dongling5411 2011-03-30 21:24
浏览 53
已采纳

如何防止更新表单上的密码字段双重md5?

On my user info update form, i let users update the pass along with other things. If they don't want to update the password in the form, they leave it blank, as in the field is left empty. On the process page, if the field is blank i insert their existing password from the db (its md5) and if they changed it i want the new password in. Below is what i am using to try and accomplish that, but it is double md5-ing no matter what:

      if (!get_magic_quotes_gpc()) {

$newpass = mysql_escape_string($_POST['password']);
$newpass = md5($_POST['password']);

    }

    // If $dob is empty
    if (empty($newpass)) {

    $newpass = "$passis"; //$passis = the password stored in db which is md5
        }
  • 写回答

3条回答 默认 最新

  • dongmou1964 2011-03-30 21:33
    关注

    Just a little reworking of your code:

      $newpass = $_POST['password'];
    
      if (!get_magic_quotes_gpc()) {
          $newpass = mysql_escape_string($newpass);
      }
    
      if(empty($newpass)) {
        $newpass = "$passis"; //$passis = existing md5'd password already stored in db
      }
      else {
        $newpass = md5($newpass); //$newpass = newly provided password needs to be md5'd before updating db
      }     
    
    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(2条)

报告相同问题?

悬赏问题

  • ¥15 微带串馈天线阵列每个阵元宽度计算
  • ¥15 keil的map文件中Image component sizes各项意思
  • ¥30 BC260Y用MQTT向阿里云发布主题消息一直错误
  • ¥20 求个正点原子stm32f407开发版的贪吃蛇游戏
  • ¥15 划分vlan后,链路不通了?
  • ¥20 求各位懂行的人,注册表能不能看到usb使用得具体信息,干了什么,传输了什么数据
  • ¥15 Vue3 大型图片数据拖动排序
  • ¥15 Centos / PETGEM
  • ¥15 划分vlan后不通了
  • ¥20 用雷电模拟器安装百达屋apk一直闪退