Re: WAYS OF AUTHENICATION - open discussion
| From: | Siim Einfeldt aka Itpunk | Date: | Sun, 05 Nov 2000 09:12:06 +0000 |
| Subject: | Re: WAYS OF AUTHENICATION - open discussion | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23775@lists.php.net to get a copy of this message | ||
I just started to think about cookies too. However, I thought I´ll make it
more secure by using both - database and cookies. At the beginning user
password is in the database (encypted of course). When user logs in, the
sessionid will be created and written to database and the same with ip and
useragent. The addition that I made to that, is using cookies. Now I write
all the session-stuff to cookies as well. And i have it in an include file
like you. And it`s included on every single page(of course) and the
sessioncheck is based on both-cookies and database. And if one doesn`t
match, user will be throught out (...well, still nicely).
And I think that`s quite a small and secure script as well, unless someone
tells me otherwise. However, I think I should take a look at LDAP for
future references...
Siim Einfeldt
>From: "MR" <(eme) (erre) (punto)@wanadoo.es>
>I and my project group were discussing what authentification method we
would use for the web we were working >in.
>The client (that guy that needs that web done NOW), proposed LDAP as
authentication method. You know, LDAP >is the thing that ISP's
>use for every authentication of any of their servers... ISP
authentification, pop or smtp authentication, >FTP autentication, web
>authenticacion (of course), even wap authentication, or whatever
authentication...
>You may know, LDAP works as this... the POP server (for example) gets an
incomming connection, gets login >and password. And the POP
>server thinks "hey, i'm gonna pass this login & password to the LDAP
server, he knows if this user can >access me"
>Finnaly, LDAP was tought to be much more than we needed, and it would
have taken a lot of time to prepare >and program.
>The client wanted HIS web to be done as quick as possible, so we decided
to use the simple way...
>COOKIES.
>The user is authenticated at the very beginning of each PHP page. If the
posted (or cookie!)login & password >doesn't match the login
>& password in the database we use, the system returns an authentication
error... otherwise, the user is >accepted.
>Simple, and very quick to implement with the wonderful
INCLUDE() function.
>Ah, the code does use a user & password when loading the login & password
from the oracle database... (they >are not encrypted any
>way!!) the only thing is that the final user just cannot see any of the
php code, you know, he wouldn't ever >know the password for
>the database.
>My god, using that simple cookies is SO quick...