[PHP] 纯文本查看 复制代码
<?php
require_once 'config.php';
// 如果已登录,跳转到首页
if (isset($_SESSION['user_id'])) {
header('Location: index.php');
exit;
}
$error = '';
if ($_SERVER['REQUEST_METHOD'] === 'POST') {
$username = sanitize($_POST['username'] ?? '');
$password = $_POST['password'] ?? '';
if (empty($username) || empty($password)) {
$error = '请输入用户名和密码';
} else {
try {
$db = getDB();
$stmt = $db->prepare('SELECT * FROM users WHERE username = ?');
$stmt->execute([$username]);
$user = $stmt->fetch();
if ($user && verifyPassword($password, $user['password'])) {
// 先记录日志(在设置session之前)
try {
$stmt = $db->prepare('INSERT INTO operation_logs (user_id, username, operation, details, created_at) VALUES (?, ?, ?, ?, datetime("now"))');
$stmt->execute([$user['id'], $user['username'], 'login', '用户登录系统']);
} catch (Exception $e) {
// 日志记录失败不影响登录
error_log('登录日志记录失败: ' . $e->getMessage());
}
// 设置会话
session_regenerate_id(true); // 防止会话固定攻击
$_SESSION['user_id'] = $user['id'];
$_SESSION['username'] = $user['username'];
$_SESSION['role'] = $user['role'];
// 重定向到首页
header('Location: index.php');
exit;
} else {
$error = '用户名或密码错误';
// 记录登录失败
try {
$stmt = $db->prepare('INSERT INTO operation_logs (user_id, username, operation, details, created_at) VALUES (?, ?, ?, ?, datetime("now"))');
$stmt->execute([0, $username, 'login_failed', '登录失败']);
} catch (Exception $e) {
error_log('登录失败日志记录失败: ' . $e->getMessage());
}
}
} catch (PDOException $e) {
$error = '系统错误,请稍后重试';
error_log('登录错误: ' . $e->getMessage());
}
}
}
?>
<!DOCTYPE html>
<html lang="zh-CN">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>仓库管理系统 - 登录</title>
<style>
* {
margin: 0;
padding: 0;
box-sizing: border-box;
}
body {
font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, "Helvetica Neue", Arial, sans-serif;
background: linear-gradient(135deg, #667eea 0%, #764ba2 100%);
min-height: 100vh;
display: flex;
align-items: center;
justify-content: center;
}
.login-container {
background: white;
padding: 40px;
border-radius: 10px;
box-shadow: 0 10px 40px rgba(0, 0, 0, 0.2);
width: 100%;
max-width: 400px;
}
.login-header {
text-align: center;
margin-bottom: 30px;
}
.login-header h1 {
color: #333;
font-size: 28px;
margin-bottom: 10px;
}
.login-header p {
color: #666;
font-size: 14px;
}
.form-group {
margin-bottom: 20px;
}
.form-group label {
display: block;
margin-bottom: 8px;
color: #333;
font-weight: 500;
}
.form-group input {
width: 100%;
padding: 12px 15px;
border: 2px solid #e0e0e0;
border-radius: 5px;
font-size: 14px;
transition: border-color 0.3s;
}
.form-group input:focus {
outline: none;
border-color: #667eea;
}
.error-message {
background: #fee;
color: #c33;
padding: 10px 15px;
border-radius: 5px;
margin-bottom: 20px;
font-size: 14px;
}
.btn-login {
width: 100%;
padding: 12px;
background: linear-gradient(135deg, #667eea 0%, #764ba2 100%);
color: white;
border: none;
border-radius: 5px;
font-size: 16px;
font-weight: 500;
cursor: pointer;
transition: transform 0.2s, box-shadow 0.2s;
}
.btn-login:hover {
transform: translateY(-2px);
box-shadow: 0 5px 15px rgba(102, 126, 234, 0.4);
}
.btn-login:active {
transform: translateY(0);
}
.login-footer {
text-align: center;
margin-top: 20px;
color: #999;
font-size: 12px;
}
</style>
</head>
<body>
<div class="login-container">
<div class="login-header">
<h1>📦 仓库管理系统</h1>
<p>Warehouse Management System</p>
</div>
<?php if ($error): ?>
<div class="error-message"><?php echo htmlspecialchars($error); ?></div>
<?php endif; ?>
<form method="POST" action="">
<div class="form-group">
<label for="username">用户名</label>
<input type="text" id="username" name="username" required autofocus autocomplete="username">
</div>
<div class="form-group">
<label for="password">密码</label>
<input type="password" id="password" name="password" required autocomplete="current-password">
</div>
<button type="submit" class="btn-login">登 录</button>
</form>
<div class="login-footer">
<p>默认账号: admin / admin123</p>
</div>
</div>
</body>
</html>