note 36058 added to features.cookies

From: Date: Wed, 24 Sep 2003 12:47:59 +0000
Subject: note 36058 added to features.cookies
Groups: php.notes 
Request: Send a blank email to php-notes+get-57041@lists.php.net to get a copy of this message
Just a general comment on Wilton's code snippet: It's generally considered very bad practice to store usernames and/or passwords in cookies, whether or not they're obsfucated. Many spyware programs make a point of stealing cookie contents. A much better solution would be to either use the PHP built in session handler or create something similar using your own cookie-based session ID. This session ID could be tied to the source IP address or can be timed out as required but since the ID can be expired separately from the authentication criteria the authentication itself is not compromised. Stuart Livings ---- Manual Page -- http://www.php.net/manual/en/features.cookies.php Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+36058 Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+36058&report=yes Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+36058&report=yes

« previous php.notes (#57041) next »