Re: Authentication
| From: | Richard Lynch | Date: | Thu, 04 Jul 2002 20:18:27 +0000 |
| Subject: | Re: Authentication | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-105505@lists.php.net to get a copy of this message | ||
>Another thing some people use to strengthen their security model is to
>involve some sort of sequence number in the data that the client sends
>back. For example, instead of just a session ID, perhaps you have a
>cookie, URL variable, or whatever that is an encrypted (two-way so you
>can decrypt it) session ID, sequence number, and anything else you might
>think of to include. When you decrypt this at the beginning of each
>script, you make sure the sequence number is not less than the last
>sequence number sent (which you store on the server),
Unfortunately, that will break the "Back" button :-(
Once you're using IP addresses and randomly logging out valid users, and
then annoying them by breaking their "Back" button, you end up losing a not
insignificant number of viewers...
That may be acceptable, but be sure your boss/client is aware of, *really*
aware of the issue. Otherwise, you'll spend hours setting this up, then
hours more ripping it out, once the boss starts hearing from their
mother-in-law that they can't use the site.
YMMV.
--
Like Music? http://l-i-e.com/artists.htm