RE: [PHP] Authentication: is it a good solution?
| From: | Lars Holm Nielsen | Date: | Wed, 27 Sep 2000 09:56:11 +0000 |
| Subject: | RE: [PHP] Authentication: is it a good solution? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-17662@lists.php.net to get a copy of this message | ||
> Ps. I know the authentication example present in the same php manual and
the
> phplib that implement sessions, but I don't really like it 'cause probably
> I've not understand how to use it ... :-)
What you've made, is somehow you're own session management, which PHP4 and a
lot of other libraries already have implemented. You're own function could
probably do the job, but it would spare you some time to use the tools
already there.
Do you remove the unique ids from the db after a give time (Probably 15-20
minutes, after last access to site)? If not, this could result in a major
security hole.
Regards,
Lars Holm Nielsen <lars@hankat.dk>