Re: [PHP3] best way to hide username/password?

From: Date: Wed, 07 Jun 2000 19:52:44 +0000
Subject: Re: [PHP3] best way to hide username/password?
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-1247@lists.php.net to get a copy of this message
> I have a series of pages that log in to an Oracle server, then log out. > The username/password is passed from page to page, currently as hidden > form values. If you're using passwords, you must have a database on the back end. Cookies would be an easy way to pass the values, but I'm assuming you want this to work without them since they are also vulnerable to physical access. When a user logs in, create a randomly generated session ID -- base it in part on the current timestamp so you can set it to expire after a certain time. Set the session ID as the hidden variable. This variable would still be available in source, but you can set it to time out at whatever rate you want. Banks typically use 30-minute sessions. If your application needs tighter security than that, set the session variable to expire sooner, requiring a password confirmation.

« previous php.general (#1247) next »