Welcome
Welcome to the Official<strong>World of Phaos</strong>Forums.

You are currently viewing our boards as a guest, which gives you limited access to view most discussions and access our other features. By joining the World of Phaos community for free, you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content, and access many other special features. Registration is fast, simple, and absolutely free, so please, <a href="/profile.php?mode=register">join the World of Phaos community today</a>!

user sessions management

General chat about the development of 'World of Phaos'

Moderators: Aradan, zeke

user sessions management

Postby sanjeevan on Mon Jun 16, 2008 6:36 am

you are storing the user's password in a cookie. why would you do that when it is an big security hole.
sanjeevan
Level 1
 
Posts: 4
Joined: Mon Jun 16, 2008 6:25 am

Postby Aradan on Wed Aug 27, 2008 5:00 am

Extremaly good point.. one that must be addressed.
Cheers,
-Aradan
World of Phaos Developer
Aradan
WoP Forum Admin
 
Posts: 61
Joined: Thu Sep 27, 2007 12:59 am
Location: UK

Postby Arwym Starlight on Thu Aug 28, 2008 12:35 am

People are too afraid of cookies. >.> How many times have you been in trouble because you stored a cookie, really? Yeah, I think that sessions work better for this, but let's not be so paranoid about cookies. Nothing is 100% secure, especially when it's about the web.

My suggestion: make the cookies last only a few days. Maybe even just one. Give the player the option, if you want. Or let them choose whether they want to use cookies or not. And if they don't want to choose to store cookies, then a session will be created for them. :o Isn't that better? You give the player the control. And if something bad happens, you are not blamed for it. :P
User avatar
Arwym Starlight
Level 2
 
Posts: 22
Joined: Sun Sep 30, 2007 2:40 am
Location: Puerto Rico


Return to General Development Chat

Who is online

Users browsing this forum: No registered users and 1 guest