The verification page receives one opaque token, hashes it, finds the matching pending record, checks the expiry and then activates the member account. The token should be single-use.
$token = trim(
(string)($_GET['token'] ?? '')
);
if (
!preg_match(
'/^[a-f0-9]{64}$/',
$token
)
) {
http_response_code(400);
exit('Invalid verification link.');
}
$tokenHash = hash(
'sha256',
$token
);
$stmt = $connection->prepare(
'SELECT status_id, mem_id, status, expires_at
FROM mem_status
WHERE token_hash = ?
LIMIT 1'
);
$stmt->bind_param('s', $tokenHash);
$stmt->execute();
If the token is absent, expired or already used, show a neutral message and offer a new verification email rather than exposing internal record details.
$connection->begin_transaction();
try {
$stmt = $connection->prepare(
'UPDATE mem_signup
SET status = ?
WHERE mem_id = ?'
);
$verified = 'C';
$stmt->bind_param(
'si',
$verified,
$memId
);
$stmt->execute();
$stmt = $connection->prepare(
'UPDATE mem_status
SET status = ?
WHERE status_id = ?'
);
$used = 'C';
$stmt->bind_param(
'si',
$used,
$statusId
);
$stmt->execute();
$connection->commit();
} catch (Throwable $error) {
$connection->rollback();
throw $error;
}
Related tutorials: MySQLi SELECT, UPDATE and switch.
After verification, continue to member login.
$mem_id=$_GET['mem_id'];
$status_id=$_GET['status_id'];
$email=$_GET['email'];
$userid=$_GET['userid'];
$word=$_GET['word'];case 'B':
if($userid==$row->userid && $word==$row->word && $email==$row->email && $mem_id==$row->mem_id){
// update mem_signup table with status=C
// update mem_status table with status=C
//--
}else{
$msg .=" You have followed a wrong link , Please check your email again ";
$msg_status='danger';
}
break;switch ($status){
case 'C':
$msg .=" You have already confirmed your email address, You can <a href=login.php>Login</a> ";
$msg_status='info';
break;
-----
}
Author & Instructor at plus2net
I write and maintain practical tutorials on Python, PHP, SQL, JavaScript, HTML, jQuery, and web development at plus2net. The tutorials focus on clear explanations, working examples, and code that readers can test and adapt while learning.