Security and Cookies

From: Date: Wed, 13 Dec 2000 02:01:28 +0000
Subject: Security and Cookies
Groups: php.general 
Request: Send a blank email to php-general+get-29977@lists.php.net to get a copy of this message
When I authenticate a user to access a certain part of a web site, I deliver a cookie right after the authentication succeeds. After that, I only check if the cookie exists or not. Then, I read a message on this list (don't remember which one) about someone who stored the login info (encrypted) on the cookie, and then he ran a query to the database to authenticate the cookie data each time a page required this cookie. So my doubts are if I am implementing a good authentication scheme by just checking if the cookie exists. What do you think, and better yet, share with the list what is your approach. Thanks in advance. -- ************************************ Ivan R. Quintero E.* (507)228-3477 Aptdo 1263 * (507)228-9105 Balboa, Ancon * Republic of Panama * ************************************

« previous php.general (#29977) next »