473,404 Members | 2,178 Online
Bytes | Software Development & Data Engineering Community
Post Job

Home Posts Topics Members FAQ

Join Bytes to post your question to a community of 473,404 software developers and data experts.

Help

Dal
Help! I'm trying to get a login script to work.

I get this error message

MySQL Login Error: You have an error in your SQL syntax near
''jvsd0001_customers` WHERE cust_name='testuser' AND
cust_pass='test123'' at line 1

I'm using a database called test
here is mysql table:
mysql> select * from jvsd0001_customers;
+---------+-----------+---------------+
| cust_id | cust_name | cust_password |
+---------+-----------+---------------+
| 1 | testuser | test123 |
+---------+-----------+---------------+
1 row in set (0.00 sec)

[jvsd0001@hal] pico login.php

UW PICO(tm) 4.2 File:
login.php Modified

<?php
$username = $_POST['user'];
$password = $_POST['pass'];
if (!$_POST['pass'] && !$_POST['user']) {
?>
<html><b>Member Login</b>
<br><form method="POST">Username:
<br><input type="text" name="user" value="">
<br>Password:
<br><input type="text" name="pass" value="">
<br><input type="submit" name="submit" value="Login">
<?php
} else {
mysql_connect ("localhost", "abdullah") or die ('My SQL Error: ' .
mysql_error());
mysql_select_db ("test");
$stuff = mysql_query("SELECT * FROM 'jvsd0001_customers` WHERE
username='".$cust_name."' AND password='".$cust_pass."'") or
die("MySQL
Login Error: ".mysql_error());
if (mysql_num_rows($stuff) > 0) {
echo("Logged in");
} else {
echo("Login Incorrect. Please Try Again!");
}
}
?>

What's wrong???

I can't get this script to work either.

<?php
if(!isset($HTTP_POST_VARS['cust_name'])&&!isset($HTTP_POST_VARS['cust_pass']))
{
//Visitor needs to enter a name and password
?>
<h1>Please Log In</h1>
This page is secret.
<form method="post" action="secretdb.php">
<table border="1">
<tr>
<th> Username </th>
<td> <input type="text" name="cust_name"> </td>
</tr>
<tr>
<th> Password </th>
<td> <input type="password" name="cust_pass"> </td>
</tr>
<tr>
<td colspan="2" align="center">
<input type="submit" value="Log In">
</td>
</tr>
</table>
</form>
<?php
}
else
{
// connect to mysql
$mysql = mysql_connect( 'localhost', 'abdullah');
if(!$mysql)
{
echo 'Cannot connect to database.';
exit;
}
// select the appropriate database
$mysql = mysql_select_db( 'test' );
if(!$mysql)
{
echo 'Cannot select database.';
exit;
}

// query the database to see if there is a record which matches
$query = "select count(*) from jvsd0001_customers where
cust_name = '$cust_name' and
cust_pass = '$cust_pass'";

$result = mysql_query( $query );
if(!$result)
{
echo 'Cannot run query.';
exit;
}

$count = mysql_result( $result, 0, 0 );

if ( $count > 0 )
{
// visitor's name and password combination are correct
echo '<h1>Here it is!</h1>';
echo 'I bet you are glad you can see this secret page.';
}
else
{
// visitor's name and password combination are not correct
echo '<h1>Go Away!</h1>';
echo 'You are not authorized to view this resource.';
}
}
?>

Can abody tell me what I'm doing wrong here, please!
Jul 17 '05 #1
6 3378

Well, in answer to your question, you need to change a few lines:

For starters:

mysql_connect ("localhost", "abdullah") or die ('My SQL Error: ' .
mysql_error());
mysql_select_db ("test");

should read:

$db = mysql_connect("localhost", "abdullah") or die ('My SQL Error: ' .
mysql_error());
mysql_select_db("test", $db);

Secondly:

$stuff = mysql_query("SELECT * FROM 'jvsd0001_customers` WHERE
username='".$cust_name."' AND password='".$cust_pass."'")

should read:

$stuff = mysql_query("SELECT * FROM jvsd0001_customers WHERE
username='".$cust_name."' AND password='".$cust_pass."'", $db);

This is because PHP can manage several databases at once, so you need to
give each database a variable name. I've chosen $db, but you can use
whatever you want.

Secondly, you should probably be using encrypted passwords. It's just a
good idea. It's even built right in to MySQL. Instead of using password =
"your password here", you would use password = password("your password
here"). This will encode the password into a 16-digit hexadecimal string.

Next, if a user enters a quotation mark into their username or password,
it'll screw up your query. I'm not sure if there's a simple way of fixing
this.

