PHP Change Password script using mysqlChange password feature is a common requirement for any membership management script. Here members can change their password after logging in to the member area. Here we will check the session of the member to allow or disallow the access the change password page of the site. Here we can ask the member to enter the old password once and then enter new password twice.
This is a basic script and we can create a change password script by using Ajax ( with PHP MySQL) and update the new passwords. Our new membership management script uses this and there is a demo available to check the functionality.
The new password will be effective from the next login of the member.
We will ask the member to enter the new password twice. Both the entered password should match and must pass the validation. If all the checks passed well then we will update the record of the member with new password.
Let us start with the form. You can download the code at the end of this tutorial but here is the form for change password. Now this form will submit to another page where all the values will be validated and then table will be updated with new password. First we will see the member has opened this page after logging in, if not then we will stop the execuation of the page by using exit command. Here is the part of the code to do that.
Checking user Session statusThis checking of session is common in many pages where a login member can only access for example the pages where the profile to be updated or present page where password to be changed. So we have kept this common code in a separate file check.php and include that file in all required pages.
Inside the file check.php we have only few lines of code to check the session. Here it is for your reference.
Now let us collect all the form posted data of the user
Now we will set the flags for validation of the variables. Please note that we have used limited validation here and you can go for more checking as per your requirements. ( like allowing only numbers or chars in the password etc )
Now check the old password
After this we will see that our entered password is not less than 3 char and more that 8 char length.
Now let us check wheter both the passwords are equal or not
Now if our validation is ok then we will go for updation sql and if validation is not ok then we will display the error message. In our query we are using sql update statement and based on the success of the sql update statement we can display the message. Here is the code for the updation of the member table.
If the database updating is successful then the user has to use new password for next time login. Or the user can be redirected to logout page and can be asked to login again.
To keep the script simple we have used md5 encryption for password and storing in database. For better security it is advisable to use mcrypt() platform to store password.
By using jQuery we need not reload the page to pass the data to backend script.
PHP Session: Creating , using destroying Session variables PHP Session ID: generating session id and re-generating Online membership management script Posting Activation key for lost encrypted password to the email address Creating a signup page and storing member details in MySQL Storing signup data in a table Changing or updating password by the logged in member Forgot password feature in member signup script Basic login form Login script to authenticate user from a mysql table data Checking the status of user for login or logged out Updating member profile inside member area Adding Profile Photo by Members after login Finding out who are online