Re: Cookies/Remeber password
| From: | Andy Warwick | Date: | Tue, 20 Jun 2000 21:41:44 +0000 |
| Subject: | Re: Cookies/Remeber password | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-2368@lists.php.net to get a copy of this message | ||
on 20/6/00 11:29 pm, Ayman Mackouly at aymack@netvision.net.il wrote:
> Hi folks,
>
> I'm trying to do a simple username/password login for new members in my
> website (both are saved in mysql table) and I'm considering adding "Remember
> me" option, which means the user doesn't have to enter his username/password
> to login member's section instead username/password are loaded from a cookie.
>
> I have three questions regarding that:
>
> 1.Is it a good idea to save username/password in a cookie?
> 2.Is there any built-in string encryption methond in PHP?
> 3.How do I set a cookie that doesn't expire?
Ayman
I have just put together a site that does something similar, but I use three
values for verification rather than two.
In the mySQL table, each user has a unique ID number as their primary key.
They login in using their username and password, but I save the cookie on
their machine as their ID number and username. From this I can confirm the
third item, the password, if needed. If someone read their cookie, they
could get the two values, but would still need to know their password to
login in on another machine.
The two items are sufficient to recognise them as a returning user, without
revealing any more about them.
i.e.
USER_ID USERNAME PASSWORD
000001 Foo Bar
User "Foo" logs in with password "Bar", but cookie is saved as
"000001:Foo"
If someone else attempts to login as "Foo", they have no way of knowing
"Bar", even if they know 000001.
Downsides are;
1. If a user forgets to log out, the next person will still get in
automatically as the cookie is still set.
2. When a user logs in, his password is passed via the form to the server
for that one instance in plain text.
3. If a user copies the cookie to another machine they can get in.
These were acceptable in my situation, as registration is only used to add
functionality to the site, not protect sensitive data.
If this isn't sufficient, you have to look at encrypting the password as it
is passed to the server over a secure connection, and use some sort of
session tracking to force a logout at the end.
As to setting a cookie that doesn't expire, simply set it to expire in 2060,
or some other really far point in the future. If their machine is still
working at that point I would be very surprised.
If you have any more questions on my solution, feel free to email me direct.
HTH