Authentication: is it a good solution?

From: Date: Tue, 26 Sep 2000 06:32:45 +0000
Subject: Authentication: is it a good solution?
Groups: php.general 
Request: Send a blank email to php-general+get-17455@lists.php.net to get a copy of this message
Hi, I've some doubts in order to use a my application that works protecting a reserved area (I'm working with php3+apache)... I've created a client form to submit values (username & password): after a validation process, I send to the browser a cookie contains a value (an alphanumeric & random string of 32 chars length creating by md5(rand(uniqid())); ) and I store this value in mysql table. At the end, all time that this client try to get a function present in the file protected, I check: if the cookie var exist, if the cookie value is on the mysql table and finally I return a var: Yes or Not. If is set Yes, the client can do the request web function; if Not, I print out the validation form again ... Here a small code for example: if(!(isset($auth_value)) { include("login.form.txt"); } else { //the code to check //the $auth_value //against the db table //returs a value Yes or Not if($are_you="Y") { //switch the action //blah, blah //main functions are all here } else { include("login.form.txt"); } } Well, my main question is: is this process safe enough? It seems work fine, but I need a confirm from some guys more expert then me ... Many thanks in advance max Ps. I know the authentication example present in the same php manual and the phplib that implement sessions, but I don't really like it 'cause probably I've not understand how to use it ... :-)

« previous php.general (#17455) next »