note 52648 deleted from function.setcookie by cmb
| From: | cmb@php.net | Date: | Sun, 10 Nov 2019 12:51:16 +0000 |
| Subject: | note 52648 deleted from function.setcookie by cmb | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-213008@lists.php.net to get a copy of this message | ||
Note Submitter: terry at scribendi dot com
----
A few comments have suggested using serialize() to set object or array data into a cookie. There
are a couple of reasons to be carefull with that technique:
Security: If the cookie is human readable, then it is also fairly easy for end users to play around
with it. Wrapping your cookie setting and getting in an encryption routine will prevent tampering,
and make sure that your cookies don't make any sense to any client-side exploits or other sites
they get sent to thanks to browser bugs.
Bulk: If you serialize even a fairly simple class, then you get a lot of data. Large cookies will
make browser requests fat and slow, and some browsers have a limit on cookie size, so think about
what data you really need to persist, and create __sleep() and __wakeup() methods to package the
data into the shortest possible form. You can get better and faster results when you write your own
__sleep() and __wakup() to implode() or pack() your data, than by using zlib compress() on the
serialized object.