session security for authentication
| From: | j d robinson | Date: | Fri, 20 Oct 2000 15:00:47 +0000 |
| Subject: | session security for authentication | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-21404@lists.php.net to get a copy of this message | ||
Is there anything wrong with authenticating people using thier session id
and a session variable?
For example a function authenticate() would:
1.check a username and password against a database value, if they match, the
user gets a session
2. session_register is used to set a session variable '$admin' to '1'
on subsequent page requests,
1. '$admin' is set to '0'
2. Then session_start is called overwriting $admin= '0' with $admin='1'
(assuming they are authentic)
3. The existance of '$admin' = '1' is checked, if true they are
authenticated.
Assuming no one gets hold of another persons session id this is secure
right?
Is'nt this (effectively setting a tempory password) more secure than using a
cookie, which would send the users password and name to the server every
page request, making it more likely to be captured?
Regards
Dale Robinson