RE: [PHP] Using cookies
| From: | Joseph Bannon | Date: | Tue, 21 Oct 2003 21:48:13 +0000 |
| Subject: | RE: [PHP] Using cookies | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-167013@lists.php.net to get a copy of this message | ||
I think it's the responsibility of whomever is holding the key (ie, the
username and password). When a user logs into my site, I put their
username and password in a cookie. I then check those cookies to allow
them access to membership only parts of the site. It is thus their
responsibility to keep people from accessing the cookies on their
machine. If I don't put the username and password on their machine and
just use a session id, now the responsibility is in my hands.
J.