Re: Re[2]: [PEAR-DEV] We need another Auth
| From: | Bertrand Mansion | Date: | Mon, 10 Jun 2002 11:56:08 +0000 |
| Subject: | Re: Re[2]: [PEAR-DEV] We need another Auth | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-6857@lists.php.net to get a copy of this message | ||
le 10/06/02 13:17, Nicolas Hoizey à nhoizey@php.net a écrit :
>> I think that if the session is not started it means the user is not
>> authenticated.
>
> IMHO, you don't need sessions to manage authentication. Auth can use
> sessions, but it is not required, so the user can be authenticated
> even if there is no session started.
True, you can store something telling you the user is authenticated in a
cookie but this is very risky. Or you can pass this value along your urls
(even more risky).
At the moment, I can't think of a better way to handle authentication than
sessions. Even if someone could hijack your session id (because it is stored
in your cookie or your url) and get authenticated this way. It can be done
by using some javascript code. For instance, I am the admin of a job offers
site. People can post new offers on my site by using a form. In the job
description field, someone write some javascript to get the cookie value and
send this value to some other site which is just waiting for it. When me,
the admin, I am browsing the new offers, the javascript launches and the
other site knows my session id and can hijack my authenticated session.
You could even imagine some viruses which would go through your cookie files
and send the value it finds somewhere on the internet (a newsgroup).
OK, this is fantasy but it still is possible, especially with windows.
>> If you use a 'remember me' button, you will have to store the
>> session somewhere for later use.
>
> No. This needs another cookie. Sessions usually "die" when the user
> closes his browser.
There are two ways to do it and your solution is the second way, the way
Markus apparently chose for his code. This way is probably cleaner (you can
get rid of the session file with the garbage collector). I am still
considering the security risks.
Bertrand Mansion
Mamasam