Re: Cookies/Remeber password

From: Date: Tue, 20 Jun 2000 21:41:44 +0000
Subject: Re: Cookies/Remeber password
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-2368@lists.php.net to get a copy of this message
on 20/6/00 11:29 pm, Ayman Mackouly at aymack@netvision.net.il wrote: > Hi folks, > > I'm trying to do a simple username/password login for new members in my > website (both are saved in mysql table) and I'm considering adding "Remember > me" option, which means the user doesn't have to enter his username/password > to login member's section instead username/password are loaded from a cookie. > > I have three questions regarding that: > > 1.Is it a good idea to save username/password in a cookie? > 2.Is there any built-in string encryption methond in PHP? > 3.How do I set a cookie that doesn't expire? Ayman I have just put together a site that does something similar, but I use three values for verification rather than two. In the mySQL table, each user has a unique ID number as their primary key. They login in using their username and password, but I save the cookie on their machine as their ID number and username. From this I can confirm the third item, the password, if needed. If someone read their cookie, they could get the two values, but would still need to know their password to login in on another machine. The two items are sufficient to recognise them as a returning user, without revealing any more about them. i.e. USER_ID USERNAME PASSWORD 000001 Foo Bar User "Foo" logs in with password "Bar", but cookie is saved as "000001:Foo" If someone else attempts to login as "Foo", they have no way of knowing "Bar", even if they know 000001. Downsides are; 1. If a user forgets to log out, the next person will still get in automatically as the cookie is still set. 2. When a user logs in, his password is passed via the form to the server for that one instance in plain text. 3. If a user copies the cookie to another machine they can get in. These were acceptable in my situation, as registration is only used to add functionality to the site, not protect sensitive data. If this isn't sufficient, you have to look at encrypting the password as it is passed to the server over a secure connection, and use some sort of session tracking to force a logout at the end. As to setting a cookie that doesn't expire, simply set it to expire in 2060, or some other really far point in the future. If their machine is still working at that point I would be very surprised. If you have any more questions on my solution, feel free to email me direct. HTH

« previous php.general (#2368) next »