authentication scheme[B
| From: | dbarber | Date: | Tue, 12 Sep 2000 15:09:39 +0000 |
| Subject: | authentication scheme[B | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-16365@lists.php.net to get a copy of this message | ||
Hello,
I would like some feedback on the security aspects of the following
authentication scheme.
A session_id is set as soon as a user enters the site.
when the user logs in, it sets a variable in a global file that is
appended to the top of every page. The variable name would be the
person's login and its value would be the person's email address.
login=dan
password=rewwer
email=dan@where.com
checks against database; ok, account is good; append to global file, $dan
= '$email';
From then on, I can use $dan to pull information about this account.
when the session expires, the variable is removed from the global file.
Does that make sense; Does anyone see any holes, or problems in
implementation? Is there a better, simpler way?
I've looked at other schemes, but found most were too complicated, or
very difficult to implement.
thanks,
Dan