Re: WAYS OF AUTHENICATION - open discussion
| From: | Siim Einfeldt aka Itpunk | Date: | Sat, 04 Nov 2000 09:45:36 +0000 |
| Subject: | Re: WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23691@lists.php.net to get a copy of this message | ||
>Don't make mysql users. That is wrong.
I don`t, but I do know people who make. What is so bad about? Of course,
when there will be very many users..but why this is so bad solution?
>The first and second ideas are the correct ones whether you do hand
>written sessions or use PHP4. The part that I think you are missing
>is that the "session" is a unique key so to speak that lets the user
>be active.
I understand that. I have used it myself:-) But probably I just didn´t
make myself clear enough.
>Another part is that this table that holds the sessions
>usually gets cleaned out by something running in cron -- basically
>nuking any "expired" sessions.
In my case, this is cleaned usually by a logout button or in case someone
exits in some otehr way, the session will be deleted when someone
activates the login page again.
>This prevents what you have
>stated, that if soneone knew the session, they can get in.
I`m not talkin about people to get to know the sessions, but rather
usernames and passwords. For example: lets say that I have a file called
connect.inc.php3 and I have included to every page that I have. The file
itself contains the following information:
$db = mysql_connect("somehost","someuser","somepass");
Now when somone knows the filename (inthis case connect.inc.php3) and he
knows the variable name (in this case $db), he can include theinc file in
his own page and echo the $db and so getting to know the mysql user
information.
Siim Einfeldt