PHP   发布时间:2022-04-04  发布网站:大佬教程  code.js-code.com
大佬教程收集整理的这篇文章主要介绍了PHP登录脚本和SQL查询始终返回相同的用户ID大佬教程大佬觉得挺不错的,现在分享给大家,也给大家做个参考。

我发布了一个问题,寻求帮助来解决我遇到的问题,由于已本地化,因此已关闭.我现在解决了我的问题.

我问的原始问题可以看到PHP Login Script Returning Same user id?.

我的登录脚本有问题.一切似乎都正常,我没有任何错误.

基本上,当我登录时,从数据库中检索到的user_uid(用户uid)始终为3,由于某种原因,它没有获得正确的user_uid,但是存储在会话中的所有其他详细信息都是正确的.

引起问题的查询是这一

$stmt = $dbh->prepare("
     SELECT
         *
     FROM
         users, users_roles, users_profiles
     WHERE
         user_login = :username
     OR
         user_email = :email

     LIMIT 1");

如果我从SQL查询删除users_roles和users_profiles,而只是从users表中检索,它将获得正确的user_uid,这一定与我要从多个表中检索并且查询在某处混乱有关.

这是我的架构和SQL查询http://sqlfiddle.com/#!2/3cc32/1/0sqlfiddle链接

下面是回显的值数组,由于某种原因,即使以测试帐户PHPlover身份登录user_uid假定为6,它也显示user_uid’3′(位于表的第一行)似乎在某处发生冲突.

经过进一步测试,似乎它从user表中获得了正确的数据,但user_uid除外,但是它从users_profiles和users_roles中检索了数据库第一行的信息,也许它是从users表中正确获取user_uid,但是查询可能是覆盖它.

我运行的查询是@L_169_18@myAdmin,它仍然执行相同的操作,这绝对与我的SQL查询有关,如何解决我的查询,以便它检索正确的user_uid?

Array
(
    [user_uid] => 3 // should be 6, 3 is the user_uid of the first row in database, seems to just fetch first row :/
    [user_status] => 1 
    [user_login] => PHPLover
    [user_pass] => 5e79a29e6292e7690a6bf56484140114f1374933081d499b8cc5034685950a16668868cd0886d93f9bc634a5649a6037022a5ef62e9b5d13cda24619bbdf610b;507a7ea891f609.84619944
    [user_email] => smaple@sample.com
    [user_registered] => 2012-10-14 09:58:16
    [user_display_name] => 
    [user_Failed_logins] => 0
    [id] => 3 // not sure where this is coming from  but should be 6 like user_uid
    [user_role] => subscriber
    [user_gender] => 
    [user_url] => 
    [user_R_697_11845@sn] => 
    [user_aim] => 
    [user_yim] => 
    [user_twitter] => 
    [user_facebook] => 
)

这是我的登录脚本,因为我将问题范围缩小到了SQL查询,因此无需显示它,但是我认为我会发布它,以防它帮助人们进一步了解正在发生的事情.

<?PHP
// ob_start()
ob_start();

// Include config.PHP
require_once("".$_SERVER['DOCUMENT_ROOT']."/de-admin/config.PHP");

// if user is logged in redirect them to control panel
// an already logged in user cAnnot login whilst already logged in!
alreadyloggedin();

// top.inc.PHP
require_once($top_inc);
?>

<!-- Meta start -->
<title><?PHP echo SITE_NAME; ?> - Member Login</title>
<Meta name="description" content="<?PHP echo SITE_NAME; ?> - Member Login, Sign in" />
<Meta name="keywords" content="sign up, member, login, signin, account, membership, <?PHP echo SITE_NAME; ?>" />
<!-- Meta end -->

<?PHP
// sidebar.inc.PHP
require_once($sidebar_inc);

// main.inc.PHP
require_once($main_inc);
?>

<?PHP

    if(isset($_POST['username_email'], $_POST['password'], $_POST[BOT_TEST], $_POST['token'])){

        // check if form token is valid
        IsValidFormTokenHash();

        // initialize form errors array
        $error    = array();

        // fetch form data
        $username_email = trim($_POST['username_email']);
        $password       = trim($_POST['password']);
        $bottest        = $_POST[BOT_TEST];

        // validate form data
        if(empty($username_email)){
            $error[] = 'Please enter your username or email address';
        }
        if(empty($password)){
            $error[] = 'Please enter your password';
        }
        if(!empty($bottest)){
            $error[] = 'Spambot detected, if your human please try again';
        }
        if(!empty($username_email) && !empty($password)){
            try{

                // connect to database
                $dbh = sql_con();

                // prepare query
                $stmt = $dbh->prepare("
                            SELECT
                                *
                            FROM
                                users, users_roles, users_profiles
                            WHERE
                                users.user_login = :username
                            OR
                                users.user_email = :email
                            AND
                                users.user_uid = users_roles.user_uid
                            AND
                                users.user_uid = users_profiles.user_uid
                            LIMIT 1");

