note 31377 deleted from function.setcookie by victor
| From: | victor@php.net | Date: | Sat, 27 Mar 2004 20:23:15 +0000 |
| Subject: | note 31377 deleted from function.setcookie by victor | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-67252@lists.php.net to get a copy of this message | ||
Note Submitter: serrano@no.emails.pls
----
Hi,
it seems most of the coders get stuck with expiring the cookie, and using the cookie in the same
document as they set it.
first case, you will face many problems when using expiring cookies for session data etc.
SO, SOLUTION: don't use expire at all, or use it to expire the cookie once browser session is
closed (0). then, keep track of cookie expires in database, and refresh this each time the user gets
this cookie renewed. I always re-set expiration when user is logged in and accesses any admin pages.
no time difference matters will occur this way.
SOLUTION #2: make your clients life easier, and make a little front-end like like this: have
variables (an array, for e.g) for your cookied user data (for me, usually only username and an
authentication cookie). Then, at code startup, make sure client does not spoof these variables
(might be necessary, but not alway). two things left to do are: check if user sent cookie data, and
if did, update your variables, and, when you set a cookie, set your variables also. a real-life
example:
$user = array (
"name" => "",
"pass" => "",
"session" => "",
"id" => ""
);
if ($_COOKIE[name]) $user[name]=$_COOKIE[name]);
if ($_COOKIE[session]) $user[session]=$_COOKIE[session]);
if ($user[name] && $user[session]) {
# here check your database if username and session are valid. if not, drop user out here to the
login screen (eg. include ("login.html"); die();)
# if they are, renew cookies
setcookie ("name", $user[name] (...) );
setcookie ("session", $user[session] (...) );
# update expiration in your database here
}
elseif ($user[name] && $user[pass]) {
# user submitted credentials, check database if those are valid, if not, drop user back to login
screen (see above).
$result = mysql_query ("select id from users where username='$user[name]' and
pass=password('$user[pass]')");
if (!mysql_num_rows ($result)) {
include ("login.html");
die();
};
# otherwise, fetch user id, generate a cookie, send him, and update db
$row = mysql_fetch_array ($result);
$user[id] = $row[id];
$user [session] = md5(uniqid(mt_rand()));
setcookie ("username", $user[name]);
setcookie ("session", $user[session]);
#update database, like this:
mysql_query ("update users set session=$user[session], expire=".(time()+3600)."
where user_id = $user[id]");
}
else {
# if has no cookies, not submitted credentials, drop login page
include ("login.html");
die ();
};
from this on, you can use the $user array for anything. you can use more cookies as well, and you
can skip most of the code if you do not want authentication (but then, why expire and security at
all ? :) I hope this code works fine, wrote from scratch... but, you can intagrate any startup
procedure related to client sessions etc.
as you can see, there is no need at all of any redirects (Location: etc.), which is a completely
innecessary thing.
a little explanation on the database: I assumed you have a table like this:
create table users (id int(32) primary key not null auto_increment, username char(16), pass
char(16), session char(32), expire int(64));
and remember to store passwords using mysql's password ()function, so passwords will be safe.
this table will be fast for many users as well, and should you change any database user data later
in this script, you can reference it with $user[id]... in this case _REALLY_ make sure client will
not spoof this variable of yours! :)