'];
// 查询用户
$stmt = $db->prepare("SELECT id, password FROM users WHERE username = ?");
$stmt->execute([$username]);
$user = $stmt->fetch();
// 验证密码
if($user && password_verify($password, $user['password'])) {
$_SESSION['user_id'] = $user['id'];
header("Location: dashboard.php");
} else {
echo "用户名或密码错误";
}
?>
用户认证与会话管理
创建受保护页面(dashboard.php)检查登录状态
<?php
session_start();
if(!isset($_SESSION['user_id'])) {
header("Location: login.php");
exit;
}
// 获取当前用户信息
$db = new PDO('mysql:host=localhost;dbname=test', 'username', 'password');
$stmt = $db->prepare("SELECT username FROM users WHERE id = ?");
$stmt->execute([$_SESSION['user_id']]);
$user = $stmt->fetch();
?>
<h1>欢迎, <?php echo htmlspecialchars($user['username']); ?></h1>
<a href="logout.php">退出登录</a>
创建退出登录功能(logout.php)
<?php
session_start();
session_destroy();
header("Location: login.php");
?>
数据库表结构
创建用户表SQL语句
CREATE TABLE users (
id INT AUTO_INCREMENT PRIMARY KEY,
username VARCHAR(50) NOT NULL UNIQUE,
password VARCHAR(255) NOT NULL,
email VARCHAR(100) NOT NULL UNIQUE,
created_at TIMESTAMP DEFAULT CURRENT_TIMESTAMP
);
安全注意事项
密码必须使用password_hash()函数进行哈希处理
$password = password_hash($_POST['password'], PASSWORD_DEFAULT);
所有用户输入都应进行过滤和转义
$username = filter_input(INPUT_POST, 'username', FILTER_SANITIZE_STRING);
使用预处理语句防止SQL注入

$stmt = $db->prepare("INSERT INTO users (username, password) VALUES (?, ?)");
$stmt->execute([$username, $password]);






