Skip to content
Advertisement

Verify hashed passwords from MySQL database using Prepared Statements

I’m trying to verify my user’s hashed password from my MySQL Database using the password_hash() and password_verify() functions. I am trying to do this with prepared PHP statements for added security but with having no luck. Anyone know why?

Here’s the code:

and here is the database:

Database Layout

What I’ve tried:

Unable to extract password hash from database with prepared statements

Verify hashed password from database

I would really appreciate some help with this.

Many thanks!

Advertisement

Answer

You have to look up the hashed password using the username, not the password, because you don’t know what the hashed password is. Then you use password_verify() to check that the entered password matches the hashed password.

User contributions licensed under: CC BY-SA
7 People found this is helpful
Advertisement