User authentication and cookies
| From: | David VanHorn | Date: | Fri, 21 Jul 2000 13:41:45 +0000 |
| Subject: | User authentication and cookies | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-7561@lists.php.net to get a copy of this message | ||
I've just implemented a user authentication system using cookies, and it seems to work pretty well, except for one problem.
I can't support two users on the same account.
Nor can I prevent the second user from logging in.
The way my system works is that when you supply a valid uname/password, you get a cookie, and the cookie is stored in the db. When you visit a secure page, I get your cookie, and give you another. If your cookie matches what's in the db, then I store the new one in it's place, and allow access to the page.
The problem occurs when user #2 logs in, and his cookie is stored in the DB.
Now when you change pages, your cookie no longer matches, and you have to re-login, which dumps user #2.
I thought about a logout, but I can't enforce a user to log out, so I really have no way to implement that, plus it would keep anyone else from logging in until....? on that account.
This behaviour is fine for 99% of the time, but I have a test account where I would like to let guest users in to check out the system. Problem is, I can only have one guest at any time.
What I'm looking for is some mechanism that will allow me to let guests into the system, without cluttering up the db.
I thought about generating randomized user names and accounts based on that, but then I have to clean them up, and a malicious user could hack me with a script to create thousands of guest accounts.
How do other sites handle the possibility of multiple browsers on the same account?
--
www.SpamWhack.com A pre-emptive strike against spam
Where's dave? http://www.findu.com/cgi-bin/find.cgi?kc6ete-9
My transistor sings
with unintended parasitic
the smoke escapes
By Jeff Stout