Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #17249 > unrolled thread

Problem validating user and hashed value in db

Started bywart2ww <fcc@bmi.net>
First post2017-01-10 12:46 -0800
Last post2017-01-11 09:22 -0500
Articles 2 on this page of 42 — 5 participants

Back to article view | Back to comp.lang.php


Contents

  Problem validating user and hashed value in db wart2ww <fcc@bmi.net> - 2017-01-10 12:46 -0800
    Re: Problem validating user and hashed value in db Jerry Stuckle <jstucklex@attglobal.net> - 2017-01-10 22:39 -0500
      Re: Problem validating user and hashed value in db wart2ww <fcc@bmi.net> - 2017-01-10 19:51 -0800
        Re: Problem validating user and hashed value in db Jerry Stuckle <jstucklex@attglobal.net> - 2017-01-10 23:28 -0500
          Re: Problem validating user and hashed value in db wart2ww <fcc@bmi.net> - 2017-01-10 22:32 -0800
            Re: Problem validating user and hashed value in db "Christoph M. Becker" <cmbecker69@arcor.de> - 2017-01-11 12:47 +0100
              Re: Problem validating user and hashed value in db Jerry Stuckle <jstucklex@attglobal.net> - 2017-01-11 09:07 -0500
                Re: Problem validating user and hashed value in db "Christoph M. Becker" <cmbecker69@arcor.de> - 2017-01-11 15:37 +0100
                  Re: Problem validating user and hashed value in db Jerry Stuckle <jstucklex@attglobal.net> - 2017-01-11 15:40 -0500
                  Re: Problem validating user and hashed value in db Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2017-01-11 23:18 +0100
                    Re: Problem validating user and hashed value in db wart2ww <fcc@bmi.net> - 2017-01-12 07:32 -0800
                      Re: Problem validating user and hashed value in db "Christoph M. Becker" <cmbecker69@arcor.de> - 2017-01-12 17:23 +0100
                        Re: Problem validating user and hashed value in db wart2ww <fcc@bmi.net> - 2017-01-12 10:18 -0800
                          Re: Problem validating user and hashed value in db "Christoph M. Becker" <cmbecker69@arcor.de> - 2017-01-12 19:36 +0100
                            Re: Problem validating user and hashed value in db wart2ww <fcc@bmi.net> - 2017-01-12 11:12 -0800
                              Re: Problem validating user and hashed value in db wart2ww <fcc@bmi.net> - 2017-01-12 12:05 -0800
                                Re: Problem validating user and hashed value in db Jerry Stuckle <jstucklex@attglobal.net> - 2017-01-12 15:20 -0500
                                  Re: Problem validating user and hashed value in db wart2ww <fcc@bmi.net> - 2017-01-12 13:51 -0800
                                    Re: Problem validating user and hashed value in db Jerry Stuckle <jstucklex@attglobal.net> - 2017-01-12 17:00 -0500
                                  Re: Problem validating user and hashed value in db wart2ww <fcc@bmi.net> - 2017-01-12 13:53 -0800
                                    Re: Problem validating user and hashed value in db Jerry Stuckle <jstucklex@attglobal.net> - 2017-01-12 17:02 -0500
                                      Re: Problem validating user and hashed value in db wart2ww <fcc@bmi.net> - 2017-01-13 07:16 -0800
                                        Re: Problem validating user and hashed value in db Jerry Stuckle <jstucklex@attglobal.net> - 2017-01-13 10:39 -0500
                                          Re: Problem validating user and hashed value in db wart2ww <fcc@bmi.net> - 2017-01-13 09:06 -0800
                                            Re: Problem validating user and hashed value in db Jerry Stuckle <jstucklex@attglobal.net> - 2017-01-13 12:58 -0500
                                              Re: Problem validating user and hashed value in db wart2ww <fcc@bmi.net> - 2017-01-13 10:30 -0800
                                                Re: Problem validating user and hashed value in db Jerry Stuckle <jstucklex@attglobal.net> - 2017-01-13 13:57 -0500
                                                  Re: Problem validating user and hashed value in db wart2ww <fcc@bmi.net> - 2017-01-13 13:29 -0800
                                                    Re: Problem validating user and hashed value in db Jerry Stuckle <jstucklex@attglobal.net> - 2017-01-13 16:57 -0500
                                                      Re: Problem validating user and hashed value in db wart2ww <fcc@bmi.net> - 2017-01-13 14:23 -0800
                                                        Re: Problem validating user and hashed value in db Jerry Stuckle <jstucklex@attglobal.net> - 2017-01-14 13:03 -0500
                                                Re: Problem validating user and hashed value in db "Christoph M. Becker" <cmbecker69@arcor.de> - 2017-01-13 20:02 +0100
                                                  Re: Problem validating user and hashed value in db Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2017-01-13 21:35 +0100
                                                    Re: Problem validating user and hashed value in db Jerry Stuckle <jstucklex@attglobal.net> - 2017-01-13 16:24 -0500
                                                      Re: Problem validating user and hashed value in db Ben Bacarisse <ben.usenet@bsb.me.uk> - 2017-01-14 02:37 +0000
                                                        Re: Problem validating user and hashed value in db wart2ww <fcc@bmi.net> - 2017-01-13 19:20 -0800
                                                        Re: Problem validating user and hashed value in db Jerry Stuckle <jstucklex@attglobal.net> - 2017-01-14 12:57 -0500
                                                        Re: Problem validating user and hashed value in db Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2017-01-14 19:47 +0100
                                                          Re: Problem validating user and hashed value in db Jerry Stuckle <jstucklex@attglobal.net> - 2017-01-14 14:00 -0500
                            Re: Problem validating user and hashed value in db Thomas 'PointedEars' Lahn <PointedEars@web.de> - 2017-01-13 16:27 +0100
                              Re: Problem validating user and hashed value in db "Christoph M. Becker" <cmbecker69@arcor.de> - 2017-01-13 16:39 +0100
            Re: Problem validating user and hashed value in db Jerry Stuckle <jstucklex@attglobal.net> - 2017-01-11 09:22 -0500

