Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.php > #4152

Re: standard easy way to set up a registration/logon cookie?

From The Natural Philosopher <tnp@invalid.invalid>
Newsgroups comp.lang.php
Subject Re: standard easy way to set up a registration/logon cookie?
Date 2011-12-27 21:06 +0000
Organization albasani.net
Message-ID <jddc0f$i8o$1@news.albasani.net> (permalink)
References <jdaaht$amv$1@news.albasani.net> <h1vhf7p2cqrlbfi3u7eojc68lm702nq3uf@4ax.com>

Show all headers | View raw


r.mariotti@fdcx.net wrote:
> On Mon, 26 Dec 2011 17:23:08 +0000, The Natural Philosopher
> <tnp@invalid.invalid> wrote:
> 
>> Someone wants to set up a specialist discussion site: I want to keep it 
>> simple  so I don't want to use a pre packaged solution.
>>
>> Essentially he needs to let users comment on topics, and have some 
>> control over spam and abuse, hence registration and a name/password combo.
>>
>> But given the technical lack of sophistication of the target audience, 
>> persistent cookies would be a good thing to allow them to stay logged in 
>> indefinitely (or not if the desire)
>>
>> I'd like to hand out some random cookie when they register, or log in 
>> and stick it in the database, together with a time value which, if they 
>> don't want to 'persist' would be ignored if it was out of date.
>>
>> Then write a simple PHP module that says 'if the cookie is valid, you 
>> are Joe Bloggs and you can post away' else if not, throw them into a 
>> login/registration screen.
>>
>> Is 'sessions' any real help here? Or is it just easier to set and 
>> retrieve a cookie at a more basic level?
>>
> 
> You might want to consider looking at what's available as a CMS
> specific for forums.  You would search network.acquia.com or
> drupal.org for plug in solutions.
> Just my $.02 worth.

I might, except for two things.

I can code faster than I can discover how other peoples abortions work.

The amount of probes on my site already looking for proprietary solution 
code that isn't there because I haven't installed any leads me to 
believe that other peoples' solutions (unless you understand them fully) 
are a massive invitation to hackers:

At least this way there is very little I need to guard against beyond 
the stock SQL injection attacks and  the search for unguarded scannable 
directories.

It is the case that as with so many things I have implemented in real 
lie, buying someone else's solution and learning how to make it do the 
70% of what you want that it is capable of doing, is often  more time 
consuming than writing the 99% solution yourself.

When trying to make an electric toy van, it ill behoves one to start 
with a train set..

Back to comp.lang.php | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

standard easy way to set up a registration/logon cookie? The Natural Philosopher <tnp@invalid.invalid> - 2011-12-26 17:23 +0000
  Re: standard easy way to set up a registration/logon cookie? houghi <houghi@houghi.org.invalid> - 2011-12-26 18:50 +0100
  Re: standard easy way to set up a registration/logon cookie? Allodoxaphobia <knock_yourself_out@example.net> - 2011-12-26 21:40 +0000
    Re: standard easy way to set up a registration/logon cookie? houghi <houghi@houghi.org.invalid> - 2011-12-27 18:47 +0100
      Re: standard easy way to set up a registration/logon cookie? The Natural Philosopher <tnp@invalid.invalid> - 2011-12-27 20:59 +0000
    Re: standard easy way to set up a registration/logon cookie? The Natural Philosopher <tnp@invalid.invalid> - 2011-12-27 20:49 +0000
  Re: standard easy way to set up a registration/logon cookie? r.mariotti@fdcx.net - 2011-12-26 18:00 -0500
    Re: standard easy way to set up a registration/logon cookie? The Natural Philosopher <tnp@invalid.invalid> - 2011-12-27 21:06 +0000

csiph-web