Hopefully, this helps.

--
Jonathan Lamothe
Founder of the Anime Void.
http://ani-void.cjb.net
Jul 17 '05 #2
Jonathan Lamothe wrote:
Next, if a user enters a quotation mark into their username or password,
it'll screw up your query. I'm not sure if there's a simple way of fixing
this.


$sql .= "WHERE '".str_replace("'","''",$dubious_user_input)."' ";

Jul 17 '05 #3
Look at your line:

username='".$cust_name."' AND password='".$cust_pass."'"

and write

username='$cust_name' AND password='$cust_pass'")

instead.
Eagle
On 24 Nov 2003 13:38:20 -0800, da**@cogeco.ca (Dal) wrote:
Help! I'm trying to get a login script to work.

I get this error message

MySQL Login Error: You have an error in your SQL syntax near
''jvsd0001_customers` WHERE cust_name='testuser' AND
cust_pass='test123'' at line 1

I'm using a database called test
here is mysql table:
mysql> select * from jvsd0001_customers;
+---------+-----------+---------------+
| cust_id | cust_name | cust_password |
+---------+-----------+---------------+
| 1 | testuser | test123 |
+---------+-----------+---------------+
1 row in set (0.00 sec)

[jvsd0001@hal] pico login.php

UW PICO(tm) 4.2 File:
login.php Modified

<?php
$username = $_POST['user'];
$password = $_POST['pass'];
if (!$_POST['pass'] && !$_POST['user']) {
?>
<html><b>Member Login</b>
<br><form method="POST">Username:
<br><input type="text" name="user" value="">
<br>Password:
<br><input type="text" name="pass" value="">
<br><input type="submit" name="submit" value="Login">
<?php
} else {
mysql_connect ("localhost", "abdullah") or die ('My SQL Error: ' .
mysql_error());
mysql_select_db ("test");
$stuff = mysql_query("SELECT * FROM 'jvsd0001_customers` WHERE
username='".$cust_name."' AND password='".$cust_pass."'") or
die("MySQL
Login Error: ".mysql_error());
if (mysql_num_rows($stuff) > 0) {
echo("Logged in");
} else {
echo("Login Incorrect. Please Try Again!");
}
}
?>

What's wrong???

I can't get this script to work either.

<?php
if(!isset($HTTP_POST_VARS['cust_name'])&&!isset($HTTP_POST_VARS['cust_pass']))
{
//Visitor needs to enter a name and password
?>
<h1>Please Log In</h1>
This page is secret.
<form method="post" action="secretdb.php">
<table border="1">
<tr>
<th> Username </th>
<td> <input type="text" name="cust_name"> </td>
</tr>
<tr>
<th> Password </th>
<td> <input type="password" name="cust_pass"> </td>
</tr>
<tr>
<td colspan="2" align="center">
<input type="submit" value="Log In">
</td>
</tr>
</table>
</form>
<?php
}
else
{
// connect to mysql
$mysql = mysql_connect( 'localhost', 'abdullah');
if(!$mysql)
{
echo 'Cannot connect to database.';
exit;
}
// select the appropriate database
$mysql = mysql_select_db( 'test' );
if(!$mysql)
{
echo 'Cannot select database.';
exit;
}

// query the database to see if there is a record which matches
$query = "select count(*) from jvsd0001_customers where
cust_name = '$cust_name' and
cust_pass = '$cust_pass'";

$result = mysql_query( $query );
if(!$result)
{
echo 'Cannot run query.';
exit;
}

$count = mysql_result( $result, 0, 0 );

if ( $count > 0 )
{
// visitor's name and password combination are correct
echo '<h1>Here it is!</h1>';
echo 'I bet you are glad you can see this secret page.';
}
else
{
// visitor's name and password combination are not correct
echo '<h1>Go Away!</h1>';
echo 'You are not authorized to view this resource.';
}
}
?>

Can abody tell me what I'm doing wrong here, please!


Jul 17 '05 #4
password = password("your password
here").


Hi !

What function is this ???????
It's not even listed in the PHP.net manual or anywhere else I look.
Am I missing something?

Eagle

Jul 17 '05 #5
Eagle wrote:
Look at your line:

username='".$cust_name."' AND password='".$cust_pass."'"

and write

username='$cust_name' AND password='$cust_pass'")

instead.
Eagle


Am I missing something or is that just a coding style issue.

Personally, I prefer the former. It separates the variables out more
clearly and is therefor easier to read for me.

