Re: We need another Auth

From: Date: Mon, 10 Jun 2002 11:30:27 +0000
Subject: Re: We need another Auth
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-6852@lists.php.net to get a copy of this message
le 10/06/02 12:53, Markus Wolff à wolff@21st.de a écrit : > Am Mon, 10 Jun 2002 12:39:21 +0200 schrieb Bertrand Mansion > <bmansion@mamasam.com>: >> The objective for me being that I don't want to store session files for >> users that don't need the 'remember me' feature. How do you handle this in >> your new auth class ? > > As you mentioned in an earlier posting, storing the 'remember me' option > in the session wouldn´t make too much sense, because when garbage > collection is done, the session is gone and you´ll have to > re-authenticate again. > > I use a separate cookie with the user´s handle in it. If that cookie is > present, the user is authenticated automatically without having to > provide a password. As this generally is risky business, you can turn > this feature off, which is the standard setting. Also, all cookie > parameters (name, path, domain, expiration date) can be freely > configured (as well as session name, session variable name, parameter > names for handle/password input and anything else that makes sense to be > configurable). I look forward to see your code, I think you made the good choices here. Just a thought, maybe it would be better to store a md5 hash of 'username:password' in the cookie instead of the user's handle. This way, it would be harder to guess that it is not a session id from the outside. 'Remember me' stuff is risky business as you say. For instance, I could fake a cookie value with someone else's handle and get automatically authentified. It is harder to guess a md5 hash than a username. This also means you will need to create a new field in your table for this hash because otherwise you won't be able to compare your cookie value to anything. Did you think about a way to handle this ? Bertrand Mansion Mamasam

« previous php.pear.dev (#6852) next »