php实现登录验证
PHP 登录验证实现方法
数据库连接与用户表创建
确保已创建数据库和用户表,包含至少username和password字段。使用PDO连接数据库:
$host = 'localhost';
$dbname = 'your_database';
$username = 'db_username';
$password = 'db_password';
try {
$pdo = new PDO("mysql:host=$host;dbname=$dbname", $username, $password);
$pdo->setAttribute(PDO::ATTR_ERRMODE, PDO::ERRMODE_EXCEPTION);
} catch (PDOException $e) {
die("Connection failed: " . $e->getMessage());
}
登录表单设计
创建HTML表单提交用户名和密码:
<form action="login.php" method="post">
<input type="text" name="username" placeholder="Username" required>
<input type="password" name="password" placeholder="Password" required>
<button type="submit">Login</button>
</form>
密码验证处理
在login.php中验证用户凭据,使用password_hash()存储密码,password_verify()验证:
session_start();
if ($_SERVER['REQUEST_METHOD'] == 'POST') {
$username = $_POST['username'];
$password = $_POST['password'];
$stmt = $pdo->prepare("SELECT * FROM users WHERE username = ?");
$stmt->execute([$username]);
$user = $stmt->fetch();
if ($user && password_verify($password, $user['password'])) {
$_SESSION['user_id'] = $user['id'];
$_SESSION['username'] = $user['username'];
header("Location: dashboard.php");
exit();
} else {
$error = "Invalid username or password";
}
}
会话管理与安全措施
实现会话超时和CSRF防护:
// 设置会话过期时间(1小时)
ini_set('session.gc_maxlifetime', 3600);
session_set_cookie_params(3600);
// 生成CSRF令牌
if (empty($_SESSION['csrf_token'])) {
$_SESSION['csrf_token'] = bin2hex(random_bytes(32));
}
密码重置功能
添加密码重置选项,使用安全令牌:
// 生成重置令牌
$token = bin2hex(random_bytes(16));
$token_hash = hash("sha256", $token);
$expiry = date("Y-m-d H:i:s", time() + 60 * 30); // 30分钟有效
$stmt = $pdo->prepare("UPDATE users SET reset_token_hash = ?, reset_token_expires = ? WHERE email = ?");
$stmt->execute([$token_hash, $expiry, $email]);
输入验证与过滤
对所有用户输入进行过滤和验证:
$username = filter_input(INPUT_POST, 'username', FILTER_SANITIZE_STRING);
$password = filter_input(INPUT_POST, 'password', FILTER_SANITIZE_STRING);
错误处理与日志记录
记录登录尝试和错误:
// 记录失败尝试
if (!empty($error)) {
error_log("Failed login attempt for username: " . $username);
}
前端验证增强
添加JavaScript基础验证:

document.querySelector('form').addEventListener('submit', function(e) {
if (!this.username.value || !this.password.value) {
e.preventDefault();
alert('Both fields are required!');
}
});






