Authentication: is it a good solution?
| From: | n e t b r a i n | Date: | Tue, 26 Sep 2000 06:32:45 +0000 |
| Subject: | Authentication: is it a good solution? | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-17455@lists.php.net to get a copy of this message | ||
Hi,
I've some doubts in order to use a my application that works protecting a
reserved area (I'm working with php3+apache)...
I've created a client form to submit values (username & password): after a
validation process, I send to the browser a cookie contains a value (an
alphanumeric & random string of 32 chars length creating by
md5(rand(uniqid())); ) and I store this value in mysql table. At the end,
all time that this client try to get a function present in the file
protected, I check: if the cookie var exist, if the cookie value is on the
mysql table and finally I return a var: Yes or Not.
If is set Yes, the client can do the request web function; if Not, I print
out the validation form again ...
Here a small code for example:
if(!(isset($auth_value)) {
include("login.form.txt");
} else {
//the code to check
//the $auth_value
//against the db table
//returs a value Yes or Not
if($are_you="Y") {
//switch the action
//blah, blah
//main functions are all here
} else {
include("login.form.txt");
}
}
Well, my main question is: is this process safe enough? It seems work fine,
but I need a confirm from some guys more expert then me ...
Many thanks in advance
max
Ps. I know the authentication example present in the same php manual and the
phplib that implement sessions, but I don't really like it 'cause probably
I've not understand how to use it ... :-)