【问题标题】:Change Password in PHP在 PHP 中更改密码
【发布时间】:2012-03-23 23:47:40
【问题描述】:

我在 PHP 中有一个更改密码脚本,我想做的是从用户输入的前一个屏幕中获取变量,然后将它们与 mysql 数据库进行比较。如果旧密码与他们输入的不匹配,我希望它失败并出现错误。这是我到目前为止的代码.. 但我知道将字符串与变量进行比较是行不通的,但需要知道如何转换它们以便它们可以比较。以下是有问题的页面。

密码目前存储在数据库上的普通 txt 中,但稍后将更改为 md5。问题是如何将输入的值与从数据库中提取的值进行比较?

<html>
<head>
<title>Password Change</title>
</head>
<body>

<?php

mysql_connect("localhost", "kb1", "BajyXhbRAWSVKPsA") or die(mysql_error());
mysql_select_db("kb1") or die(mysql_error());

    $todo=mysql_real_escape_string($_POST['todo']);
    $username=mysql_real_escape_string($_POST['userid']); 
    $password=mysql_real_escape_string($_POST['password']);
    $password2=mysql_real_escape_string($_POST['password2']);
    $oldpass=mysql_real_escape_string($_POST['oldpass']);

/////////////////////////

if(isset($todo) and $todo == "change-password"){
//Setting flags for checking
$status = "OK";
$msg="";

//MYSQL query to pull the current password from the database and store it in  $q1

$results = mysql_query("SELECT password FROM kb_users WHERE username = '$username'") or             die(mysql_error());  
$q1 = mysql_fetch_array($results);
//print_r($q1)


//changing the string $oldpass to using the str_split which converts a string to an     array.

//$oldpass1 = str_split($oldpass,10);

if(!$q1)  

    {  
        echo "The username <b>$username</b> does not exist in the database.  Please         click the retry button to attempt changing the password again. <BR><BR><font face='Verdana'     size='2' color=red>$msg</font><br><center><input type='button' value='Retry'     onClick='history.go(-1)'></center>"; die();
    }  

if ($oldpass == $q1){

$msg = $msg.  "The provided password <b>$oldpass</b> is not the same as what is in the     database. Please click the retry button to attempt changing the password again.<BR><br>";

$status = "NOTOK";} 
/*
if ($q1 <> $oldpass1) {    
$msg = $msg.  "The provided password <b>$oldpass</b> is not the same as what is in the     database. Please click the retry button to attempt changing the password again.<BR><br>";
$status = "NOTOK";  }
*/

if ( strlen($password) < 3 or strlen($password) > 10 ){
$msg=$msg.  "Your new password must be more than 3 char legth and a maximum 10 char     length<BR><BR>";
$status= "NOTOK";}                  

if ( $password <> $password2 ){
$msg=$msg.  "Both passwords are not matching<BR>";
$status= "NOTOK";}                  


if($status<>"OK")
    { 
        echo "<font face='Verdana' size='2' color=black>$msg</font><br><center>    <input type='button' value='Retry' onClick='history.go(-1)'></center>";
    }
        else {
        // if all validations are passed.

            if (mysql_query("UPDATE kb_users SET password='$password' where         username='$username'") or die(mysql_error())); 

                {
                    echo "<font face='Verdana' size='2' ><center>Thanks     <br> Your password has been changed successfully. Please keep changing your password for     better security</font></center>";
                }
            }
        }


?>      
</body>
</html>

【问题讨论】:

标签: php passwords


【解决方案1】:

首先,不建议在查询中直接使用 POST 数据。您最好先将这些数据转义,以避免注入。

另外,我认为您使用 if 的方式并不是最好的方式。我认为不需要状态变量。在这种情况下,这是肯定的。 $status 在您测试它的值之前设置为 NOTOK。所以它总是NOTOK,这将导致你的脚本永远不会更新任何密码。

我将您的测试结构更改为我认为更好的结构。好好看看你想测试什么,因为现在你的测试都混在一起了。

<html>
<head>
    <title>Password Change</title>
</head>

<body>

    <?php
        // MySQL connection details

        $todo=mysql_real_escape_string($_POST['todo']);
        $username=mysql_real_escape_string($_POST['userid']); 
        $password=mysql_real_escape_string($_POST['password']);
        $password2=mysql_real_escape_string($_POST['password2']);
        $oldpass=mysql_real_escape_string($_POST['oldpass']);

        if(isset($todo) and $todo == "change-password"){

            $results = mysql_query("SELECT password FROM kb_users WHERE username = '$username'") or             die(mysql_error());  
            $q1 = mysql_fetch_array($results);

            if (!$q1) {
                // The user does not exist in the database. 
            }

            if ($oldpass == $q1) {
                // The current password matches the input from the oldpass field.

                if (strlen($password) > 3 or strlen($password) < 10) {
                    // Password meets requirements
                    if ($password == $password2) {
                        //Passwords match, update the password in the database
                    }
                    else {
                        // The new passwords do not match.
                    }
                }
                else {
                    // Password is too short / long
                }

            }
        }
    ?>
</body>

【讨论】:

  • 感谢 Sander 在更新密码之前状态不会更新为“NOTOK”,除非 2 个新密码不匹配。我已经测试了字符串长度和匹配的密码。我遇到的问题是从数据库中提取当前密码,然后将其与用户输入的旧密码进行比较。密码现在以纯文本形式存储在数据库中,但稍后将更改为哈希或 md5。因此,问题在于将输入的内容与从数据库中提取的内容进行比较
  • @mcj212 等等,我的错。您现在正在将数组与字符串进行比较。您应该指定要比较的数组元素。您应该为此使用$q1['field_name']。所以,在你的情况下$q1['password'].
猜你喜欢
  • 2011-06-29
  • 1970-01-01
  • 1970-01-01
  • 2018-11-15
  • 1970-01-01
  • 2012-02-12
  • 2016-08-14
  • 1970-01-01
  • 1970-01-01
相关资源
最近更新 更多