Page 3 of 3 — ← Prev page 1 2 [3]


#17276

From"Christoph M. Becker" <cmbecker69@arcor.de>
Date2017-01-13 16:39 +0100
Message-ID<o5asah$sqs$1@solani.org>
In reply to#17275
On 13.01.2017 at 16:27, Thomas 'PointedEars' Lahn wrote:

> Christoph M. Becker wrote:
> 
>> If an header is supposed to be sent, but isn't, that certainly could
>> cause all kinds of issues.  Instead of wondering whether this very issue
>> is caused by the failing header call, I suggest you fix it, and then
>> check whether the other issue still persists. :-)
> 
> Regarding the fix: the problem may not be obvious, neither may be the fix.

ACK.

> A common reason for this warning is when one does not follow the 
> recommendation in the PHP-FIG PSR-2 Coding Style Guide to not write the “?>” 
> at the end of files that contain only PHP code (I would extend that 
> recommendation to files that *end with* PHP code). [1]  Because then any 
> whitespace that follows *is* output, too.  If, for example, you have 
> configured your editor to add a newline when saving the file (or it does 
> that without asking), you will cause PHP to generate output; not so if you 
> omit the “?>”.

A *single* newline (LF or CRLF) will _not_ cause PHP to produce output,
but is rather swallowed instead, see <https://3v4l.org/A8DUT>.
Interestingly, I haven't been able to find this info in the PHP manual
(even though I recall to have it seen there) nor in the PHP language
specification[2].

> [1] <http://www.php-fig.org/psr/psr-2/#files>
[2] <https://github.com/php/php-langspec/>

-- 
Christoph M. Becker

[toc] | [prev] | [next] | [standalone]