                // execute query
                $stmt->execute(array(':username' => $username_email, ':email' => $username_email));

                if ($stmt->rowCount() > 0) {

                    $result = $stmt->fetch(PDO::FETCH_ASSOC);
                    echo '<pre>';
                    print_r($result);
                    echo '</pre>';
                    $user_db_pass = $result['user_pass'];

                    if(!Validatepassword($password, $user_db_pass)){
                        $error[] = 'Invalid Login Details';
                    } else {

                        $user_status = $result['user_status'];

                        if($user_status == user_STATUS_VERIFY){
                            $error[] = 'You must verify your account before you can log in';
                        }elseif($user_status == user_STATUS_SUSPENDED){
                            $error[] = 'This account has been suspended';
                        }elseif($user_status == user_STATUS_SPAM){
                            $error[] = 'This account has been marked as potentially spam';
                        } else {

                            // user valid

                            // fetch user details and assign there details to there sessions
                            $_SESSION['user_uid']          = $result['user_uid'];
                            $_SESSION['user_status']       = $result['user_status'];
                            $_SESSION['user_login']        = $result['user_login'];
                            $_SESSION['user_email']        = $result['user_email'];
                            $_SESSION['user_registered']   = $result['user_registered'];
                            $_SESSION['user_display_name'] = $result['user_display_name'];
                            $_SESSION['user_role']         = $result['user_role'];
                            $_SESSION['user_gender']       = $result['user_gender'];
                            $_SESSION['user_url']          = $result['user_url'];
                            $_SESSION['user_R_697_11845@sn']          = $result['user_R_697_11845@sn'];
                            $_SESSION['user_aim']          = $result['user_aim'];
                            $_SESSION['user_yim']          = $result['user_yim'];
                            $_SESSION['user_twitter']      = $result['user_twitter'];
                            $_SESSION['user_facebook']     = $result['user_facebook'];

                            // unset (destroy) form token
                            UnsetFormToken();

                            // On successful login get URI user was on
                            // so we can redirect them BACk to URI they was on
                            /*if(isset($_SESSION['redirect_to'])){
                                // if session redirect_to is found this means
                                // they tried to access a membersarea()
                                // so we get the URI and redirect to the
                                // secure page they tried accessing before logged in
                                $redirect_to = $_SESSION['redirect_to'];
                                // unset the session var
                                unset($_SESSION['redirect_to']);
                                // redirect
                                header("LOCATIOn: ".SITE_URl."$redirect_to");
                                exit();
                            } else {
                                header("LOCATIOn: /member/control-panel");
                                exit();
                            }*/

                            // Now logged in redirect to control panel
                            //header("LOCATIOn: /member/control-panel");
                            exit;
                        }
                    }

                } else {
                    $error[] = 'Incorrect login details';
                }

                // close database connection
                $dbh = null;

            }
            catch (PDOException $E){
                ExceptionErrorHandler($E);
                require_once($footer_inc);
                exit;
            }
        }

        // If errors found display errors
        if(!empty($error)){
            $SiteErrormessages = '';
            foreach($error as $msg){
                $SiteErrormessages .= "$msg <br />";
            }
        }
    }


    // display error messages
    if(isset($SiteErrormessages)){
        SiteErrormessages();
    }

    // the below values is to replace placeholders in tpl
    $TemplatereplacementValues = array(
        'SITE_NAME'         => SITE_NAME,
        'FORM_TOKEN_HASH'   => GenerateFormTokenHash(),
        'BOT_TEST'          => Bottest()
    );

    // signup.tpl template LOCATIOn
    $tpl = DOCUMENT_ROOT.'inc/tPL/login.tpl';

    // load signup template
    PageContentTemplate($tpl, $TemplatereplacementValues);

?>

<?PHP
// footer.inc.PHP
require_once($footer_inc);

// ob_end-flush
ob_end_flush();
?>

解决方法:

改写这个:

FROM users, users_profiles, users_roles

对此

FROM users
INNER JOIN users_profiles USING (user_uid)
INNER JOIN users_roles USING (user_uid)

…否则,您的查询会产生CROSS JOIN(至少可以这样说,效率非常低).

如果某些用户记录在users_profiles和users_roles中可能没有对应的记录,则应在此处用LEFT OUTER JOIN替换INNER JOIN(对于这些用户,在返回的行集中,对应的列值将设置为NULL).

大佬总结

以上是大佬教程为你收集整理的PHP登录脚本和SQL查询始终返回相同的用户ID全部内容,希望文章能够帮你解决PHP登录脚本和SQL查询始终返回相同的用户ID所遇到的程序开发问题。

如果觉得大佬教程网站内容还不错,欢迎将大佬教程推荐给程序员好友。

本图文内容来源于网友网络收集整理提供,作为学习参考使用,版权属于原作者。
如您有任何意见或建议可联系处理。小编QQ:384754419,请注明来意。
标签: