简体   繁体   中英

PHP login error - it always lets me login no matter if a user exists or not

code - not sure whats happening please help:

$accountname = $_POST['logname'];
$password = $_POST['logpassword']; 
echo '<br>';

$logsql = mysqli_query("SELECT Name FROM practice.users WHERE Name = $accountname and Password = $password;");
if (mysqli_num_rows($logsql) < 0) {
     echo 'Account doesnt exist';
}
else {
    echo 'Welcome ' . $accountname;
}
//wITHOUT TAKING SECURITY INTO CONSIDERATION AND BEST PRACTICESS CONSIDER BELOW

$accountname = $_POST['logname'];
$password = $_POST['logpassword']; 
echo '<br>';//WHY THIS LINE BREAK
//$logsql = mysqli_query("SELECT Name FROM practice.users WHERE Name = $accountname and Password = $password;");

// ADD A CONNECTION BEFORE A THE QUERY SEPERATED BY A COMMA
// ADD SINGLE QUOTES ON '$accountname' AND '$password' VARIABLES
$logsql = mysqli_query($connection, "SELECT Name FROM practice.users WHERE Name = '$accountname' AND Password = '$password'");
if (mysqli_num_rows($logsql) < 0) {
     echo 'Account doesnt exist';
}
else {
    echo 'Welcome ' . $accountname;
}

The technical post webpages of this site follow the CC BY-SA 4.0 protocol. If you need to reprint, please indicate the site URL or the original address.Any question please contact:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM