Re: Session tracking question
| From: | Todd Cary | Date: | Tue, 23 Jan 2001 20:46:42 +0000 |
| Subject: | Re: Session tracking question | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-36263@lists.php.net to get a copy of this message | ||
Wade -
I am very new with using PHP so I cannot submit my answer as "what most
use". However, here is what I use:
I do not like to be dependent on Cookies. For me, Cookies are a
convenience. That is, I may store a UserID and if it is in a Cookie,
use the ID to put up a greeting or whatever.
Secondly, I am DB oriented, so I opt for DB solutions. I create a
SessionID using the time() function. This is stored in the DB with an
Expire time and it is the only value I pass from page to page (I use
POST for passing values). On login, I do get the UserID and PW and if
they are OK, I then assign the Session ID.
I realize there are many additions to the above that can make it more
secure, but I am not dealing with sensitive data at this time.
Todd
--
Todd Cary
Ariste Software
todd@aristesoftware.com