note 35001 added to function.setcookie

From: Date: Fri, 15 Aug 2003 01:00:23 +0000
Subject: note 35001 added to function.setcookie
Groups: php.notes 
Request: Send a blank email to php-notes+get-54171@lists.php.net to get a copy of this message
To adamh at densi dot com (30-Jul-2003 05:28) "Keep in mind for security's sake that cookies can be edited by the client and stolen from the client. Like $_GET and $_POST, Their data should NOT be trusted. Don't put passwords (even hashes), credit card numbers, SQL query parameters, filenames, or anything else sensitive in them!" If you are unable to use sessions for some reason (for example if you have several separate web front ends. There are ways to ensure that the user has not tampered with the cookie values. Say that you want to store information in $x and $y - and you must be sure that the user doesn't tinker with it, you simply add a "salt". I.e.: $data = array('x' => $x, 'y' => $y); $data = serialize($data); $chksum = md5($data . md5('secret salt here')); $var = serialize(array($data,$chksum)); setcookie('data',$var,0,'/'); Now you can extract it with: var = unserialize($_COOKIE['data']); list($data,$chksum) = $var; if (md5($data . md5('secret salt here')) == $chksum) { // Data is valid $data = unserialize($data); $x = $data['x']; $y = $data['y']; } But of course I agree that you should never store anything important in them that the users could 'take advantage of'. ---- Manual Page -- http://www.php.net/manual/en/function.setcookie.php Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+35001 Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+35001&report=yes Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+35001&report=yes

« previous php.notes (#54171) next »