session security for authentication

From: Date: Fri, 20 Oct 2000 15:00:47 +0000
Subject: session security for authentication
Groups: php.general 
Request: Send a blank email to php-general+get-21404@lists.php.net to get a copy of this message
Is there anything wrong with authenticating people using thier session id and a session variable? For example a function authenticate() would: 1.check a username and password against a database value, if they match, the user gets a session 2. session_register is used to set a session variable '$admin' to '1' on subsequent page requests, 1. '$admin' is set to '0' 2. Then session_start is called overwriting $admin= '0' with $admin='1' (assuming they are authentic) 3. The existance of '$admin' = '1' is checked, if true they are authenticated. Assuming no one gets hold of another persons session id this is secure right? Is'nt this (effectively setting a tempory password) more secure than using a cookie, which would send the users password and name to the server every page request, making it more likely to be captured? Regards Dale Robinson

« previous php.general (#21404) next »