Re: User authentication and cookies
| From: | TomHenry | Date: | Fri, 21 Jul 2000 16:48:47 +0000 |
| Subject: | Re: User authentication and cookies | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-7600@lists.php.net to get a copy of this message | ||
David,
It "sounds like" there's only one session record being saved in the database.
You need to create a separate record for each session (each new user) and save the value of the cookie for that user/session as part of the database record.
There are several versions of session databases around. Take a look through the various code archives and PHPLIB (and their code as an example) for table layouts -- you'll get great ideas.
Without the actual code you are using to create the sessions and the cookies it's not possible (for me) to help any further.
HTH,
Tom Henry
At 08:41 AM 7/21/00 -0500, David VanHorn wrote:
I've just implemented a user authentication system using cookies, and it seems to work pretty well, except for one problem. I can't support two users on the same account. Nor can I prevent the second user from logging in. The way my system works is that when you supply a valid uname/password, you get a cookie, and the cookie is stored in the db. When you visit a secure page, I get your cookie, and give you another. If your cookie matches what's in the db, then I store the new one in it's place, and allow access to the page. The problem occurs when user #2 logs in, and his cookie is stored in the DB. Now when you change pages, your cookie no longer matches, and you have to re-login, which dumps user #2. I thought about a logout, but I can't enforce a user to log out, so I really have no way to implement that, plus it would keep anyone else from logging in until....? on that account. This behaviour is fine for 99% of the time, but I have a test account where I would like to let guest users in to check out the system. Problem is, I can only have one guest at any time. What I'm looking for is some mechanism that will allow me to let guests into the system, without cluttering up the db. I thought about generating randomized user names and accounts based on that, but then I have to clean them up, and a malicious user could hack me with a script to create thousands of guest accounts. How do other sites handle the possibility of multiple browsers on the same account? -- www.SpamWhack.com A pre-emptive strike against spam Where's dave? http://www.findu.com/cgi-bin/find.cgi?kc6ete-9 My transistor sings with unintended parasitic the smoke escapes By Jeff Stout -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net--------------------------------------------------------------------
Strategic Business Systems (978) 745-2332
http://BusinessWebs.com/
--------------------------------------------------------------------