嗨,我想在这里添加一个区分大小写的错误陷阱在我的登录函数,顺便说一下,我正在使用MVC框架有人能帮忙吗?我想使用户名和密码区分大小写,这样输入不匹配的错误异常将发生..................我已经尝试过,但失败了,也许有人可以帮助我热去解决这个困境
//THIS IS THE CODE OF MY CONTROLLER
public function login() {
if(isLoggedIn()) {
header("Location: " .URLROOT . "/");
}
$data = [
'title' => 'Login page',
'username' => '',
'password' => '',
'usernameError' => '',
'passwordError' => ''
];
//Check for post
if($_SERVER['REQUEST_METHOD'] == 'POST'){
//Sanitize post data
$_POST = filter_input_array(INPUT_POST);
$data = [
'username' => trim($_POST['username']),
'password' => trim($_POST['password']),
'usernameError' => '',
'passwordError' => '',
];
$findUser = $this->userModel->findUser($data);
//Validate username
if(empty($data['username'])){
$data['usernameError'] = 'Please enter a username.';
}else if($findUser === false){
$data['usernameError'] = "Username not registered";
}
//Validate username
if(empty($data['password'])){
$data['passwordError'] = 'Please enter a password.';
}else if($findUser === false){
$data['passwordError'] = "Password not registered";
}
$findUser = $this->userModel->getUserDetails($data);
//Check if all errors are empty
if(empty($data['usernameError']) && empty($data['passwordError'])){
$loggedInUser = $this->userModel->login($data['username'], $data['password']);
if($loggedInUser){
$this->createUserSession($loggedInUser);
}else {
$data['passwordError'] = 'Password is incorrect. Please try again.';
$this->view('users/login',$data);
}
}
}else{
$data = [
'username' => '',
'password' => '',
'usernameError' => '',
'passwordError' => ''
];
}
//THIS IS THE CODE OF MY MODEL
public function login($username, $password) {
$this->db->query('SELECT * FROM user WHERE username = :username');
//Bind value
$this->db->bind(':username', $username);
$row = $this->db->single();
$hashedPassword = !empty($row) ? $row->password:'';
if(password_verify($password, $hashedPassword)){
return $row;
}else {
return false;
}
}
$this->view('users/login', $data);
}
区分大小写错误陷阱
2条答案
按热度按时间cuxqih211#
如果您需要进行区分大小写的查询,使用BINARY运算符非常容易,它会强制进行逐字节比较:
7uzetpgm2#
密码是区分大小写的,因为它使用的是原生的
password_hash
和password_verify
函数,所以可以很容易地使用以下函数进行测试:如果您真的希望用户名区分大小写,也可以对用户名字段使用区分大小写的排序规则,例如
utf8mb4_0900_as_cs
,more info here。测试用例: