User authentication and cookies

From: Date: Fri, 21 Jul 2000 13:41:45 +0000
Subject: User authentication and cookies
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-7561@lists.php.net to get a copy of this message
I've just implemented a user authentication system using cookies, and it seems to work pretty well, except for one problem. I can't support two users on the same account. Nor can I prevent the second user from logging in. The way my system works is that when you supply a valid uname/password, you get a cookie, and the cookie is stored in the db. When you visit a secure page, I get your cookie, and give you another. If your cookie matches what's in the db, then I store the new one in it's place, and allow access to the page. The problem occurs when user #2 logs in, and his cookie is stored in the DB. Now when you change pages, your cookie no longer matches, and you have to re-login, which dumps user #2. I thought about a logout, but I can't enforce a user to log out, so I really have no way to implement that, plus it would keep anyone else from logging in until....? on that account. This behaviour is fine for 99% of the time, but I have a test account where I would like to let guest users in to check out the system. Problem is, I can only have one guest at any time. What I'm looking for is some mechanism that will allow me to let guests into the system, without cluttering up the db. I thought about generating randomized user names and accounts based on that, but then I have to clean them up, and a malicious user could hack me with a script to create thousands of guest accounts. How do other sites handle the possibility of multiple browsers on the same account? -- www.SpamWhack.com A pre-emptive strike against spam Where's dave? http://www.findu.com/cgi-bin/find.cgi?kc6ete-9 My transistor sings with unintended parasitic the smoke escapes By Jeff Stout

« previous php.general (#7561) next »