Re: Security and Cookies
| From: | Ignacio Vazquez-Abrams | Date: | Tue, 12 Dec 2000 23:08:28 +0000 |
| Subject: | Re: Security and Cookies | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-29979@lists.php.net to get a copy of this message | ||
On Tue, 12 Dec 2000, rodrigo wrote:
> When I authenticate a user to access a certain part of a web site, I
> deliver a cookie right after the authentication succeeds. After that, I
> only check if the cookie exists or not.
>
> Then, I read a message on this list (don't remember which one) about
> someone who stored the login info (encrypted) on the cookie, and then he
> ran a query to the database to authenticate the cookie data each time a
> page required this cookie.
>
> So my doubts are if I am implementing a good authentication scheme by
> just checking if the cookie exists. What do you think, and better yet,
> share with the list what is your approach.
>
> Thanks in advance.
>
A much better idea is to use the cookie to retrieve some information from a
separate source (e.g., database). The presence or absence of that information
determines the validity of the cookie.
--
Ignacio Vazquez-Abrams <ignacio@openservices.net>