Re: PHP4
| From: | James Lyon | Date: | Tue, 30 May 2000 13:33:30 +0000 |
| Subject: | Re: PHP4 | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-628@lists.php.net to get a copy of this message | ||
> Typical me, if I can over complicate something I will. I think you may have
> just brought me on leaps and bounds in just a couple of sentences, cheers
A business associate, Andy (hi if you're reading this!) has kindly just pointed
out to me something I've taken for granted here ...
When I use the unique ID, I lazily use an auto-incrementing integer. This isn't
secure ... if you care about people hacking about and messing with other
people's baskets, then you should randomize and/or encrypt the identifier so it
can't be guessed.
As it happens I use it in a situation where the security isn't an issue ... when
the basket is taken to the checkout it's converted into a secure package using
an entirely different approach over 128-bit SSL to be sure.
Hope this helps,
James.