Re: PHP4
| From: | James Lyon | Date: | Tue, 30 May 2000 14:07:57 +0000 |
| Subject: | Re: PHP4 | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-632@lists.php.net to get a copy of this message | ||
> OK Thnanks for the advice ... my site will be account based, so they will
> need account code, account password and basket id. Do you think this will
> be OK ?
Sounds like your baskets are a bit more sensitive than the scenario I depicted!
Go for the better solution of proper passwords (watch for guessable passwords
and sight in transit ... SSL?) and use basket ID's that aren't guessable. The
basic principal is the same though. Store the details on the server and just use
a code for tying the browser to the basket.
Just to explain, my shopping basket site is out in the open with
publicly-accessible databases and no user accounts. Anyone can wander about
helping themselves to products (like at a conventional real-life supermarket)
and apart from very bored people stealing your shopping basket for a larf, you
take it to the checkout. There I convert to a secure system and confirm /
complete the transaction for real money only once the basket is unpacked
securely at the checkout. My customers only buy one, maybe two items, so they
know what they're getting ...
In your case I think you want something much more safely tied to the user
browsing, from the outset.
> Or have you got any other recommendations, have you got one of your sites I
> can go and visit ?
Just as soon as Barclays get their act together ... should be later this week,
but we've been thinking that for over a month now. The entire site is running in
a private area at present but we're waiting for the bank to activate their end
of the secure part of the software...
Nudge me again later in the week for the URL if you're interested :-)