Re: Storing passwords in session variables

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 





Am 11.12.2012 20:51, schrieb Peet Grobler:
On 2012/12/11 2:46 PM, Paul Halliday wrote:
Client <-> Server is encrypted,  can I toss these into session variables?


Do note your full url (including &user=xx&pass=yy will be logged in
apache logs, and depending on configuration in squid logs in-between too.

Normally you would pass credential as post variables or even better use http auth for that. (read about http code 401

How to send in HTTP: http://en.wikipedia.org/wiki/Basic_access_authentication

Read in auth vars in PHP: http://php.net/manual/de/features.http-auth.php



--
Marco Behnke
Dipl. Informatiker (FH), SAE Audio Engineer
Zend Certified Engineer PHP 5.3

Tel.: 0174 / 9722336
e-Mail: marco@xxxxxxxxxx

Softwaretechnik Behnke
Heinrich-Heine-Str. 7D
21218 Seevetal

http://www.behnke.biz

<<attachment: smime.p7s>>


[Index of Archives]     [PHP Home]     [Apache Users]     [PHP on Windows]     [Kernel Newbies]     [PHP Install]     [PHP Classes]     [Pear]     [Postgresql]     [Postgresql PHP]     [PHP on Windows]     [PHP Database Programming]     [PHP SOAP]

  Powered by Linux