After signup, create an opaque, one-time verification token, store only a hash of that token with an expiry time, and email the raw token to the member in an HTTPS verification URL.
$memId = filter_input(
INPUT_GET,
'mem_id',
FILTER_VALIDATE_INT
);
if (!$memId || $memId < 1) {
http_response_code(400);
exit('Invalid request.');
}
$stmt = $connection->prepare(
'SELECT mem_id, userid, email, status
FROM mem_signup
WHERE mem_id = ?
LIMIT 1'
);
$stmt->bind_param('i', $memId);
$stmt->execute();
$token = bin2hex(
random_bytes(32)
);
$tokenHash = hash(
'sha256',
$token
);
$expiresAt = date(
'Y-m-d H:i:s',
time() + 3600
);
Store $tokenHash, the member ID, an expiry time and a pending/used state. Do not store the raw token if you do not need to.
$stmt = $connection->prepare(
'INSERT INTO mem_status
(mem_id, token_hash, expires_at, status)
VALUES (?, ?, ?, ?)'
);
$status = 'B';
$stmt->bind_param(
'isss',
$memId,
$tokenHash,
$expiresAt,
$status
);
$stmt->execute();
$verificationUrl =
$domainPath .
'si_conf.php?token=' .
rawurlencode($token);
The raw token is sent to the member; the database contains only its hash. The link should expire and work once.
Use a configured transactional email provider or a correctly configured mail transport. Do not hardcode mail credentials in public source. The message should explain why it was sent and how long the link remains valid.
Related tutorials: random values, insert ID and SELECT.
Continue to verify the token and activate the account.
$mem_id=$_GET['mem_id'];
if(!is_numeric($mem_id)){
echo "Data Error";
exit;
}if($stmt = $connection->prepare("SELECT userid,email from mem_signup WHERE mem_id=? and status='A'")){
----
}http://example.com/f/si_conf.php?mem_id=14&email=userid@gmail.com&userid=myuserid&status_id=16&word=a498656b1e61a93ef81ad86006ccc8b2
Author & Instructor at plus2net
I write and maintain practical tutorials on Python, PHP, SQL, JavaScript, HTML, jQuery, and web development at plus2net. The tutorials focus on clear explanations, working examples, and code that readers can test and adapt while learning.