I NEVER include variables references in a double quoted string literals.
But that's just my style.
Jul 17 '05 #6
"Eagle" <ea*********@lycos.com> wrote in message
news:rp********************************@4ax.com...
password = password("your password
here").


Hi !

What function is this ???????
It's not even listed in the PHP.net manual or anywhere else I look.
Am I missing something?

Eagle

It is a function in MySQL, not PHP.
Jul 17 '05 #7

This thread has been closed and replies have been disabled. Please start a new discussion.

Similar topics

21
by: Dave | last post by:
After following Microsofts admonition to reformat my system before doing a final compilation of my app I got many warnings/errors upon compiling an rtf file created in word. I used the Help...
9
by: Tom | last post by:
A question for gui application programmers. . . I 've got some GUI programs, written in Python/wxPython, and I've got a help button and a help menu item. Also, I've got a compiled file made with...
6
by: wukexin | last post by:
Help me, good men. I find mang books that introduce bit "mang header files",they talk too bit,in fact it is my too fool, I don't learn it, I have do a test program, but I have no correct doing...
3
by: Colin J. Williams | last post by:
Python advertises some basic service: C:\Python24>python Python 2.4.1 (#65, Mar 30 2005, 09:13:57) on win32 Type "help", "copyright", "credits" or "license" for more information. >>> With...
7
by: Corepaul | last post by:
Missing Help Files When I enter "recordset" as the keyword and search the Visual Basic Help index, I get many topics of interest in the resulting list. But there isn't any information available...
5
by: Steve | last post by:
I have written a help file (chm) for a DLL and referenced it using Help.ShowHelp My expectation is that a developer using my DLL would be able to access this help file during his development time...
8
by: Mark | last post by:
I have loaded Visual Studio .net on my home computer and my laptop, but my home computer has an abbreviated help screen not 2% of the help on my laptop. All the settings look the same on both...
10
by: JonathanOrlev | last post by:
Hello everybody, I wrote this comment in another message of mine, but decided to post it again as a standalone message. I think that Microsoft's Office 2003 help system is horrible, probably...
1
by: trunxnirvana007 | last post by:
'UPGRADE_WARNING: Array has a new behavior. Click for more: 'ms-help://MS.VSCC.v80/dv_commoner/local/redirect.htm?keyword="9B7D5ADD-D8FE-4819-A36C-6DEDAF088CC7"' 'UPGRADE_WARNING: Couldn't resolve...
0
by: hitencontractor | last post by:
I am working on .NET Version 2003 making an SDI application that calls MS Excel 2003. I added a menu item called "MyApp Help" in the end of the menu bar to show Help-> About. The application...
0
BarryA
by: BarryA | last post by:
What are the essential steps and strategies outlined in the Data Structures and Algorithms (DSA) roadmap for aspiring data scientists? How can individuals effectively utilize this roadmap to progress...
1
by: Sonnysonu | last post by:
This is the data of csv file 1 2 3 1 2 3 1 2 3 1 2 3 2 3 2 3 3 the lengths should be different i have to store the data by column-wise with in the specific length. suppose the i have to...
0
marktang
by: marktang | last post by:
ONU (Optical Network Unit) is one of the key components for providing high-speed Internet services. Its primary function is to act as an endpoint device located at the user's premises. However,...
0
Oralloy
by: Oralloy | last post by:
Hello folks, I am unable to find appropriate documentation on the type promotion of bit-fields when using the generalised comparison operator "<=>". The problem is that using the GNU compilers,...
0
jinu1996
by: jinu1996 | last post by:
In today's digital age, having a compelling online presence is paramount for businesses aiming to thrive in a competitive landscape. At the heart of this digital strategy lies an intricately woven...
0
by: Hystou | last post by:
Overview: Windows 11 and 10 have less user interface control over operating system update behaviour than previous versions of Windows. In Windows 11 and 10, there is no way to turn off the Windows...
0
tracyyun
by: tracyyun | last post by:
Dear forum friends, With the development of smart home technology, a variety of wireless communication protocols have appeared on the market, such as Zigbee, Z-Wave, Wi-Fi, Bluetooth, etc. Each...
0
agi2029
by: agi2029 | last post by:
Let's talk about the concept of autonomous AI software engineers and no-code agents. These AIs are designed to manage the entire lifecycle of a software development project—planning, coding, testing,...
0
isladogs
by: isladogs | last post by:
The next Access Europe User Group meeting will be on Wednesday 1 May 2024 starting at 18:00 UK time (6PM UTC+1) and finishing by 19:30 (7.30PM). In this session, we are pleased to welcome a new...

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.