Re: Re[2]: [PEAR-DEV] We need another Auth

From: Date: Mon, 10 Jun 2002 11:56:08 +0000
Subject: Re: Re[2]: [PEAR-DEV] We need another Auth
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-6857@lists.php.net to get a copy of this message
le 10/06/02 13:17, Nicolas Hoizey à nhoizey@php.net a écrit : >> I think that if the session is not started it means the user is not >> authenticated. > > IMHO, you don't need sessions to manage authentication. Auth can use > sessions, but it is not required, so the user can be authenticated > even if there is no session started. True, you can store something telling you the user is authenticated in a cookie but this is very risky. Or you can pass this value along your urls (even more risky). At the moment, I can't think of a better way to handle authentication than sessions. Even if someone could hijack your session id (because it is stored in your cookie or your url) and get authenticated this way. It can be done by using some javascript code. For instance, I am the admin of a job offers site. People can post new offers on my site by using a form. In the job description field, someone write some javascript to get the cookie value and send this value to some other site which is just waiting for it. When me, the admin, I am browsing the new offers, the javascript launches and the other site knows my session id and can hijack my authenticated session. You could even imagine some viruses which would go through your cookie files and send the value it finds somewhere on the internet (a newsgroup). OK, this is fantasy but it still is possible, especially with windows. >> If you use a 'remember me' button, you will have to store the >> session somewhere for later use. > > No. This needs another cookie. Sessions usually "die" when the user > closes his browser. There are two ways to do it and your solution is the second way, the way Markus apparently chose for his code. This way is probably cleaner (you can get rid of the session file with the garbage collector). I am still considering the security risks. Bertrand Mansion Mamasam

« previous php.pear.dev (#6857) next »