note 36058 added to features.cookies
| From: | myfirstname at braincell dot cx | Date: | Wed, 24 Sep 2003 12:47:59 +0000 |
| Subject: | note 36058 added to features.cookies | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-57041@lists.php.net to get a copy of this message | ||
Just a general comment on Wilton's code snippet: It's generally considered very bad
practice to store usernames and/or passwords in cookies, whether or not they're obsfucated.
Many spyware programs make a point of stealing cookie contents.
A much better solution would be to either use the PHP built in session handler or create something
similar using your own cookie-based session ID. This session ID could be tied to the source IP
address or can be timed out as required but since the ID can be expired separately from the
authentication criteria the authentication itself is not compromised.
Stuart Livings
----
Manual Page -- http://www.php.net/manual/en/features.cookies.php
Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+36058
Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+36058&report=yes
Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+36058&report=yes