# Please Please Help - User Auth Probelms

**URL:** <https://forum.kirupa.com/t/please-please-help-user-auth-probelms/157799>\
**Category:** programming\
**Created:** [August 4, 2005, 11:52am UTC](https://forum.kirupa.com/t/please-please-help-user-auth-probelms/157799 "2005-08-04T11:52:58Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![WelshSteve](https://avatars.discourse-cdn.com/v4/letter/w/ec9cab/32.png) [@WelshSteve](https://forum.kirupa.com/u/WelshSteve)\
**Post date:** [August 4, 2005, 11:52am UTC](https://forum.kirupa.com/t/please-please-help-user-auth-probelms/157799/1 "2005-08-04T11:52:58Z")

</div>

Hi there i have already posted asking for help but so far no responses. All of code is zipped in my other post but i will include my PHP code in this one, I am following the user\_authentication tutorial from this site, so far i have it so it saves to the database but it doesnt recognise the user and wont let me log in using the correct details. Can someone please help me, ive been staring at this code for so long now that my head is going to explode.

**User.php**

\<?

require\_once(‘conf.inc.php’);  
require\_once(‘functions.php’);

// —  
// register new user  
// —  
function register($username,$pass,$email,$question,$answer)  
{  
GLOBAL $db, $table;  
$username = trim($username);  
$pass = trim($pass);  
$email = trim($email);  
$question = addslashes(trim($question));  
$answer = addslashes(trim($answer));  
$validEmail = valid\_email($email);  
$validName = valid\_userName($username);  
$validPass = valid\_password($pass);  
if(!$validName) return “error=invalid name”;  
if(!$validPass) return “error=invalid password”;  
if(!$validEmail) return “error=invalid email”;

// all checks ok  
$query = mysql\_query(“INSERT INTO tutorial\_user\_auth (userName,userPassword,userMail,userQuestion,userAnswer) VALUES "  
.”(’".$username."’,’".$pass."’,’".$email."’,’".$question."’,’".$answer."’)");  
if(!$query)  
{  
return “error=” . mysql\_error();  
} else {  
return “user=ok”;  
}  
}

// —  
// login, check user  
// —  
function login($username,$pass)  
{  
GLOBAL $db,$table;  
$username = trim($username);  
$pass = md5(trim($pass));  
$query = “SELECT \* FROM tutorial\_user\_auth WHERE userName = '”.$username."’ AND userPassword = ‘".$pass."’";  
$result = mysql\_query( $query ) or die (“didn’t query”);

```
 //see if there's an EXACT match
$num = mysql_num_rows( $result );
if ($num == 1){
print "status=You're in&checklog=1";
} else {
print "status=Sorry, but your user name and password did not match a user name/password combination in our database. Usernames and passwords are entered in from a different file.&checklog=2"

```

}

// —  
// forget password  
// —  
function forget($email)  
{  
GLOBAL $db,$table;  
$email = trim($email);  
$query = mysql\_query(“SELECT userName, userQuestion from tutorial\_user\_auth WHERE userMail = '”.$email."’");  
if(mysql\_num\_rows($query)\<1)  
{  
return “error=email not present into database”;  
}  
$row = mysql\_fetch\_array($query);  
return “userName=$row[userName]&userQuestion=” . stripslashes($row[‘userQuestion’]);  
}

// —  
// generate new password  
// —  
function new\_password($username,$email,$answer)  
{  
GLOBAL $db,$table;  
$username = trim($username);  
$email = trim($email);  
$answer = addslashes(trim($answer));  
$query = mysql\_query(“SELECT \* FROM tutorial\_user\_auth WHERE userName = '”.$username."’ AND userMail = ‘".$email."’ AND userAnswer = ‘".$answer."’");  
if(mysql\_num\_rows($query) \< 1)  
{  
return “error=wrong answer”;  
}  
$rand\_string = ‘’;  
// —  
// generating a random 8 chars lenght password  
// —  
for($a=0;$a\<7;$a++)  
{  
do  
{  
$newrand = chr(rand(0,256));  
} while(!eregi("^[a-z0-9]$",$newrand));  
$rand\_string .= $newrand;  
}  
$pwd\_to\_insert = md5($rand\_string);  
$new\_query = mysql\_query(“UPDATE tutorial\_user\_auth SET userPassword = '”.$pwd\_to\_insert."’ WHERE userName = ‘".$username."’ AND userMail = ‘".$email."’");  
if(!$new\_query)  
{  
return “error=unable to update value”;  
}  
return “userName=$username&new\_pass=$rand\_string”;  
}

// —  
// decisional switch  
// —  
if(isset($HTTP\_POST\_VARS[“action”]))  
{  
switch($HTTP\_POST\_VARS[“action”])  
{  
case “register”:  
$result = register($HTTP\_POST\_VARS[‘username’],$HTTP\_POST\_VARS[‘pass’],$HTTP\_POST\_VARS[‘email’],$HTTP\_POST\_VARS[‘question’],$HTTP\_POST\_VARS[‘answer’]);  
print $result;  
break;  
case “login”:  
$result = login($HTTP\_POST\_VARS[‘username’],$HTTP\_POST\_VARS[‘pass’]);  
print “user=” . $result;  
break;  
case “forget”:  
$result = forget($HTTP\_POST\_VARS[‘email’]);  
print $result;  
break;  
case “new\_password”:  
$result = new\_password($HTTP\_POST\_VARS[‘username’],$HTTP\_POST\_VARS[‘email’],$HTTP\_POST\_VARS[‘answer’]);  
print $result;  
break;  
}  
}  
?\>

**Functions.php**

\<?  
error\_reporting(E\_ALL);  
function valid\_email($email)  
{  
// check if email is valid  
if( !eregi("^[a-z0-9]+([\_\.-][a-z0-9]+)_"  
."@([a-z0-9]+([.-][a-z0-9]+))_$",$email, $regs))  
{  
return false;  
} else if( gethostbyname($regs[2]) == $regs[2] )  
{  
// if host is invalid  
return false;  
} else {  
return true;  
}  
}

function valid\_userName($name)  
{  
// check valid input name  
if(!eregi("^[a-z0-9]{8,15}$",$name))  
{  
return false;  
} else {  
return true;  
}  
}

function valid\_password($pwd)  
{  
// check valid password  
if(!eregi("^[a-z0-9]{6,8}$",$pwd))  
{  
return false;  
} else {  
return true;  
}  
}  
?\>

**config.php**

\<?php  
header(“Expires: Mon, 26 Jul 1997 05:00:00 GMT”); // Data passata  
header(“Last-Modified: " . gmdate(“D, d M Y H:i:s”) . " GMT”);  
// sempre modificato  
header(“Cache-Control: no-store, no-cache, must-revalidate”); // HTTP/1.1  
header(“Cache-Control: post-check=0, pre-check=0”, false);  
header(“Pragma: no-cache”); // HTTP/1.0  
error\_reporting(E\_ALL);  
$host = ‘localhost’;  
$dbuser = ‘root’;  
$dbpass = ‘’;  
$dbname = ‘login’;  
$table = ‘tutorial\_user\_auth’;  
$db = mysql\_connect($host,$dbuser,$dbpass) or die(“error=could not connect to $host”);  
$db = mysql\_select\_db($dbname);  
if(!$db)  
{  
print “error=could not connect to $dbname table”;  
exit;  
}  
?\>

any help would be much appreciated, i am new to the world of PHP and MySQl but i do have flash knowledge.  
steve
