Re: User authentication

by Snuggle (Friar)
by Snuggle (Friar)
on Jul 24, 2001

in reply to User authentication

On the few semi-secure (nothing too sensitive) sites that I have worked on, we have always stored the username and crypto password in a session based cookie. This cookie would be persistant for the session only by not setting the expires cookie variable. We would also set a longer term cookie with the username a some simple preferences, so on login the page would display as set by the user. If any changes were to be made, the user would log in and subsequent pages would look for and authenticate the session cookie.

This allows the user to have "off the cuff" preferences available but includes persistant access after login.

Re: Re: User authentication
by Siddartha (Curate) on Jul 25, 2001 at 12:49 UTC
    Yes this does help.

    It seems to be the best way for this particular case.



