Re: Sessions / logins / cookies / security

From: Date: Thu, 18 Jul 2002 06:21:02 +0000
Subject: Re: Sessions / logins / cookies / security
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-108215@lists.php.net to get a copy of this message
There's a good article on authentication at phpbuilder.com http://www.phpbuilder.com/columns/tim20000505.php3 that may provide an idea or two. ----- Original Message ----- From: "Chad Day" <cday@atpco.com> Newsgroups: php.general To: <php-general@lists.php.net> Sent: Tuesday, July 16, 2002 10:30 AM Subject: Sessions / logins / cookies / security > I asked something similar a little while ago, but didn't do a good job > clarifying. > > What I'm looking to do is when a user logs in, I start up the session.. I > then have the registered session var to verify they are authenticated as > they move throughout the site. > > Now, when they close the browser and come back, I want them to still be > authenticated. Obviously, I have to set a cookie. But what do I set? Do I > set just their user ID? The MD5 of their password? What's the most secure > way, that's not easily spoofed? I don't know that much about cookies, but > if I just use a user ID, couldn't someone just change that ID value and > 'become' another user? > > Thanks for any advice, > Chad >

« previous php.general (#108215) next »