Re: secure cookies
| From: | David VanHorn | Date: | Mon, 14 Aug 2000 18:08:39 +0000 |
| Subject: | Re: secure cookies | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-11655@lists.php.net to get a copy of this message | ||
At 12:50 PM 8/14/00 -0500, Lewis Bergman wrote:
Is there any opinion on how to pass usernames and ID's securely in a cookie? Prefer to NOT use mcrypt if possible. Any pointers or articles would be most appreciated.Do you have to? Here's what I do, maybe adaptable for you. On the login page, I issue a 10 digit random as the cookie, and take username and password, if valid, then I store the cookie in their record. On the next page visit I give a new cookie (replacing the old) and look up the user using the old cookie. If valid, then I store the new cookie for next time. AFAIK, it's pretty hard to spoof, without extreme means. Part of the validation is checking their current IP address against a range of addresses valid for that account (the user sets this) but you may not need/want to go that far. You might check that their IP is the same as last time, and if not ask them to re-validate. I'm also interested to know what else can be done for user authentication. -- Where's dave? http://www.findu.com/cgi-bin/find.cgi?kc6ete-9