Re: Security and Cookies

From: Date: Tue, 12 Dec 2000 23:08:28 +0000
Subject: Re: Security and Cookies
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-29979@lists.php.net to get a copy of this message
On Tue, 12 Dec 2000, rodrigo wrote: > When I authenticate a user to access a certain part of a web site, I > deliver a cookie right after the authentication succeeds. After that, I > only check if the cookie exists or not. > > Then, I read a message on this list (don't remember which one) about > someone who stored the login info (encrypted) on the cookie, and then he > ran a query to the database to authenticate the cookie data each time a > page required this cookie. > > So my doubts are if I am implementing a good authentication scheme by > just checking if the cookie exists. What do you think, and better yet, > share with the list what is your approach. > > Thanks in advance. > A much better idea is to use the cookie to retrieve some information from a separate source (e.g., database). The presence or absence of that information determines the validity of the cookie. -- Ignacio Vazquez-Abrams <ignacio@openservices.net>

« previous php.general (#29979) next »