Re: Re: IE 5.5,authentication,PHP sessions: IE never stops running?

From: Date: Sun, 04 Mar 2001 05:20:28 +0000
Subject: Re: Re: IE 5.5,authentication,PHP sessions: IE never stops running?
References: 1 2  Groups: php.general php.windows 
Request: Send a blank email to php-general+get-42491@lists.php.net to get a copy of this message
Ken, I didn't believe you that IE was so stupidly implemented until I tried it myself. You are right, IE 5 rememebers the password even though I hit CANCEL on the re-authenticate prompt. And it remembers the password even when I close all browser windows. If you decide to store authentication in the session, a good way to generate a 32 character "token" is md5(uniqid(rand())). You store a copy of this token in your database (with some expiration time) and give a copy of it to the user (either in the session or in a plain old cookie). For me to implement log-out is not so easy because I am using .htaccess. I guess I'll just require the crypt() of the PW to be in a cookie. Logout will just put garbage into the cookie. Hopefully no one will discover that they can hijack someone elses login by just deleting the cookie. :-(
John Henckel          alt. mailto:henckel@iname.com
Zumbro Falls, Minnesota, USA (507) 753-2216 http://geocities.com/jdhenckel/

« previous php.general (#42491) next »