I need to check db for matching user credential on login script.
There must be atleast one matching row. Else, script should alert user not registered.

Need to check the db using the function mysqli_stmt_num_rows().
Assignment is to list all the various valid ways this function can be used to check for mathcing rows.

I conconcted 21 different ways. But I need your assistance to point-out the invalid attempts out of the 21 different attempts. That is all.

Note the 21 different IFs below. Note the comments on each. I queried the db using correct user credentials.
That means, mysqli_stmt_num_rows() should show '1'.

I have labeled my attempts from 1 to 21. I need you to give me the label numbers of the ones that are invalid.
On my tests, whichever attempt showed one matching row found, I put PASS on the comment beside it.
And, whichever attempt showed matching row NOT found, I put FAIL on the comment.
QUESTION: Which of these following 21 are invalid or incorrect way to check for matching rows ? Give me their label numbers.

Note, I know the difference between "=", "==" and "===".
And, I know the difference between "!=", "!==" and "!===".
I added some invalid checks just for experimental purposes.

Thanks

1

if(!$num_rows = mysqli_stmt_num_rows($stmt)) //FAILS
{
    die('Incorrect User Credentials!');
}

2

if(!$num_rows==mysqli_stmt_num_rows($stmt)) //FAILS
{
    die('Incorrect User Credentials!');
}

3

if($num_rows!=mysqli_stmt_num_rows($stmt)) //FAILS
{
    die('Incorrect User Credentials!');
}

4

if($num_rows!==mysqli_stmt_num_rows($stmt)) //FAILS
{
    die('Incorrect User Credentials!');
}

5

if($num_rows = mysqli_stmt_num_rows($stmt)!=1) //WORKS
{
    die('Incorrect User Credentials!');
}

6

if($num_rows = mysqli_stmt_num_rows($stmt)!==1) //WORKS
{
    die('Incorrect User Credentials!');
}

7

if($num_rows = mysqli_stmt_num_rows($stmt)<1) //WORKS
{
    die('Incorrect User Credentials!');
}

8

if($num_rows = mysqli_stmt_num_rows($stmt)=0)//FAILS
{
    die('Incorrect User Credentials!');
}

9

if($num_rows = mysqli_stmt_num_rows($stmt)==0)//WORKS
{
    die('Incorrect User Credentials!');
}

10

if($num_rows = mysqli_stmt_num_rows($stmt)===0)//WORKS
{
    die('Incorrect User Credentials!');
}

11

if(!mysqli_stmt_num_rows($stmt)) //FAILS
{
    die('Incorrect User Credentials!');
}

12

if(mysqli_stmt_num_rows($stmt)=FALSE) //FAILS
{
    die('Incorrect User Credentials!');
}

13

if(mysqli_stmt_num_rows($stmt)==FALSE) //FAILS
{
    die('Incorrect User Credentials!');
}

14

if(mysqli_stmt_num_rows($stmt)===FALSE) //WORKS
{
    die('Incorrect User Credentials!');
}

15

if(!mysqli_stmt_num_rows($stmt)=TRUE) //FAILS
{
    die('Incorrect User Credentials!');
}

16

if(!mysqli_stmt_num_rows($stmt)==TRUE) //FAILS
{
    die('Incorrect User Credentials!');
}

17

if(mysqli_stmt_num_rows($stmt)!=TRUE) //FAILS
{
    die('Incorrect User Credentials!');
}

18

if(mysqli_stmt_num_rows($stmt)!==TRUE) //FAILS
{
    die('Incorrect User Credentials!');
}

19

if(mysqli_stmt_num_rows($stmt)=NULL) //FAILS
{
    die('Incorrect User Credentials!');
}

20

if(mysqli_stmt_num_rows($stmt)==NULL) //FAILS
{
    die('Incorrect User Credentials!');
}

21

if(mysqli_stmt_num_rows($stmt)===NULL) //WORKS
{
    die('Incorrect User Credentials!');
}

CONTEXT

$domain = trim($_POST['domain']);
$domain_email = trim($_POST['domain_email']);
$password_hashed = hash('sha256',trim($_POST['password']));

//Query DB.
//Check if User already registered or not.
mysqli_report(MYSQLI_REPORT_ERROR|MYSQLI_REPORT_STRICT);
$conn = mysqli_connect("localhost","root","","buzz"); //mysqli_connect("server","user","password","db");
$stmt = mysqli_stmt_init($conn);
//$sql = "SELECT id FROM domains WHERE password = ? AND (domain = ?  OR domain_email = ?)";
$sql = "SELECT id FROM domains WHERE (domain = ? OR domain_email = ?) AND password = ?";

if(!mysqli_stmt_prepare($stmt,$sql))
{
    echo __LINE__; echo '<br>';//DELETE

    echo 'Mysqli Error: ' .mysqli_stmt_error(); //DEV MODE.
    echo '<br>';
    echo 'Mysqli Error No: ' .mysqli_stmt_errno(); //DEV MODE.
    echo '<br>';
    die('Login a Failure!');
}
else
{
    echo __LINE__; echo '<br>';//DELETE

    mysqli_stmt_bind_param($stmt,"sss",$domain,$domain_email,$password_hashed);
    mysqli_stmt_execute($stmt);
    mysqli_stmt_bind_result($stmt,$id);
    if(!mysqli_stmt_fetch($stmt)) //This triggers if credentials are wrong.
    {   
        echo __LINE__; echo '<br>';//DELETE

        mysqli_stmt_close($stmt);
        mysqli_close($conn);
        die('Password fetching failed!');
    }
    else
    {
        echo __LINE__; echo '<br>';//DELETE


