note 37732 deleted from function.setcookie by crell
| From: | crell@php.net | Date: | Tue, 12 Apr 2022 00:36:42 +0000 |
| Subject: | note 37732 deleted from function.setcookie by crell | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-218149@lists.php.net to get a copy of this message | ||
Note Submitter: apex at xepa dot nl
----
Note on setting cookies allowing access to sites:
If you are not using something "personal" from the computer that you are sending the
cookie too watch out. Via javascript it is possible to steal cookies from other users. Thus
allowing the stealer to login to your site as another user that might not have access otherwise.
Try to add something like the user's ip in the cookie and allowing access from that ip only
with the stored cookie data.
[Editor's note: ... or simply use sessions. You can't be sure that the visitor will use
the same IP the next visit. Not even on the next request (thanks to proxy servers)]