Re: WAYS OF AUTHENICATION - open discussion

From: Date: Sun, 05 Nov 2000 09:12:06 +0000
Subject: Re: WAYS OF AUTHENICATION - open discussion
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-23775@lists.php.net to get a copy of this message
I just started to think about cookies too. However, I thought I´ll make it more secure by using both - database and cookies. At the beginning user password is in the database (encypted of course). When user logs in, the sessionid will be created and written to database and the same with ip and useragent. The addition that I made to that, is using cookies. Now I write all the session-stuff to cookies as well. And i have it in an include file like you. And it`s included on every single page(of course) and the sessioncheck is based on both-cookies and database. And if one doesn`t match, user will be throught out (...well, still nicely). And I think that`s quite a small and secure script as well, unless someone tells me otherwise. However, I think I should take a look at LDAP for future references... Siim Einfeldt >From: "MR" <(eme) (erre) (punto)@wanadoo.es> >I and my project group were discussing what authentification method we would use for the web we were working >in. >The client (that guy that needs that web done NOW), proposed LDAP as authentication method. You know, LDAP >is the thing that ISP's >use for every authentication of any of their servers... ISP authentification, pop or smtp authentication, >FTP autentication, web >authenticacion (of course), even wap authentication, or whatever authentication... >You may know, LDAP works as this... the POP server (for example) gets an incomming connection, gets login >and password. And the POP >server thinks "hey, i'm gonna pass this login & password to the LDAP server, he knows if this user can >access me" >Finnaly, LDAP was tought to be much more than we needed, and it would have taken a lot of time to prepare >and program. >The client wanted HIS web to be done as quick as possible, so we decided to use the simple way... >COOKIES. >The user is authenticated at the very beginning of each PHP page. If the posted (or cookie!)login & password >doesn't match the login >& password in the database we use, the system returns an authentication error... otherwise, the user is >accepted. >Simple, and very quick to implement with the wonderful INCLUDE() function. >Ah, the code does use a user & password when loading the login & password from the oracle database... (they >are not encrypted any >way!!) the only thing is that the final user just cannot see any of the php code, you know, he wouldn't ever >know the password for >the database. >My god, using that simple cookies is SO quick...

« previous php.general (#23775) next »