【问题标题】:email validation in phpphp中的电子邮件验证
【发布时间】:2012-10-04 09:13:19
【问题描述】:

我正在尝试将我的用户名验证为电子邮件地址,但是 PHP 不允许我这样做!这里有什么问题?

//This checks if all the fields are filled or not
if (!empty($_POST['username']) || 
!empty($_POST['password']) ||
!empty($_POST['repassword']) || 
!empty($_POST['user_firstname']) ||
!empty($_POST['user_lastname']) ){
header('Location: register.php?msg=You didn\'t complete all of the required fields');
}

if (filter_var($_POST['username'], FILTER_VALIDATE_EMAIL) === false){
$errors[] = 'The email address you entered is not valid';
}

这是我在 register.php 中使用的表格

<form action="createuser.php" method="post" name="registration_form" id="registration_form">
<label>Email</label>
<input name="username" type="text" id="username" size="50" maxlength="50" /><br />

【问题讨论】:

  • 向用户发送一些带有首次密码的电子邮件并且不进行更多验证就足够了吗?
  • 我只是想确保用户输入了电子邮件作为用户名!
  • 您尝试的电子邮件是什么,还是非电子邮件? FILTER_VALIDATE_EMAIL 允许不指定全局域的本地邮件地址,例如"user@localhost" 是一个有效的电子邮件。
  • 如果我输入任何字符串,它会接受它作为电子邮件地址。我希望它只接受电子邮件地址的

标签: php html sql email-validation


【解决方案1】:

错别字?

header('Location: register.php?msg=You didn't complete all of the required fields');
                                           ^---unescaped embedded quote

你的空逻辑也有问题。您正在检查是否有任何字段 NOT 为空(例如已填写),然后抱怨它们未填写。删除! 以反转逻辑。

if (empty(...) || empty(...) || etc...)

【讨论】:

  • 谢谢!但这仍然不能解决电子邮件问题:)
  • php 怎么不让你这样做呢?它拒绝所有电子邮件地址?
  • @Marc B 这是说不要验证的一种方式:D
  • filter_var 返回过滤后的数据,例如它会返回一个有效的电子邮件地址。您正在严格测试布尔 false,但它返回一个字符串。
  • 你有一个很牛的XSS注入漏洞:goawaymom.com/login/…
【解决方案2】:

使用正则表达式来验证您的电子邮件地址

function check_email_address($email) {
  // First, we check that there's one @ symbol, 
  // and that the lengths are right.
  if (!preg_match("^[^@]{1,64}@[^@]{1,255}$", $email)) {
    // Email invalid because wrong number of characters 
    // in one section or wrong number of @ symbols.
    return false;
  }
  // Split it into sections to make life easier
  $email_array = explode("@", $email);
  $local_array = explode(".", $email_array[0]);
  for ($i = 0; $i < sizeof($local_array); $i++) {
    if
(!preg_match("^(([A-Za-z0-9!#$%&'*+/=?^_`{|}~-][A-Za-z0-9!#$%&
↪'*+/=?^_`{|}~\.-]{0,63})|(\"[^(\\|\")]{0,62}\"))$",
    $local_array[$i])) {
      return false;
    }
  }
  // Check if domain is IP. If not, 
  // it should be valid domain name
  if (!preg_match("^\[?[0-9\.]+\]?$", $email_array[1])) {
    $domain_array = explode(".", $email_array[1]);
    if (sizeof($domain_array) < 2) {
        return false; // Not enough parts to domain
    }
    for ($i = 0; $i < sizeof($domain_array); $i++) {
      if
(!preg_match("^(([A-Za-z0-9][A-Za-z0-9-]{0,61}[A-Za-z0-9])|
↪([A-Za-z0-9]+))$",
$domain_array[$i])) {
        return false;
      }
    }
  }
  return true;
}

然后检查它是否返回 true 将其重定向到位置,如果不是则简单地抛出一个错误

【讨论】:

    【解决方案3】:

    您将无法验证电子邮件,因为您的 if 语句错误.. 它正在检查任何帖子是否不为空。

    替换为

    if (empty($_POST['username']) || empty($_POST['password']) || empty($_POST['repassword']) || empty($_POST['user_firstname']) || empty($_POST['user_lastname'])) {
    

    【讨论】:

      【解决方案4】:

      对于初学者,请查看语法高亮显示为什么会出现解析错误。

      header('Location: register.php?msg=You didn't complete all of the required fields');
      

      需要成为:

      header('Location: register.php?msg=You didn\'t complete all of the required fields');
      

      【讨论】:

      • 哦,糟糕,现在就是这样!仍然没有解决我的问题。
      【解决方案5】:

      你如何使用javascript window.location?有时标题功能很敏感。并且还在表单中放置一个提交按钮,因为加载时默认字段为空。

      if(isset($_POST['your_submit_button_name'])){
      
      if (empty($_POST['username']) || 
      empty($_POST['password']) ||
      empty($_POST['repassword']) || 
      empty($_POST['user_firstname']) ||
      empty($_POST['user_lastname']) ){
      ?>
       <script>
       window.location = 'register.php?msg=You didn\'t complete all of the required fields';
       </script>
      <?php
      }
      
         if (filter_var($_POST['username'], FILTER_VALIDATE_EMAIL) === false){
         $errors[] = 'The email address you entered is not valid';
         }
      }
      

      注意:我删除“!”在你的空函数之前,因为你捕获的是空的字段。

      【讨论】:

        【解决方案6】:

        尝试使用这个解决方案:

        $FormData = $_POST;
        if(isset($FormData['button_name'])){
            $Errors = array();
            foreach ($$FormData as $key => $value) {
                if(empty($value)) $Errors[] = 'Some message';
                if($key = 'username'){
                    if(filter_var($value, FILTER_VALIDATE_EMAIL){
                        $Errors[] = 'The email address you entered is not valid';
                    } 
                }
            }
            if(empty($Errors)){
                // @todo Do some action 
            } else {
                header('Location: register.php?msg=You didn\'t complete all of the required fields');
            }
        }
        

        【讨论】:

          【解决方案7】:
          function check_email($check) {
          $expression = "/^[a-zA-Z0-9._-]+@[a-zA-Z0-9._-]+\.([a-zA-Z]{2,4})$/";
          if (preg_match($expression, $check)) {
              return true;
          } else {
              return false;
          } 
          }
          

          现在使用这个方法:

          if(!check_email($_REQUEST['ContactEmail'])){
            $register_error .="Enter the correct email address!<br />";
            $reg_error=1; 
          }
          

          【讨论】:

            猜你喜欢
            • 2011-09-25
            • 2017-03-19
            • 1970-01-01
            • 2017-10-12
            • 1970-01-01
            • 1970-01-01
            • 2012-04-10
            • 2011-01-15
            • 2011-01-22
            相关资源
            最近更新 更多