Re: User validation problem (newbie issue)

From: Date: Sun, 03 Sep 2000 00:01:48 +0000
Subject: Re: User validation problem (newbie issue)
References: 1  Groups: php.db 
Request: Send a blank email to php-db+get-2594@lists.php.net to get a copy of this message
Here's a more compact approach: $query = mysql_query("SELECT COUNT(*) FROM Users WHERE Username='$Username' AND Password='$Password'") or die(mysql_error()); if (mysql_result($query, 0) == 1) { echo "Verified"; } else { echo "Error"; } The SELECT COUNT(*) will always return a number (should be 0 or 1 unless the database is broken), so you don't need to work with mysql_numrows() or anything else like that. Returning a single error is better for security purposes since it won't let the user know that they have a valid username, which is good if someone's trying to collect usernames for nefarious purposes (ditto email my password pages - don't show the user's email address in the HTML response). There is one other addition I'd make - don't compare the password directly. Store MD5 hashes of the password and use something like AND Password='" . md5($Password) . "' instead. This prevents someone from breaking into your server and getting a list of passwords, which is a good idea given how many people reuse passwords on multiple sites. If they got someone's email address and password, I'd bet that that information would let them get into many other sites. This can be harmless for, say, personalized news sites and disastrous with ecommerce. Even if all of the damage happens on other sites, most users will consider you responsible.

« previous php.db (#2594) next »