64x64 icon dark hosting
Get a Tuts+ subscription for just $45! Deploy New Relic now to claim.
Advertisement

How to Implement Email Verification for New Members

by

Have you ever created an account with a website, and were required to check your email and click through a verification link sent by the company in order to activate it? Doing so highly reduces the number of spam accounts. In this lesson, we'll learn how to do this very thing!


What Are We Going to Build?

We are going to build a nice PHP sign-up script where a user can create an account to gain access to a "members section" of a website.
After the user creates his account, the account will then be locked until the user clicks a verification link that he will receive in his email inbox.


Step 1 - Sign-up Page

We first need a simple page where our visitors can sign up their accounts; so that's the first thing we will build.
I would like to remind you that this is a PHP tutorial, and in my opinion, I think you need to know the basics of HTML before moving on with PHP. I'll add comments to the HTML & CSS to describe each line of code.

index.php - This is our sign up page with a basic form.

css/style.css - This is stylesheet for index.php and further pages.

As you can see, I have added a comment to each line that describes what they do. Also, you might have noticed the following comment in the index.php file:

We are going to write our PHP between these 2 lines!


Step 2 - Input Validation

The first thing we are going to build is a piece of code that's going to validate the information. Here is a short list detailing what needs to be done.

  • If the name field is not empty.
  • If the name is not to short.
  • If the email field is not empty.
  • If the email address is valid xxx@xxx.xxx

So our first step is checking if the form is being submitted, and that the fields are not empty.

Time for a breakdown! We start of with an IF statement and we are first validating the name field:

So if you would submit the form now with empty fields, nothing happens. If you fill in both fields then our script will run the code between the brackets.
Now we are going to create a piece of code that will check if an email address is valid. If it's not, we will return a error. Also let's turn our post variables into local variables:

We can now reach our data via our local variables. As you can see, I also added a MySQL escape string to prevent MySQL injection when inserting the data into the MySQL database.

"The mysql_real_escape_string() function escapes special characters in a string for use in an SQL statement."

Regular Expressions

Next up is a small snippet that checks if the email address is valid.

Please note that I did not personally write this regular expression, it's a small snippet from php.net.
Basically, it verifies if the email is written in the following format:

Now in the eregi, you can see that it checks if the email contains characters from the alphabet, if it has any numbers, or a phantom dash (_), and of course the basic requirements for an email (email)'@' and a (dot)'.' If none of these characters are found, the expression returns "false". Okay, so now we need to add some basic error messages.

As you can see we have made a local variable "$msg", this allows us to show the error or the success message anywhere on the page.
And we are going to display it between the instruction text and the form.

Add this to style.css, to style our status message a bit.


Step 3 - Creating the Database & Establishing a Connection

Now we need to establish a database connection and create a table to insert the account data. So let's go to PHPMyAdmin and create a new database with the name registrations and create a user account that has access to that database in order to insert and update data.

Let's create our users table, with 5 fields:

So now we must enter details for these fields:

For those who don't want to input this data manually, you can instead run the following SQL code.

Our database is created, now we need to establish a connection using PHP. We'll write the following code at the start of our script just below the following line:

We'll use the following code to connect to the database server and select the registrations database. (basic MySQL connection)

Now that we've established a connection to our database, we can move on to the next step and insert the account details.


Step 4 - Insert Account

Now it's time to enter the submitted account details to our database and generate an activation hash. Write the following code below this line:

Activation Hash

In our database we made a field called hash, this hash is a 32 character string of text. We also send this code to the user's email address. They then can click the link (which contains the hash) and we will verify if it matches up with the one in the database. Let's create a local variable called $hash and generate a random md5 hash.

What did we do? Well we are using the PHP function "rand" to generate a random number between 0 and 1000. Next our MD5 function will turn this number into a 32 character string of text which we will use in our activation email. My choice is to use MD5, because it generates a hash of 32 characters which is secure and, in this case, impossible to crack.

Creating a Random Password

The next thing we need to is to create a random password for our member:

Insert the following information into our database using a MySQL query

As you can see, we insert all data with a MySQL escape string around it to prevent any MySQL injection.
You also might notice that the MD5 function changes the random password into a secure hash for protection. Example: if an "evil" person gains access to the database, he can't read the passwords.

For testing, fill in the form and check if the data is being inserted into our database.


Step 5 - Send the Verification Email

Right after we have inserted the information into our database, we need to send an email to the user with the verification link. So let's use the PHP "mail" function to do just that.

Now let's brake down the message:

In the code above we send a short description to our user which contains the username and password -- using the local variables we created when the data was posted.

In this section of the code, we created a dynamic link. The result of this will look like this:

As you can see, it creates a solid url, which is impossible to guess. This is a very secure way to verify the email address of a user.


Step 6 - Account Activation

As you can see, our url links to verify.php so let's create that, using the same basic template we used for index.php.
However, remove the form from the template.

The first thing we need to do is check if we have our $_GET variables (email & hash)

To make things a bit easier, let's assign our local variables and add some MySQL injection prevention by, once again, using the MySQL escape string.

Next is to check the data from the url against the data in our database using a MySQL query.

In the code above, we used a MySQL select statement, and checked if the email and hash matched. But beside that, we checked if the status of the account is "inactive". Finally, we use mysql_num_rows to determine how many matches have been found. So let's try this out. Simply use a simple echo to return the results.

We have a MATCH! To change the result, simply change the email and you'll see that the number returned is 0.
We can use our $match variable to either activate the account or return a error when no match has been found.

In order to activate the account, we must update the active field to 1 using a MySQL query.

So we use the same search terms for the update as we used in our MySQL select query. We change active to 1 where the email, hash and field active = 0 match up. We also return a message telling the user that his account has been activated. You can add a message like we did here to the "no match" part. So the final code should look similar to:

If you visit verify.php without any strings, the follow error will be shown:


Step 7 - Login

In this final step, I will show you how to create a basic login form and check if the account is activated. First create a new file called login.php with the basic template we used before, but this time I changed the form into a login form.

The form is basic html, and almost the same as the signup form, no further explanation is needed. Now it's time to write the code for the login script, which we will write just below the MySQL connection code. We start with something we also did in the signup form.

So we first check to see if the data is being posted, and we make sure that it's not empty.
Next is to create some local variables for the post data:

We created the local variables and changed the password into a md5 hash to match it with the password hash we have stored in the database.
Now, it's time to create the connection to our "users" table and verify if the entered data is correct.

We wrote a MySQL query that will select the username, password and active information from our database, if the username and password match up.
AND active='1' is !IMPORTANT!, this makes sure that you can only login if your account is activated. We use the MySQL num rows again to see how many matches are found.

In the code above we check if the login was a success or not.


The End

And that's the end of this tutorial! I hope you enjoyed it, and if you did please leave a comment below!

Advertisement