RE: [PHP] Session With Cookies

From: Date: Sun, 04 Feb 2001 09:59:23 +0000
Subject: RE: [PHP] Session With Cookies
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-38087@lists.php.net to get a copy of this message
> > In case of login/password required sites, I use the login and > password as > > cookie values and have _no_ expiredate set. Every time a request is made > > _both_ cookie values (login and password) are checked with that on the > > server. > > I would hope that you are not storing and matching the user's plaintext > password... > Well .. I am ... nobody but the user itself can see the login and password in the cookie. Unless it's on non-SSL connection and somebody is packet-shiffing around. Otherwise there would be no leak for somebody else to get this information, is there? And if the user doesn't logout, the cookie is still destroyed when the browser is closed anyway. Eelco.

« previous php.general (#38087) next »