note 31377 deleted from function.setcookie by victor

From: Date: Sat, 27 Mar 2004 20:23:15 +0000
Subject: note 31377 deleted from function.setcookie by victor
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-67252@lists.php.net to get a copy of this message
Note Submitter: serrano@no.emails.pls ---- Hi, it seems most of the coders get stuck with expiring the cookie, and using the cookie in the same document as they set it. first case, you will face many problems when using expiring cookies for session data etc. SO, SOLUTION: don't use expire at all, or use it to expire the cookie once browser session is closed (0). then, keep track of cookie expires in database, and refresh this each time the user gets this cookie renewed. I always re-set expiration when user is logged in and accesses any admin pages. no time difference matters will occur this way. SOLUTION #2: make your clients life easier, and make a little front-end like like this: have variables (an array, for e.g) for your cookied user data (for me, usually only username and an authentication cookie). Then, at code startup, make sure client does not spoof these variables (might be necessary, but not alway). two things left to do are: check if user sent cookie data, and if did, update your variables, and, when you set a cookie, set your variables also. a real-life example: $user = array ( "name" => "", "pass" => "", "session" => "", "id" => "" ); if ($_COOKIE[name]) $user[name]=$_COOKIE[name]); if ($_COOKIE[session]) $user[session]=$_COOKIE[session]); if ($user[name] && $user[session]) { # here check your database if username and session are valid. if not, drop user out here to the login screen (eg. include ("login.html"); die();) # if they are, renew cookies setcookie ("name", $user[name] (...) ); setcookie ("session", $user[session] (...) ); # update expiration in your database here } elseif ($user[name] && $user[pass]) { # user submitted credentials, check database if those are valid, if not, drop user back to login screen (see above). $result = mysql_query ("select id from users where username='$user[name]' and pass=password('$user[pass]')"); if (!mysql_num_rows ($result)) { include ("login.html"); die(); }; # otherwise, fetch user id, generate a cookie, send him, and update db $row = mysql_fetch_array ($result); $user[id] = $row[id]; $user [session] = md5(uniqid(mt_rand())); setcookie ("username", $user[name]); setcookie ("session", $user[session]); #update database, like this: mysql_query ("update users set session=$user[session], expire=".(time()+3600)." where user_id = $user[id]"); } else { # if has no cookies, not submitted credentials, drop login page include ("login.html"); die (); }; from this on, you can use the $user array for anything. you can use more cookies as well, and you can skip most of the code if you do not want authentication (but then, why expire and security at all ? :) I hope this code works fine, wrote from scratch... but, you can intagrate any startup procedure related to client sessions etc. as you can see, there is no need at all of any redirects (Location: etc.), which is a completely innecessary thing. a little explanation on the database: I assumed you have a table like this: create table users (id int(32) primary key not null auto_increment, username char(16), pass char(16), session char(32), expire int(64)); and remember to store passwords using mysql's password ()function, so passwords will be safe. this table will be fast for many users as well, and should you change any database user data later in this script, you can reference it with $user[id]... in this case _REALLY_ make sure client will not spoof this variable of yours! :)

« previous php.notes (#67252) next »