Signup collects the new member's account details, gives immediate client-side feedback, repeats every important check on the server, hashes the password, and stores the member with an unverified status until email verification succeeds.
FILTER_VALIDATE_EMAIL and check uniqueness server-side.Related tutorials: Form Validation, Password Validation and Checkbox Validation.
$( "#signup-form" ).on(
"submit",
function ( event ) {
event.preventDefault();
const $form = $( this );
const password =
$( "#password" ).val();
const confirmPassword =
$( "#password2" ).val();
if (
password !== confirmPassword
) {
$( "#signup-status" ).text(
"Passwords do not match."
);
return;
}
if (
!$( "#terms" )
.prop( "checked" )
) {
$( "#signup-status" ).text(
"Please agree to the terms."
);
return;
}
$.post(
"signupck.php",
$form.serialize(),
null,
"json"
)
.done(function ( response ) {
$( "#signup-status" ).text(
response.message
);
})
.fail(function () {
$( "#signup-status" ).text(
"Unable to create the account."
);
});
}
);
$userid = trim(
(string)($_POST['userid'] ?? '')
);
$email = trim(
(string)($_POST['email'] ?? '')
);
$password =
(string)($_POST['password'] ?? '');
$password2 =
(string)($_POST['password2'] ?? '');
$terms =
(string)($_POST['terms'] ?? '');
if (
!ctype_alnum($userid) ||
strlen($userid) < 6 ||
strlen($userid) > 15
) {
throw new RuntimeException(
'Invalid user ID.'
);
}
if (
!filter_var(
$email,
FILTER_VALIDATE_EMAIL
)
) {
throw new RuntimeException(
'Invalid email address.'
);
}
if (
strlen($password) < 8 ||
$password !== $password2
) {
throw new RuntimeException(
'Password validation failed.'
);
}
if ($terms !== 'yes') {
throw new RuntimeException(
'Terms must be accepted.'
);
}
$stmt = $connection->prepare(
'SELECT mem_id
FROM mem_signup
WHERE userid = ? OR email = ?
LIMIT 1'
);
$stmt->bind_param(
'ss',
$userid,
$email
);
$stmt->execute();
For public signup forms, consider returning a neutral response where account-enumeration risk matters rather than revealing too much about existing accounts.
$passwordHash = password_hash(
$password,
PASSWORD_DEFAULT
);
$stmt = $connection->prepare(
'INSERT INTO mem_signup
(userid, email, password, status)
VALUES (?, ?, ?, ?)'
);
$status = 'A';
$stmt->bind_param(
'ssss',
$userid,
$email,
$passwordHash,
$status
);
$stmt->execute();
See password_hash(), password_verify() and AUTO_INCREMENT.
Do not treat the new account as fully verified yet. Continue to create and send the email-verification link.
Legacy plus-signup-v2 signup demo
my_function_userid=function my_function_userid(status,str){
if(status=='NOTOK'){
$('#userid').css('border-color', 'red');
}else{
$('#userid').css('border-color', '');
}
$('#msg_userid').html(str);
}$(".btt1").click(function(event){
if(!$("#terms").prop('checked')){
my_function_terms("NOTOK","You must agree to terms and conditions ");
}else{
$.post( "signupck.php", $( "#f1" ).serialize(),function(return_data){
......
}if(!ctype_alnum($userid)){if ( strlen($userid) 15) {
---
}if(!filter_var($email,FILTER_VALIDATE_EMAIL)){
---
}if ($terms<>"yes") {
$msg=$msg."You must agree to site user terms and conditions<BR>";
$status= "NOTOK";}if ( strlen($password)< 6 ) {
$elements[msg_password2].="Password should not be less than 6 . <BR>";
$elements[pw]='F';
$status= "NOTOK";}if ( $password <> $password2) {
$elements[msg_password2].="Password does not match with re-typed password .";
$elements[pw]='F';
$status= "NOTOK";}if($stmt = $connection->prepare("SELECT userid FROM mem_signup WHERE userid=? ")){
---
}if($stmt = $connection->prepare("SELECT email FROM mem_signup WHERE email=? ")){
--
}if($_SESSION[my_captcha] != $captch){
$elements[msg_captch].= " Enter the data shown ";
$status = "NOTOK";
$elements[captch]='F';
}$password=password_hash($password,PASSWORD_DEFAULT);
Author & Instructor at plus2net
I write and maintain practical tutorials on Python, PHP, SQL, JavaScript, HTML, jQuery, and web development at plus2net. The tutorials focus on clear explanations, working examples, and code that readers can test and adapt while learning.