Re: Encrypt Password for Session

From: Date: Tue, 22 May 2001 08:00:07 +0000
Subject: Re: Encrypt Password for Session
References: 1 2 3  Groups: php.general 
Request: Send a blank email to php-general+get-53819@lists.php.net to get a copy of this message
Troy Moreland wrote:
If I can't decrypt it, then I can't pass that password for the user. How do I keep passing the password then w/o having to write it to the session. Is that the right way to do it??
I don't know if this is the right way but what I would do is have a login page that does the md5 databse lookup, if it is successful writes the users name to a variable to the current session, maybe $verified_user Now every page tests for $verified_user you will know if they have logged in correctly, This approach seems to work very well for me, I don't know if there are any major security holes though? example: if ( isset($verified_user) ) { $user = $verified_user; } else { $user = "nobody"; } Hope this helps, it is pretty simple really. Regards Joseph

« previous php.general (#53819) next »