【发布时间】:2014-12-08 07:02:23
【问题描述】:
所以我不确定这里出了什么问题,我尝试了多种方法,但我无法让它工作,我按照手册但似乎没有改变,我有一个简单的登录.php ,我已经检查了我的查询,但是它可以在 mysql 上运行,我有错误报告,我怀疑这可能是因为我正在 WAMP 服务器上测试它,但我不确定这是否有任何关系请帮忙。
已编辑
<?php
session_start();
ERROR_REPORTING( E_ALL | E_STRICT );
ini_set('display_errors',1);error_reporting(-1);
include_once 'UniversalConnect.php';
class login{
public function __construct()
{
$this->dologin();
}
private function dologin()
{
$name = $_POST['name'];
$pass = $_POST['pass'];
$mysqli = new mysqli("127.0.0.1","root","root","mrt");
var_dump($mysqli);
$sql="SELECT * FROM administradores WHERE nombre_administrador= ? AND password= ?";
$stmt = $mysqli->prepare($sql);
if ( !$stmt ) {
printf('errno: %d, error: %s', $mysqli->errno, $mysqli->error);
die;
}
$stmt->bind_param("ss",$name,$pass);
if ( !$name ) {
printf('errno: %d, error: %s', $stmt->errno, $stmt->error);
}
$stmt->execute();
$stmt->store_result();
if($stmt->num_rows==1)
{
var_dump($rows);
header("location: indexSCAF.html");
else{
$errmsg_arr[] = 'Username and Password are not found';
$errflag = true;
}
if($errflag) {
$_SESSION['ERRMSG_ARR'] = $errmsg_arr;
session_write_close();
exit();
}
}
}/*close function dologin*/
}/*close class */
?>
var_dumps 给出的结果
string 'admin' (length=5)
string 'test' (length=4)
object(mysqli)[3]
public 'affected_rows' => null
public 'client_info' => null
public 'client_version' => null
public 'connect_errno' => null
public 'connect_error' => null
public 'errno' => null
public 'error' => null
public 'error_list' => null
public 'field_count' => null
public 'host_info' => null
public 'info' => null
public 'insert_id' => null
public 'server_info' => null
public 'server_version' => null
public 'stat' => null
public 'sqlstate' => null
public 'protocol_version' => null
public 'thread_id' => null
public 'warning_count' => null
object(mysqli_stmt)[4]
public 'affected_rows' => null
public 'insert_id' => null
public 'num_rows' => null
public 'param_count' => null
public 'field_count' => null
public 'errno' => null
public 'error' => null
public 'error_list' => null
public 'sqlstate' => null
public 'id' => null
object(mysqli_stmt)[4]
public 'affected_rows' => null
public 'insert_id' => null
public 'num_rows' => null
public 'param_count' => null
public 'field_count' => null
public 'errno' => null
public 'error' => null
public 'error_list' => null
public 'sqlstate' => null
public 'id' => null
null
【问题讨论】:
-
您是否尝试启用 mysqli 错误报告? php.net/manual/en/mysqli.error.php
-
您的数据库调用没有任何错误处理。将此添加到脚本的顶部以使 mysqli 抛出异常:
mysqli_report(MYSQLI_REPORT_STRICT);。除此之外,您不应该在数据库中存储纯文本密码。相反,您应该对它们进行加盐和哈希处理。 -
不应该
$stmt->bind_param("ss",$user,$pass);是$stmt->bind_param("ss",$name,$pass);吗?似乎是最合乎逻辑的解释,因为您没有$user变量。 -
是的,对不起,我刚刚改了,谢谢,但它仍然抛出所有空
标签: php mysql mysqli null prepared-statement