authentication scheme[B

From: Date: Tue, 12 Sep 2000 15:09:39 +0000
Subject: authentication scheme[B
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-16365@lists.php.net to get a copy of this message
Hello, I would like some feedback on the security aspects of the following authentication scheme. A session_id is set as soon as a user enters the site. when the user logs in, it sets a variable in a global file that is appended to the top of every page. The variable name would be the person's login and its value would be the person's email address. login=dan password=rewwer email=dan@where.com checks against database; ok, account is good; append to global file, $dan = '$email'; From then on, I can use $dan to pull information about this account. when the session expires, the variable is removed from the global file. Does that make sense; Does anyone see any holes, or problems in implementation? Is there a better, simpler way? I've looked at other schemes, but found most were too complicated, or very difficult to implement. thanks, Dan

« previous php.general (#16365) next »