note 53770 deleted from function.md5 by nlopess
| From: | nlopess@php.net | Date: | Wed, 13 Jul 2005 12:52:11 +0000 |
| Subject: | note 53770 deleted from function.md5 by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-91890@lists.php.net to get a copy of this message | ||
Note Submitter: Thomas Holz
----
You can easily use md5() to create safe (signed) links, which cannot created by anybody else. This
can be useful to transfer the user from one page to another without allowing him to manipulate any
parameters (product price for example).
Example URL: (don't click it, it's just an example ;-)
http://www.easy2sync.com/?p1=myvalue&p2=ABCDEF0123456789
To make this secure, generate p2 as md5($p1."mysecretvalue");
This way, you can use md5 as a primitive signature. As long as you keep your secret string really
secret, nobody else can generate links that you target page would accept (since it would compare p2
with the md5 result of p1 and secret string).
Thomas
--------------------------------------------
http://www.easy2sync.com/en/produkte/e2s4o.php