#17257

FromJerry Stuckle <jstucklex@attglobal.net>
Date2017-01-11 09:22 -0500
Message-ID<o55euq$qbc$1@jstuckle.eternal-september.org>
In reply to#17253
On 1/11/2017 1:32 AM, wart2ww wrote:
> On Tuesday, January 10, 2017 at 8:28:10 PM UTC-8, Jerry Stuckle wrote:
>> On 1/10/2017 10:51 PM, wart2ww wrote:
>>> On Tuesday, January 10, 2017 at 7:38:51 PM UTC-8, Jerry Stuckle wrote:
>>>> On 1/10/2017 3:46 PM, wart2ww wrote:
>>>>> I have a form that only asks for a password. The valid password is encriypted using password_hash($userPW, PASSWORD_BCRYPT, [12]) and stored in the database.
>>>>>
>>>>> The connection is valid and I get a confirmation that the connection has been made. However, when it comes to validating the userpw and the hashed value I get an error message. Below is the code and where the error is occuring. Being new, I am asking for help after 6 hours of working on this.
>>>>>
>>>>> <!doctype html>
>>>>> <html lang="en">
>>>>> <head>
>>>>> <meta charset="UTF-8">
>>>>> <title>Login</title>
>>>>> <link rel="stylesheet" href="https://maxcdn.bootstrapcdn.com/bootstrap/3.3.6/css/bootstrap.min.css">
>>>>> </head>
>>>>>
>>>>> <body>
>>>>>
>>>>> <?php
>>>>> // userpw entered by user for validation is 123abc
>>>>> // $hashedPW is stored in the db
>>>>> // $hashedPW = '$2y$10$fLAVp7OMvvKzXYKHPGJ7kucfj7HxJilnrsHXo/b1FLL44d.EoSe7e';
>>>>>
>>>>> // test to see if submit button has been clicked
>>>>> if(isset($_POST['submit'])) {
>>>>> 	$userPW = trim($_POST['pass']);
>>>>> 		
>>>>> 	$userQuery = $con->prepare("SELECT userpw FROM myPasswordDb");
>>>>>
>>>>> 	$userQuery->execute([
>>>>> 		'userPW'=> $userPW
>>>>> 	]);
>>>>> 	
>>>>> 	$pw = $userQuery->fetch(PDO::FETCH_OBJ);
>>>>>
>>>>> 	$db_password = $pw->userPW; // error seems to be here - returns false
>>>>> 	
>>>>> 	if(password_verify($userPW, $db_password)){
>>>>> 		echo "<p class='bg-danger'>user verified</p>";
>>>>> 	} else {
>>>>> 		echo "<p class='bg-danger'>user not verified</p>";
>>>>> 	}
>>>>> }
>>>>>
>>>>> ?>
>>>>>
>>>>>
>>>>> <form action="" method="post" autocomplete="off">
>>>>>
>>>>> 	<label for="pass" style="margin-top: 30px; margin-left: 30px;">
>>>>> 		Password
>>>>> 		<input type="text" name="pass" style="margin-left: 10px;">
>>>>> 	</label><br><br>
>>>>>
>>>>> 	<input type="submit" name="submit">
>>>>> </form>
>>>>>
>>>>> </body>
>>>>> </html>
>>>>>
>>>>>
>>>>
>>>> You didn't provide the MySQL table definition, so this is somewhat a
>>>> guess.  But what's in $pw where you get the error?  Try
>>>>
>>>> print_r($pw);
>>>>
>>>> That should help.
>>>>
>>>> Also, be aware you aren't using any selection criteria, so every row in
>>>> the table will be retrieved.  And since you didn't use ORDER BY, the
>>>> order of retrieval is not guaranteed.  If you ever have more than one
>>>> row in the table, this will eventually cause you problems.
>>>>
>>>> You didn't post the code for your password_verify function, so it's
>>>> unknown if you'll have a problem there or not.
>>>>
>>>
>>> The table is only designed to have one field and one record so I didn't see the need for a WHERE clause.
>>>
>>> I think the verify is included: password_verify($userPW, $db_password) I have done a print_r and $pw does return the value in the table. The problem is that the next statement($db_password = $pw->userPW; // error seems to be here - returns false) is where everything stops. Nothing happens after the FETCH statement. I hope that clears it up for you. If not, let me know. Thanks.
>>>
>>
>> So, what does print_r($pw) actually show?  That is critical to the rest
>> of the code.
>>
> 
> Just ran the print_r and got nothing. In my attempts, at one point I did get the db table value but I am not now. Sorry for the confusion.
> 

OK, so you need to find out why it is empty.

What is the result of your

$userQuery->execute([
		'userPW'=> $userPW

call?  And btw - what is the 'userPW=> $userPW?  You don't have any
parameters in your SELECT statement, so there's nothing to pass.

Also, ensure you are looking at the page source when looking at the
output of print_r().  Depending on what else you have in your HTML,
output may or may not show up in the normal browser window, but always
will in the source.

-- 
==================
Remove the "x" from my email address
Jerry Stuckle
jstucklex@attglobal.net
==================

[toc] | [prev] | [standalone]


Page 3 of 3 — ← Prev page 1 2 [3]

Back to top | Article view | comp.lang.php


csiph-web