Re: [PHP3] best way to hide username/password?
| From: | Drew Kime | Date: | Wed, 07 Jun 2000 19:52:44 +0000 |
| Subject: | Re: [PHP3] best way to hide username/password? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-1247@lists.php.net to get a copy of this message | ||
> I have a series of pages that log in to an Oracle server, then log out.
> The username/password is passed from page to page, currently as hidden
> form values.
If you're using passwords, you must have a database on the back end. Cookies
would be an easy way to pass the values, but I'm assuming you want this to work
without them since they are also vulnerable to physical access.
When a user logs in, create a randomly generated session ID -- base it in part on
the current timestamp so you can set it to expire after a certain time. Set the
session ID as the hidden variable. This variable would still be available in
source, but you can set it to time out at whatever rate you want. Banks
typically use 30-minute sessions. If your application needs tighter security
than that, set the session variable to expire sooner, requiring a password
confirmation.