Re: Re: IE 5.5,authentication,PHP sessions: IE never stops running?
| From: | John Henckel | Date: | Sun, 04 Mar 2001 05:20:28 +0000 |
| Subject: | Re: Re: IE 5.5,authentication,PHP sessions: IE never stops running? | ||
| References: | 1 2 | Groups: | php.general php.windows |
| Request: | Send a blank email to php-windows+get-5813@lists.php.net to get a copy of this message | ||
Ken, I didn't believe you that IE was so stupidly implemented until I tried it myself. You are right, IE 5 rememebers the password even though I hit CANCEL on the re-authenticate prompt. And it remembers the password even when I close all browser windows.
If you decide to store authentication in the session, a good way to generate a 32 character "token" is md5(uniqid(rand())). You store a copy of this token in your database (with some expiration time) and give a copy of it to the user (either in the session or in a plain old cookie).
For me to implement log-out is not so easy because I am using .htaccess. I guess I'll just require the crypt() of the PW to be in a cookie. Logout will just put garbage into the cookie. Hopefully no one will discover that they can hijack someone elses login by just deleting the cookie. :-(
John Henckel alt. mailto:henckel@iname.comZumbro Falls, Minnesota, USA (507) 753-2216 http://geocities.com/jdhenckel/