Member Email Verification

The verification page receives one opaque token, hashes it, finds the matching pending record, checks the expiry and then activates the member account. The token should be single-use.

Read and Hash the Token Top ↑

$token = trim(
    (string)($_GET['token'] ?? '')
);

if (
    !preg_match(
        '/^[a-f0-9]{64}$/',
        $token
    )
) {
    http_response_code(400);
    exit('Invalid verification link.');
}

$tokenHash = hash(
    'sha256',
    $token
);

Find a Pending Unexpired Verification Top ↑

$stmt = $connection->prepare(
    'SELECT status_id, mem_id, status, expires_at
     FROM mem_status
     WHERE token_hash = ?
     LIMIT 1'
);
$stmt->bind_param('s', $tokenHash);
$stmt->execute();

If the token is absent, expired or already used, show a neutral message and offer a new verification email rather than exposing internal record details.

Activate the Account in a Transaction Top ↑

$connection->begin_transaction();

try {
    $stmt = $connection->prepare(
        'UPDATE mem_signup
         SET status = ?
         WHERE mem_id = ?'
    );
    $verified = 'C';
    $stmt->bind_param(
        'si',
        $verified,
        $memId
    );
    $stmt->execute();

    $stmt = $connection->prepare(
        'UPDATE mem_status
         SET status = ?
         WHERE status_id = ?'
    );
    $used = 'C';
    $stmt->bind_param(
        'si',
        $used,
        $statusId
    );
    $stmt->execute();

    $connection->commit();
} catch (Throwable $error) {
    $connection->rollback();
    throw $error;
}

Verification States Top ↑

  • Pending: token exists, is not expired and has not been used.
  • Verified: account is active and the verification token has been consumed.
  • Expired/invalid: do not activate; provide a resend path.

Related tutorials: MySQLi SELECT, UPDATE and switch.

Next Step Top ↑

After verification, continue to member login.

Original Source Examples Retained for Migration Reference Top ↑

Historical code: these source-page examples are retained so no learner-purpose example is silently lost. Use the modern secure patterns above for new work.

Original example 1

$mem_id=$_GET['mem_id'];
$status_id=$_GET['status_id'];
$email=$_GET['email'];
$userid=$_GET['userid'];
$word=$_GET['word'];

Original example 2

case 'B':    
if($userid==$row->userid && $word==$row->word && $email==$row->email && $mem_id==$row->mem_id){
// update mem_signup table with status=C
// update mem_status table with status=C
//--
}else{
$msg .=" You have followed a wrong link , Please check your email again  ";
$msg_status='danger';	
}	
break;

Original example 3

switch ($status){
case 'C':    
$msg .=" You have already confirmed your email address, You can <a href=login.php>Login</a> ";
$msg_status='info';
break;
	
	-----
}

Additional Original Learning Routes Top ↑






plus2net.com






✖
We use cookies to improve your browsing experience. . Learn more
HTML MySQL PHP JavaScript ASP Photoshop Articles Contact us
© 2000-2026 plus2net.com All rights reserved worldwide Privacy Policy Disclaimer