Re: Authentication

From: Date: Thu, 04 Jul 2002 20:18:27 +0000
Subject: Re: Authentication
Groups: php.general 
Request: Send a blank email to php-general+get-105505@lists.php.net to get a copy of this message
>Another thing some people use to strengthen their security model is to >involve some sort of sequence number in the data that the client sends >back. For example, instead of just a session ID, perhaps you have a >cookie, URL variable, or whatever that is an encrypted (two-way so you >can decrypt it) session ID, sequence number, and anything else you might >think of to include. When you decrypt this at the beginning of each >script, you make sure the sequence number is not less than the last >sequence number sent (which you store on the server), Unfortunately, that will break the "Back" button :-( Once you're using IP addresses and randomly logging out valid users, and then annoying them by breaking their "Back" button, you end up losing a not insignificant number of viewers... That may be acceptable, but be sure your boss/client is aware of, *really* aware of the issue. Otherwise, you'll spend hours setting this up, then hours more ripping it out, once the boss starts hearing from their mother-in-law that they can't use the site. YMMV. -- Like Music? http://l-i-e.com/artists.htm

« previous php.general (#105505) next »