Re: Re: WAYS OF AUTHENICATION - open discussion
| From: | Richard Creech - DreamRiver.com | Date: | Tue, 07 Nov 2000 09:46:37 +0000 |
| Subject: | Re: Re: WAYS OF AUTHENICATION - open discussion | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-24078@lists.php.net to get a copy of this message | ||
Hello Fábio,
Thank you very much for your post. I did not supply enough data - for example the authentication is
not for all users, just one administrator. But rather than go into those details - given that this
thread is continuing - I would much rather keep my ears to the ground and absorb as much of this
excellent thread as possible. It is a very good learning experience.
Kind Regards,
Richard.
Message-ID: <00c801c0483b$06987920$c87dcac8@asd>
From: "Fábio Ottolini" <fabio.ottolini@uol.com.br>
To: <php-general@lists.php.net>
Date: Mon, 6 Nov 2000 19:46:30 -0200
Subject: Re: [PHP] Re: WAYS OF AUTHENICATION - open discussion
The thing is that if you have lots of users things can get very tricky... At
least one line per user. If a user wants to change the password how are you
goint to handle the change? That's why I believe DB's are more suitable for
this situation. Security is not the big issue in this case unless you have
your document_root set as "/" (just kidding). On the other hand, supposing a
crazy and lunatic web admin messes up with Apache's conf files removing PHP
MIME types and PHP files are sent to the browser just as plain text,
passwords are going to be read by anyone who tries to get a hold of your
include file!!!
Best regards,
Fábio Ottolini
Eletronic.Net