Jump to content

Login Script help


PRodgers4284

Recommended Posts

I have a php login script that i am using to login to a website i am designing but im having trouble with the password field when i try to login. It code wont let me login, just keeps displaying "password incorrect" but i have entered the correct password. I have a register page that registers a users to the site and it adds the data to the database fine, but i cant seem to get it to recognize the password as it keeps telling me it incorrect. Can someone please help as i cant seem to find/solve the problem.

 

My code for the login is

 

<?php

$validation = "";

/**
* Checks whether or not the given username is in the
* database, if so it checks if the given password is
* the same password in the database for that user.
* If the user doesn't exist or if the passwords don't
* match up, it returns an error code (1 or 2). 
* On success it returns 0.
*/
function confirmUser($username, $password){
   global $conn;
   /* Add slashes if necessary (for query) */
   if(!get_magic_quotes_gpc()) {
$username = addslashes($username);
   }

   /* Verify that user is in database */
   $q = "select password from users where username = '$username'";
   $result = mysql_query($q,$conn);
   if(!$result || (mysql_numrows($result) < 1)){
      return 1; //Indicates username failure
   }

   /* Retrieve password from result, strip slashes */
   $dbarray = mysql_fetch_array($result);
   $dbarray['password']  = stripslashes($dbarray['password']);
   $password = stripslashes($password);

   /* Validate that password is correct */
   if($password == $dbarray['password']){
      return 0; //Success! Username and password confirmed
   }
   else{
      return 2; //Indicates password failure
   }
}

/**
* checkLogin - Checks if the user has already previously
* logged in, and a session with the user has already been
* established. Also checks to see if user has been remembered.
* If so, the database is queried to make sure of the user's 
* authenticity. Returns true if the user has logged in.
*/
function checkLogin(){
   /* Check if user has been remembered */
   if(isset($_COOKIE['cookname']) && isset($_COOKIE['cookpass'])){
      $_SESSION['username'] = $_COOKIE['cookname'];
      $_SESSION['password'] = $_COOKIE['cookpass'];
   }

   /* Username and password have been set */
   if(isset($_SESSION['username']) && isset($_SESSION['password'])){
      /* Confirm that username and password are valid */
      if(confirmUser($_SESSION['username'], $_SESSION['password']) != 0){
         /* Variables are incorrect, user not logged in */
         unset($_SESSION['username']);
         unset($_SESSION['password']);
         return false;
      }
      return true;
   }
   /* User not logged in */
   else{
      return false;
   }
}


/**
* Determines whether or not to display the login
* form or to show the user that he is logged in
* based on if the session variables are set.
*/
function displayLogin(){
global $validation;
   global $logged_in;
   if($logged_in){
      echo "Logged in <b>$_SESSION[username]</b>
	<br><a href=''>User Account Details</a>
	<br><a href=''>CV Page</a></li>
	<br><a href=\"logout.php\">Logout</a>";
   }
   else{
   
include "loginform.php";
echo "<p>$validation</p>";

   }
}


/**
* Checks to see if the user has submitted his
* username and password through the login form,
* if so, checks authenticity in database and
* creates session.
*/
if(isset($_POST['sublogin'])){
$_POST['user'] = trim($_POST['user']);
   /* Checks that username is in database and password is correct */
   $md5pass = md5($_POST['pass']);
   $result = confirmUser($_POST['user'], $md5pass);

   /* Check that all fields were typed in */
   if(!$_POST['user'] || !$_POST['pass']){
$validation = "You didn't fill in a required field";
   }
   /* Spruce up username, check length */
   else if(strlen($_POST['user']) > 30){
$validation = "Username is longer than 30 characters";
         }

   /* Check error codes */
   else if($result == 1){
$validation = "Username doesn't exist";
        }
   else if($result == 2){
$validation = "Incorrect Password";
       }

   /* Username and password correct, register session variables */
   $_POST['user'] = stripslashes($_POST['user']);
   $_SESSION['username'] = $_POST['user'];
   $_SESSION['password'] = $md5pass;

   /**
    * This is the cool part: the user has requested that we remember that
    * he's logged in, so we set two cookies. One to hold his username,
    * and one to hold his md5 encrypted password. We set them both to
    * expire in 100 days. Now, next time he comes to our site, we will
    * log him in automatically.
    */
   if(isset($_POST['remember'])){
      setcookie("cookname", $_SESSION['username'], time()+60*60*24*100, "/");
      setcookie("cookpass", $_SESSION['password'], time()+60*60*24*100, "/");
   }


}

/* Sets the value of the logged_in variable, which can be used in your code */
$logged_in = checkLogin();

?>

 

The code for the form is:

 

<form action="" method="post">

<p><label>Username:</label>
<input input tabindex="1" class="txtBox" type="text" name="user" maxlength="30" size="20" />
</p>
<p><label>Password: </label>
 <input input tabindex="2" class="txtBox" type="password" name="pass" maxlength="30" />
</p>
<p><label><input tabindex="3" type="checkbox" class='chkbox' name="remember">Remember Me</label>
<p> <input tabindex="4" class="go" accesskey="l" type="submit" name="sublogin" value="Login" />
<br class="spacer" />
</p>
<a href="register.php">Register</a>
</form>

 

Thanks

 

Philip

Link to comment
Share on other sites

Hey Philip, um... where is your code that grabs the info out of the textboxes? From what i can tell... you are trying to log in with a blank password. you have "global $conn" where is the code that you used for that variable? Gives us more info to work with. Another tip is at random places where you are grabbing the password, echo is out to see what it is. Another tip is that sometimes in the database the passwords are md5() encoded.

 

so what you do is...

 

grab password, md5($pass), give it to the database. simple :) hope this helps

Link to comment
Share on other sites

Hi

 

Thanks for the quick response, appreciate it your help. I managed to fix the problem, it was the registration i have, the password field name with "password1" when it should have been "password", you were right i was trying to login with a blank password, stupid mistake to make  :-[

 

Thanks again

 

Phil

Link to comment
Share on other sites

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.