        //if(!$num_rows = mysqli_stmt_num_rows($stmt)) //FAILS
        //if(!$num_rows==mysqli_stmt_num_rows($stmt)) //FAILS
        //if($num_rows!=mysqli_stmt_num_rows($stmt)) //FAILS
        //if($num_rows!==mysqli_stmt_num_rows($stmt)) //FAILS
        //if($num_rows = mysqli_stmt_num_rows($stmt)!=1) //WORKS
        //if($num_rows = mysqli_stmt_num_rows($stmt)!==1) //WORKS
        //if($num_rows = mysqli_stmt_num_rows($stmt)<1) //WORKS
        //if($num_rows = mysqli_stmt_num_rows($stmt)=0)//FAILS
        //if($num_rows = mysqli_stmt_num_rows($stmt)==0)//WORKS
        //if($num_rows = mysqli_stmt_num_rows($stmt)===0)//WORKS
        //if(!mysqli_stmt_num_rows($stmt)) //FAILS

        //if(mysqli_stmt_num_rows($stmt)=FALSE) //FAILS
        //if(mysqli_stmt_num_rows($stmt)==FALSE) //FAILS
        //if(mysqli_stmt_num_rows($stmt)===FALSE) //WORKS

        //if(!mysqli_stmt_num_rows($stmt)=TRUE) //FAILS
        //if(!mysqli_stmt_num_rows($stmt)==TRUE) //FAILS
        //if(mysqli_stmt_num_rows($stmt)!=TRUE) //FAILS
        //if(mysqli_stmt_num_rows($stmt)!==TRUE) //FAILS
        //if(mysqli_stmt_num_rows($stmt)=NULL) //FAILS
        //if(mysqli_stmt_num_rows($stmt)==NULL) //FAILS
        //if(mysqli_stmt_num_rows($stmt)===NULL) //WORKS
        {
            die('Incorrect User Credentials!');
        }

    mysqli_stmt_close($stmt);
    mysqli_close($conn);

    echo __LINE__; echo '<br>';//DELETE
    echo 'password: ' .$password; echo '<br>';
    echo 'hashed password: ' .$hashed_password; echo '<br>';

    header('location: home_Template.php');
    exit;
}

Experimented half the night and some test results confused me which I need clearing.

Dani AI

Generated

Short answer for : the only outright syntax errors in your 21 tests are 1, 8, 12, 15 and 19. Those try to assign to an expression (for example to the negation of a variable) or assign into a function call — PHP will not allow that. The other lines are mostly syntactically valid but many are fragile or misleading: some perform an assignment of a boolean (because comparison operators run before =), some depend on loose ==/!= type juggling, and a few rely on whether mysqli_stmt_num_rows() actually has a buffered result available.

Do not rely on accidental behavior from operator precedence or loose comparisons. was right to suggest clearer parentheses, and also note there is no operator !=== or !==== — that form does not exist. The robust pattern is: execute, store the result for the statement, read the numeric row count, then compare the integer explicitly. For example (pseudo-code):

mysqli_stmt_execute($stmt);
mysqli_stmt_store_result($stmt);
$num_rows = mysqli_stmt_num_rows($stmt);
if ($num_rows === 0) {
    die('Incorrect User Credentials!');
}

Notes and references: calling mysqli_stmt_store_result() is needed if you want a reliable row count from a prepared statement; otherwise mysqli_stmt_num_rows() can be unreliable for unbuffered statements. See the PHP manual on mysqli_stmt_store_result and mysqli_stmt_num_rows.

I need you to give me the label numbers of the ones that are invalid.

Aren't the ones that are invalid the ones that fail your tests?

And, I know the difference between "!=", "!==" and "!===".

There is no such thing as !===.

I always like to use extra parentheses just to make things as clear and easy-to-read as possible. I would personally do something such as this:

if(($num_rows = mysqli_stmt_num_rows($stmt)) === 0)

Of course, there's more than one way to skin a cat. (For those who are not native English speakers, it's a saying meaning there's always more than one way of getting something done.) Some of the methods you have here are just plain wrong, and some will still work, although aren't necessarily as clear. For example, $num_rows is a variable that one would presume holds a count of the number of rows. Therefore, expecting it to be either true or false doesn't make logical sense, even if it works when its value is 0 and you're testing == FALSE.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.