Re: User validation problem (newbie issue)
| From: | Chris Adams | Date: | Sun, 03 Sep 2000 00:01:48 +0000 |
| Subject: | Re: User validation problem (newbie issue) | ||
| References: | 1 | Groups: | php.db |
| Request: | Send a blank email to php-db+get-2594@lists.php.net to get a copy of this message | ||
Here's a more compact approach:
$query = mysql_query("SELECT COUNT(*) FROM Users WHERE Username='$Username'
AND Password='$Password'") or die(mysql_error());
if (mysql_result($query, 0) == 1) {
echo "Verified";
} else {
echo "Error";
}
The SELECT COUNT(*) will always return a number (should be 0 or 1 unless the
database is broken), so you don't need to work with mysql_numrows() or
anything else like that. Returning a single error is better for security
purposes since it won't let the user know that they have a valid username,
which is good if someone's trying to collect usernames for nefarious
purposes (ditto email my password pages - don't show the user's email
address in the HTML response).
There is one other addition I'd make - don't compare the password directly.
Store MD5 hashes of the password and use something like
AND Password='" . md5($Password) . "'
instead. This prevents someone from breaking into your server and getting a
list of passwords, which is a good idea given how many people reuse
passwords on multiple sites. If they got someone's email address and
password, I'd bet that that information would let them get into many other
sites. This can be harmless for, say, personalized news sites and disastrous
with ecommerce. Even if all of the damage happens on other sites, most users
will consider you responsible.