Re: Sessions / logins / cookies / security
| From: | Peter James | Date: | Thu, 18 Jul 2002 06:21:02 +0000 |
| Subject: | Re: Sessions / logins / cookies / security | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-108215@lists.php.net to get a copy of this message | ||
There's a good article on authentication at phpbuilder.com
http://www.phpbuilder.com/columns/tim20000505.php3
that may provide an idea or two.
----- Original Message -----
From: "Chad Day" <cday@atpco.com>
Newsgroups: php.general
To: <php-general@lists.php.net>
Sent: Tuesday, July 16, 2002 10:30 AM
Subject: Sessions / logins / cookies / security
> I asked something similar a little while ago, but didn't do a good job
> clarifying.
>
> What I'm looking to do is when a user logs in, I start up the session.. I
> then have the registered session var to verify they are authenticated as
> they move throughout the site.
>
> Now, when they close the browser and come back, I want them to still be
> authenticated. Obviously, I have to set a cookie. But what do I set? Do
I
> set just their user ID? The MD5 of their password? What's the most
secure
> way, that's not easily spoofed? I don't know that much about cookies, but
> if I just use a user ID, couldn't someone just change that ID value and
> 'become' another user?
>
> Thanks for any advice,
> Chad
>