Send the Email Verification Link

After signup, create an opaque, one-time verification token, store only a hash of that token with an expiry time, and email the raw token to the member in an HTTPS verification URL.

Do not put account details in the verification URL. The older project placed member ID, email, user ID, status ID and a verification word in the query string. For new work, one random token is simpler and exposes less information.

Load the New Member Safely Top ↑

$memId = filter_input(
    INPUT_GET,
    'mem_id',
    FILTER_VALIDATE_INT
);

if (!$memId || $memId < 1) {
    http_response_code(400);
    exit('Invalid request.');
}

$stmt = $connection->prepare(
    'SELECT mem_id, userid, email, status
     FROM mem_signup
     WHERE mem_id = ?
     LIMIT 1'
);
$stmt->bind_param('i', $memId);
$stmt->execute();

Create a Verification Token Top ↑

$token = bin2hex(
    random_bytes(32)
);
$tokenHash = hash(
    'sha256',
    $token
);
$expiresAt = date(
    'Y-m-d H:i:s',
    time() + 3600
);

Store $tokenHash, the member ID, an expiry time and a pending/used state. Do not store the raw token if you do not need to.

Store the Pending Verification Top ↑

$stmt = $connection->prepare(
    'INSERT INTO mem_status
     (mem_id, token_hash, expires_at, status)
     VALUES (?, ?, ?, ?)'
);
$status = 'B';
$stmt->bind_param(
    'isss',
    $memId,
    $tokenHash,
    $expiresAt,
    $status
);
$stmt->execute();
$verificationUrl =
    $domainPath .
    'si_conf.php?token=' .
    rawurlencode($token);

The raw token is sent to the member; the database contains only its hash. The link should expire and work once.

Send the Message Top ↑

Use a configured transactional email provider or a correctly configured mail transport. Do not hardcode mail credentials in public source. The message should explain why it was sent and how long the link remains valid.

Related tutorials: random values, insert ID and SELECT.

Next Step Top ↑

Continue to verify the token and activate the account.

Original Source Examples Retained for Migration Reference Top ↑

Historical code: these source-page examples are retained so no learner-purpose example is silently lost. Use the modern secure patterns above for new work.

Original example 1

$mem_id=$_GET['mem_id'];
if(!is_numeric($mem_id)){
echo "Data Error";
exit;
}

Original example 2

if($stmt = $connection->prepare("SELECT userid,email from mem_signup   WHERE mem_id=? and status='A'")){
	 ----
 }

Original example 3

http://example.com/f/si_conf.php?mem_id=14&email=userid@gmail.com&userid=myuserid&status_id=16&word=a498656b1e61a93ef81ad86006ccc8b2

Additional Original Learning Routes Top ↑






plus2net.com






✖
We use cookies to improve your browsing experience. . Learn more
HTML MySQL PHP JavaScript ASP Photoshop Articles Contact us
© 2000-2026 plus2net.com All rights reserved worldwide Privacy Policy Disclaimer