Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.programming > #2818
| From | Victor Porton <porton@narod.ru> |
|---|---|
| Newsgroups | comp.programming |
| Subject | Using sessions and cookies |
| Followup-To | comp.programming |
| Date | 2013-01-15 19:37 +0200 |
| Organization | Aioe.org NNTP Server |
| Message-ID | <kd444e$b9h$1@speranza.aioe.org> (permalink) |
Followups directed to: comp.programming
From http://www.larryullman.com/2010/01/07/custom-authentication-using-the-yii-framework/: Now, by default, Yii will use cookies for authentication. In most situations that’s fine, but if anything of a sensitive nature is being stored, you should use sessions instead. This would apply to both the user’s ID value and their role. If either is available through a cookie, it wouldn’t be hard for the user to edit that cookie’s value in order to become someone else. So, to start, let’s disable the potential for using cookies. My question: Is it OK to use cookies for: 1. storing session IDs? 2. storing username and password? Larry speaks as if using cookies and using sessions would contradict to each other. But what about the combination (1. above) to use cookies with session IDs? -- Victor Porton - http://portonvictor.org
Back to comp.programming | Previous | Next — Next in thread | Find similar | Unroll thread
Using sessions and cookies Victor Porton <porton@narod.ru> - 2013-01-15 19:37 +0200 Re: Using sessions and cookies Bjoern Hoehrmann <bjoern@hoehrmann.de> - 2013-01-15 20:33 +0100 Re: Using sessions and cookies bob <bob@coolfone.comze.com> - 2013-01-15 13:07 -0800
csiph-web