Re: Stopping stolen / spoofed / linked sessions
| From: | Rasmus Lerdorf | Date: | Sat, 30 Jun 2001 22:20:07 +0000 |
| Subject: | Re: Stopping stolen / spoofed / linked sessions | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-55692@lists.php.net to get a copy of this message | ||
> > Ok, stop right there. Sessions and authentication have nothing to do with
> > each other. To create a secure authenticated site you should be using
> > HTTP-based authentication over SSL. Sessions are simply for maintaining
> > state across http requests and have nothing to do with authentication.
> >
> > -Rasmus
>
> So setting a 'loggedin' session variable once a person has authenticated, and
> checking for that session variable each request before proceeding is not ok?
No, this is what I was trying to make sure people realized. It is only ok
if this happens over SSL and there is no chance that someone else can
sniff the session id.
-Rasmus