2017-05-25 70 views
0

我正在使用angularJS和PHP在後端的應用程序,我想在我的應用程序中實現身份驗證,並且我嘗試了下面粘貼的代碼,但它不會生成任何錯誤,任何消息,當我嘗試輸入用戶名和密碼時,無論用戶輸入什麼內容,都會轉到view'admin,這意味着它不檢查用戶和密碼。在'client'表的數據庫中,我有: NomClient和MDP(密碼)。如何檢查用戶和密碼身份驗證

的login.html

<ion-content class="padding" ng-controller="loginCtrl"> 
<div class="list list-inset" > 
<label class="item item-input"> 
     <input type="text" placeholder="nom" required="" ng-model="NomClient"> 
</label> 
<label class="item item-input"> 
     <input type="password" placeholder="Password" ng-model="mdp"> 
</label> 
    <button class="button button-block button-positive" ng-click="submit()">Login</button>  
</ion-content> 

app.js

app.controller('loginCtrl', function($scope,$state,$http){ 
    $scope.submit= function(){ 
const url = 'http://localhost/deb/login.php'; 
const postBody = { 
    NomClient: $scope.NomClient, 
    mdp: $scope.mdp 
}; 

$http.post(url, postBody).then(data => { 
    $location.path('/admin'); 
}); 
}; 

的login.php提前

<?php 

$data = json_decode(file_get_contents("php://input")); 

$connect = mysqli_connect("localhost", "root", "", "tem"); 


$response['status'] = 0; 
$response['message'] = ''; 
$NomClient=mysqli_real_escape_string($connect, $data->NomClient); 
$mdp=mysqli_real_escape_string($connect, $data->mdp); 


$query = 'SELECT * FROM `client` WHERE NomClient = "'.$NomClient.'" AND mdp= "'.$mdp.'"'; 


if(mysqli_connect_errno()){ 
    $response['status'] = 0; 
    $response['message'] = "Failed to connect to MySQL: ".mysqli_connect_error(); 
    echo jsone_encode($response);exit; 
} 

$result = mysqli_query($connect, $query); 
$rowcount=mysqli_num_rows($result); 
if($rowcount>0){ 
    $response['status'] = 1; 
    $response['message'] = 'Login successful'; 
} 
else{ 
    $response['status'] = 0; 
    $response['message'] = 'Invalid username of password'; 
} 

echo json_encode($response);exit; 
?> 

感謝

回答

-1

確定。這裏有許多問題。首先,您應該使用準備好的語句進行查詢。

$stmt = mysqli_prepare($link,"SELECT * FROM client WHERE NomClient = ? AND mdp=?;"); 
mysqli_stmt_bind_param($stmt,'ss', $NomClient, $mdp); 
mysqli_stmt_execute($stmt); 
mysqli_stmt_store_result($stmt); 
$rowcount = mysqli_stmt_num_rows($stmt) 
mysqli_stmt_free_result($stmt); 
mysqli_stmt_close($stmt); 

更大的問題是您存儲的密碼是明文,這是一種可怕的,可怕的密碼管理方式。請查看password_hash()和password_verify()。

+0

我同意你的觀點,但這不是他要問的:) – Sean

相關問題