Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.programming > #2818

Using sessions and cookies

From Victor Porton <porton@narod.ru>
Newsgroups comp.programming
Subject Using sessions and cookies
Followup-To comp.programming
Date 2013-01-15 19:37 +0200
Organization Aioe.org NNTP Server
Message-ID <kd444e$b9h$1@speranza.aioe.org> (permalink)

Followups directed to: comp.programming

Show all headers | View raw


From
http://www.larryullman.com/2010/01/07/custom-authentication-using-the-yii-framework/:

Now, by default, Yii will use cookies for authentication. In most
situations that’s fine, but if anything of a sensitive nature is
being stored, you should use sessions instead. This would apply
to both the user’s ID value and their role. If either is
available through a cookie, it wouldn’t be hard for the user to
edit that cookie’s value in order to become someone else. So, to
start, let’s disable the potential for using cookies.

My question: Is it OK to use cookies for:
1. storing session IDs?
2. storing username and password?

Larry speaks as if using cookies and using sessions would contradict
to each other. But what about the combination (1. above) to use
cookies with session IDs?

-- 
Victor Porton - http://portonvictor.org

Back to comp.programming | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

Using sessions and cookies Victor Porton <porton@narod.ru> - 2013-01-15 19:37 +0200
  Re: Using sessions and cookies Bjoern Hoehrmann <bjoern@hoehrmann.de> - 2013-01-15 20:33 +0100
  Re: Using sessions and cookies bob <bob@coolfone.comze.com> - 2013-01-15 13:07 -0800

csiph-web