I'm making a website that users can log in and new members can sign in, but when I go and test the site and go to the new member button to register, it gives me a warning saying that the password has to be between 6 and 12 characters even when I do put a password in that is in between those parameters. The code that I'm using is

ini_set("display_errors", 1);
  // include function files for this application

  //create short variable names
  // start session which may be needed later
  // start it now because it must go before headers
  try   {
    // check forms filled in
    if (!filled_out($_POST)) {
      throw new Exception('You have not filled the form out correctly. Please go back and try again.');

    // email address not valid
    if (!valid_email($email)) {
      throw new Exception('That is not a valid email address.  Please go back and try again.');

    // passwords not the same
    if ($passwd != $passwd2) {
      throw new Exception('The passwords you entered do not match. Please go back and try again.');

    // check password length is ok
    // ok if username truncates, but passwords will get
    // munged if they are too long.
    if (!preg_match('/^(?=.*\d)(?=.*[A-Za-z])[0-9A-Za-z]{6,12}$/', $passwd)) {
        throw new Exception('Your password must be between 6 and 12 characters inclusive. Please go back and try again.');

    // attempt to register
    // this function can also throw an exception
    register($username, $email, $passwd);
    // register session variable
    $_SESSION['valid_user'] = $username;

    // provide link to members page
    do_html_header('Registration successful');
    echo "Welcome " . $_POST["username"];
    echo 'Your registration was successful.  Go to the members page to start setting up your bookmarks!';
    do_html_url('member.php', 'Go to members page');

   // end page
  catch (Exception $e) {
     echo $e->getMessage();

I want the page to be able to display the person's name when they've registered correctly or display an error message saying that they need to enter a password between 6 to 12 characters and being inclusive or if they've not entered an email or name.


Since changing the line 34 from 8,12 to 6,12 I have now got Warning: mysqli::mysqli(): (HY000/2002): No such file or directory in the file shown


function db_connect() {
   $result = new mysqli('localhost', 'bm_user', 'password', 'bookmarks');
   if (!$result) {
     throw new Exception('Could not connect to database server');
   } else {
     return $result;


And Warning: mysqli::query(): Couldn't fetch mysqli in the file


function register($username, $email, $password) {
// register new person with db
// return true or error message

  // connect to db
  $conn = db_connect();

  // check if username is unique
  $result = $conn->query("select * from user where username='".$username."'");
  if (!$result) {
    throw new Exception('Could not execute query');

  if ($result->num_rows>0) {
    throw new Exception('That username is taken - go back and choose another one.');

  // if ok, put in db
  $result = $conn->query("insert into user values
                     ('".$username."', sha1('".$password."'), '".$email."')");
  if (!$result) {
      throw new Exception('Could not register you in database - please try again later.');

  return true;

function login($username, $password) {
// check username and password with db
// if yes, return true
// else throw exception

  // connect to db
  $conn = db_connect();

  // check if username is unique
  $result = $conn->query("select * from user
                     where username='".$username."'
                     and passwd = sha1('".$password."')");
  if (!$result) {
      throw new Exception('Could not log you in.');

  if ($result->num_rows>0) {
      return true;
  } else {
     throw new Exception('Could not log you in.');

function check_valid_user() {
// see if somebody is logged in and notify them if not
  if (isset($_SESSION['valid_user']))  {
      echo "Logged in as ".$_SESSION['valid_user'].".<br />";
  } else {
     // they are not logged in
     echo 'You have not filled the form out correctly.
          Please go back and try again.<br />';
     do_html_url('login.php', 'Login');

function change_password($username, $old_password, $new_password) {
// change password for username/old_password to new_password
// return true or false

  // if the old password is right
  // change their password to new_password and return true
  // else throw an exception
  login($username, $old_password);
  $conn = db_connect();
  $result = $conn->query("update user
                      set passwd = sha1('".$new_password."')
                      where username = '".$username."'");
  if (!$result) {
    throw new Exception('Password could not be changed.');
  } else {
    return true;  // changed successfully

function get_random_word($min_length, $max_length) {
// grab a random word from dictionary between the two lengths
// and return it

  // generate a random word
  $word = '';
  // remember to change this path to suit your system
  $dictionary = '/usr/dict/words';  // the ispell dictionary
  $fp = @fopen($dictionary, 'r');
  if(!$fp) {
    return false;
  $size = filesize($dictionary);

  // go to a random location in dictionary
  $rand_location = rand(0, $size);
  fseek($fp, $rand_location);

  // get the next whole word of the right length in the file
  while ((strlen($word) < $min_length) || (strlen($word)>$max_length) || (strstr($word, "'"))) {
     if (feof($fp)) {
        fseek($fp, 0);        // if at end, go to start
     $word = fgets($fp, 80);  // skip first word as it could be partial
     $word = fgets($fp, 80);  // the potential password
  $word = trim($word); // trim the trailing \n from fgets
  return $word;

function reset_password($username) {
// set password for username to a random value
// return the new password or false on failure
  // get a random dictionary word b/w 6 and 13 chars in length
  $new_password = get_random_word(6, 13);

   if($new_password == false) {
    throw new Exception('Could not generate new password.');

  // add a number  between 0 and 999 to it
  // to make it a slightly better password
  $rand_number = rand(0, 999);
  $new_password .= $rand_number;

  // set user's password to this in database or return false
  $conn = db_connect();
  $result = $conn->query("update user
                      set passwd = sha1('".$new_password."')
                      where username = '".$username."'");
  if (!$result) {
    throw new Exception('Could not change password.');  // not changed
  } else {
    return $new_password;  // changed successfully

function notify_password($username, $password) {
// notify the user that their password has been changed

$conn = db_connect();
$result = $conn->query("select email from user
                        where username='".$username."'");
if (!$result) {
  throw new Exception('Could not find email address.');
} else if ($result->num_rows == 0) {
  throw new Exception('Could not find email address.');
  // username not in db
} else {
  $row = $result->fetch_object();
  $email = $row->email;
  $from = "From: support@phpbookmark \r\n";
  $mesg = "Your PHPBookmark password has been changed to ".$password."\r\n"
          ."Please change it next time you log in.\r\n";

      if (mail($email, 'PHPBookmark login information', $mesg, $from)) {
        return true;
      } else {
        throw new Exception('Could not send email.');

1 Answers1


Your regex is off. You want 6-12 characters, but your regex is accomodating 8-12:


Change to:


But as was pointed out in the comments, there is no reason you should be messing with a user's password, offering (forcing) restrictions like that. And to be perfectly honest, when (and it's been a long time since) I come across a site that restricts what I can use as a password, I simply don't register.

