Re: Stopping stolen / spoofed / linked sessions
| From: | Rasmus Lerdorf | Date: | Fri, 29 Jun 2001 15:30:22 +0000 |
| Subject: | Re: Stopping stolen / spoofed / linked sessions | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-55557@lists.php.net to get a copy of this message | ||
> I want to use PHP4 sessions for authentication,
Ok, stop right there. Sessions and authentication have nothing to do with
each other. To create a secure authenticated site you should be using
HTTP-based authentication over SSL. Sessions are simply for maintaining
state across http requests and have nothing to do with authentication.
-Rasmus