Security and Cookies
| From: | rodrigo | Date: | Wed, 13 Dec 2000 02:01:28 +0000 |
| Subject: | Security and Cookies | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-29977@lists.php.net to get a copy of this message | ||
When I authenticate a user to access a certain part of a web site, I
deliver a cookie right after the authentication succeeds. After that, I
only check if the cookie exists or not.
Then, I read a message on this list (don't remember which one) about
someone who stored the login info (encrypted) on the cookie, and then he
ran a query to the database to authenticate the cookie data each time a
page required this cookie.
So my doubts are if I am implementing a good authentication scheme by
just checking if the cookie exists. What do you think, and better yet,
share with the list what is your approach.
Thanks in advance.
--
************************************
Ivan R. Quintero E.* (507)228-3477
Aptdo 1263 * (507)228-9105
Balboa, Ancon *
Republic of Panama *
************************************