note 35001 added to function.setcookie
| From: | (ioflux net) | Date: | Fri, 15 Aug 2003 01:00:23 +0000 |
| Subject: | note 35001 added to function.setcookie | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-54171@lists.php.net to get a copy of this message | ||
To adamh at densi dot com (30-Jul-2003 05:28)
"Keep in mind for security's sake that cookies can be edited by the client and stolen from
the client. Like $_GET and $_POST, Their data should NOT be trusted. Don't put passwords (even
hashes), credit card numbers, SQL query parameters, filenames, or anything else sensitive in
them!"
If you are unable to use sessions for some reason (for example if you have several separate web
front ends.
There are ways to ensure that the user has not tampered with the cookie values.
Say that you want to store information in $x and $y - and you must be sure that the user
doesn't tinker with it, you simply add a "salt". I.e.:
$data = array('x' => $x, 'y' => $y);
$data = serialize($data);
$chksum = md5($data . md5('secret salt here'));
$var = serialize(array($data,$chksum));
setcookie('data',$var,0,'/');
Now you can extract it with:
var = unserialize($_COOKIE['data']);
list($data,$chksum) = $var;
if (md5($data . md5('secret salt here')) == $chksum)
{
// Data is valid
$data = unserialize($data);
$x = $data['x'];
$y = $data['y'];
}
But of course I agree that you should never store anything important in them that the users could
'take advantage of'.
----
Manual Page -- http://www.php.net/manual/en/function.setcookie.php
Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+35001
Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+35001&report=yes
Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+35001&report=yes