Re: Session With Cookies
| From: | Julie Meloni | Date: | Sun, 04 Feb 2001 09:19:02 +0000 |
| Subject: | Re: Session With Cookies | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-38085@lists.php.net to get a copy of this message | ||
Eelco de Vries wrote:
This will store a cookie with a userid and an unique number ($token) as session-id (??). If I'm not mistaken, this session-id is not checked here. Thus serves no purose. Anybody who retrieve the cookie from the cookie file on the system can use it to resume the session (if done within the set 3600sec.). Even if the browser has been closed.
The example here has nothing to do with sessions, you are correct. The person who replied to you simply gave you a code snippet from one of my books that assigns a unique id via a cookie. It does not map to a PHP session. As to your case:// Set Cookie if not already set if (!isset($user_id)) { $token = md5(uniqid(rand())); setcookie("user_id", $token, time()+3600,"/",".yourdomain.com"); }
In case of login/password required sites, I use the login and password as cookie values and have _no_ expiredate set. Every time a request is made _both_ cookie values (login and password) are checked with that on the server.I would hope that you are not storing and matching the user's plaintext password... +----------------------------------------+
| Julie Meloni (julie@thickbook.com) | | || "PHP Essentials" and "PHP Fast & Easy" |
| http://www.thickbook.com |+----------------------------------------+