Member Login and Session Creation

Login verifies the submitted user ID and password against the stored password hash, requires the account to be verified, and creates authenticated session state. Return a generic failure message for invalid credentials.

Login Form Top ↑

<form id="login-form">
  <div class="form-group">
    <label for="userid">User ID</label>
    <input type="text"
           class="form-control"
           id="userid"
           name="userid"
           autocomplete="username">
  </div>

  <div class="form-group">
    <label for="password">Password</label>
    <input type="password"
           class="form-control"
           id="password"
           name="password"
           autocomplete="current-password">
  </div>

  <button type="submit"
          class="btn btn-primary">
    Login
  </button>
</form>

Post Login Data with jQuery Top ↑

$( "#login-form" ).on(
    "submit",
    function ( event ) {
        event.preventDefault();

        $.post(
            "loginck.php",
            $( this ).serialize(),
            null,
            "json"
        )
        .done(function ( response ) {
            if (
                response.status !==
                "success"
            ) {
                $( "#login-status" ).text(
                    "Invalid login details."
                );
                return;
            }

            window.location.assign(
                "index.php"
            );
        })
        .fail(function () {
            $( "#login-status" ).text(
                "Unable to login."
            );
        });
    }
);

See jQuery POST.

Fetch the Verified Account Top ↑

$stmt = $connection->prepare(
    'SELECT mem_id, userid, password
     FROM mem_signup
     WHERE userid = ?
       AND status = ?
     LIMIT 1'
);
$verified = 'C';
$stmt->bind_param(
    'ss',
    $userid,
    $verified
);
$stmt->execute();

Verify Password and Create Session Top ↑

if (
    !$row ||
    !password_verify(
        $password,
        $row['password']
    )
) {
    http_response_code(401);
    // Return the same generic message
    // for all invalid credentials.
    exit;
}

session_regenerate_id(true);

$_SESSION['mem_id'] =
    (int)$row['mem_id'];
$_SESSION['userid'] =
    (string)$row['userid'];

Do not display or store the session ID in page content. Configure session cookies as Secure, HttpOnly and SameSite as appropriate for your application.

Authentication Abuse Controls Top ↑

  • Rate-limit repeated login attempts.
  • Log suspicious attempts without logging passwords.
  • Use generic authentication failures to reduce account enumeration.
  • Require HTTPS.
  • Add MFA if the application risk warrants it.

Next Step Top ↑

After successful authentication, continue to the member-only home page.

Legacy login demo

Original Source Examples Retained for Migration Reference Top ↑

Historical code: these source-page examples are retained so no learner-purpose example is silently lost. Use the modern secure patterns above for new work.

Original example 1

SELECT userid, password,mem_id FROM mem_signup  WHERE userid=? and status = 'C'

Original example 2

if(password_verify($password,$row->password)){
 // create the session and welcome message 
}else { 
// Failure of login 
}

Original example 3

$_SESSION['id']=session_id();
$_SESSION['userid']=$row->userid;
$_SESSION['mem_id']=$row->mem_id;

Additional Original Learning Routes Top ↑






plus2net.com






✖
We use cookies to improve your browsing experience. . Learn more
HTML MySQL PHP JavaScript ASP Photoshop Articles Contact us
© 2000-2026 plus2net.com All rights reserved worldwide Privacy Policy Disclaimer