dongqiya9552 2011-07-08 18:22
浏览 20
已采纳

保护PHP $ _SESSION数据?

I'm working on a project that requires sessions instead of cookies and I was wondering what a good way to secure them are? With cookies I would just do something like this:

$x = serialize(array('username', sha1('pwd')));
setcookie('cookieName', $x, time()+60);
...
$myCookie = unserialize($_COOKIE['cookieName']));
echo $myCookie[0];

But I'm not quite sure how to go about it with sessions.

  • 写回答

3条回答 默认 最新

  • duanfu7840 2011-07-08 18:26
    关注

    There's no need to serialize data in the session. It gets serialized for you.

    Also I don't see what this has to do with security. The SHA1 hashing of the password in the cookie? You shouldn't send a password client-side at all! At least in the session that variable would only be stored server side (Sessions are stored in a server-side file by default)

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(2条)

报告相同问题?

悬赏问题

  • ¥15 拟通过pc下指令到安卓系统,如果追求响应速度,尽可能无延迟,是不是用安卓模拟器会优于实体的安卓手机?如果是,可以快多少毫秒?
  • ¥20 神经网络Sequential name=sequential, built=False
  • ¥16 Qphython 用xlrd读取excel报错
  • ¥15 单片机学习顺序问题!!
  • ¥15 ikuai客户端多拨vpn,重启总是有个别重拨不上
  • ¥20 关于#anlogic#sdram#的问题,如何解决?(关键词-performance)
  • ¥15 相敏解调 matlab
  • ¥15 求lingo代码和思路
  • ¥15 公交车和无人机协同运输
  • ¥15 stm32代码移植没反应