Re: Encrypt Password for Session

From: Date: Thu, 17 May 2001 17:19:14 +0000
Subject: Re: Encrypt Password for Session
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-53276@lists.php.net to get a copy of this message
At 12:05 PM 5/17/01 -0500, Troy Moreland wrote:
I fully understand what you are saying. The problem is that I'm storing their password so that they don't have to re-enter it on each new page visited. If I can't decrypt it, then I can't pass that password for the user. How do I keep passing the password then w/o having to write it to the session. Is that the right way to do it??
What I do, is pass a cookie. On the login page, I give them a cookie. When they input a correct UN/PW, then I store the cookie. When the go on to the user pages, I take the cookie, give them a new cookie, and compare the old cookie to the DB cookie. If it's a match, then I store the new cookie to the db. The cookie is a 13 digit base 36 number, generated randomly. -- Dave's Engineering Page: http://www.dvanhorn.org Where's dave? http://www.findu.com/cgi-bin/find.cgi?kc6ete-9

« previous php.general (#53276) next »