Re: Authentication
| From: | Justin French | Date: | Thu, 04 Jul 2002 23:11:35 +0000 |
| Subject: | Re: Authentication | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-105504@lists.php.net to get a copy of this message | ||
on 05/07/02 6:46 AM, Peter (newsaddress@saracenvsu.org.uk) wrote:
> Thanks for all the pointers. How about using JavaScript to grab things like
> the OS + browser as *added* security?
Except JavaScript isn't always guaranteed.
> In the same way, the screen resolution, colour depth and other browser
> variables could be compared.
Yuk!! I can change any of these settings during my visit, and once again,
none of these are guaranteed, due to the nature of client-side scripting,
and the variance in browsers.
> I do not see any reason for the user to log in and use my site, then later
> in the day come back to the homepage and expect to be automatically logged
> in which may simplify things a bit.
I can. In an office situation, or in a shared computer situation, or
visiting a friends computer, or ANY occurrence where others may use the
computer after you, this is a bad idea. I hate to think what damage someone
could do to one of my sites if I left myself logged in as "admin user" one
day -- worse still, if I didn't think the session would be maintained once
the browser window was closed / after a short period.
If you *want* to go this far, then make sure it's all done with check boxes
and options.
A simple "remember me" checkbox and a "public computer" checkbox (as used on
hotmail) will suffice.
Give the user options, rather than forcing your "really good idea" onto
them.
Justin French