//登录的后端PHP if($ _server ['request_method'] ==='post'){$ username = htmlspecialchars($ _post ['username']); //预防XSS $ password = htmlspecialchars($ _post ['password']); //使用准备好的语句预防SQL注入$ STMT = $ PDO->准备(“从用户select * where username =:用户名”); $ stmt-> bindparam(':用户名',$ username); $ stmt-> execute(); $ user = $ stmt-> fetch(); if($ user && password_verify($ password,$ user ['password'])){//成功登录session_start(); $ _session ['user_id'] = $ user ['id'];标头('位置:dashboard.php'); } else {echo“无效的用户名或密码”。; }}
主要关键词