Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - Have I applied the member API correctly?
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Have I applied the member API correctly?

 Post Reply Post Reply
Author
Gullanian View Drop Down
Senior Member
Senior Member
Avatar

Joined: 04 January 2002
Location: England
Status: Offline
Points: 4373
Post Options Post Options   Thanks (0) Thanks(0)   Quote Gullanian Quote  Post ReplyReply Direct Link To This Post Topic: Have I applied the member API correctly?
    Posted: 04 April 2011 at 3:52pm
The way I have applied it, is it processes the login on my custom login page (all works fine etc etc), then it selects the user code for the user that passed authentication, and drops that code in a cookie.  That code is then used to match to their database records on each page request.  I am now logged in on the forums, and my main site which is good :)

But is this correct?  The user code isn't changing because I've written my own login page, is this something I need to amend?  What would you recommend?  I've done it quite simply, might I have overlooked anything?

Thanks for any advice.  One thing I should mention is that all pages will be using SSL when they are logged in so cookie hijacking will be harder.
Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 04 April 2011 at 4:08pm
Using a cookie as authentication can be useful but as cookies are easy to fake on another machine you may want to look at combining it with some other method, such as something that authenticates the cookie server side for that session, or even using the database and using the session to track the user rather than setting cookies.
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.