dpgu5074 2012-06-18 03:56
浏览 65
已采纳

PHP用户身份验证使用数据库和IP地址?

I have been considering the problems arising with user authentication, using sessions/cookies and the security risks that come up with session hijacking. I understand that using a secure https:// is the most effective method, as well as regenerate_session_id() and using a random string for validation (amongst numerous additional procedures).

My question is this: is there a possibility to incorporate a method that forgoes sessions and cookies, and uses just database held variables?

Here is how I would set it up:

-Have a column in the user table that can hold an IP address, and one that would be a Boolean.

-When the user 'logs in', set the current IP address of the user into the database, and sets the Boolean value to false (if the user doesn't want to be 'remembered') or true (if they do).

-On page load, it checks the current IP address with the one stored in the user database. If it matches, the user is considered valid.

-On window close, the script would then clear those values and the user would be 'logged out'.

-If the user wanted to 'stay logged in' (which I know is a huge security risk) then a toggle (the Boolean value) would simply deactivate the log out script and the IP address would stay stored for the user.

What would be the fallbacks to such a method? Is it even possible?

  • 写回答

3条回答 默认 最新

  • dongluanban3536 2012-06-18 04:00
    关注

    IP addresses are simply not an accurate and reliable way to uniquely identify a user. The IP may change during the session, and more than one user agent may be using the same outbound IP.

    Sorry :-)

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(2条)

报告相同问题?

悬赏问题

  • ¥15 winform的chart曲线生成时有凸起
  • ¥15 msix packaging tool打包问题
  • ¥15 finalshell节点的搭建代码和那个端口代码教程
  • ¥15 用hfss做微带贴片阵列天线的时候分析设置有问题
  • ¥15 Centos / PETSc / PETGEM
  • ¥15 centos7.9 IPv6端口telnet和端口监控问题
  • ¥20 完全没有学习过GAN,看了CSDN的一篇文章,里面有代码但是完全不知道如何操作
  • ¥15 使用ue5插件narrative时如何切换关卡也保存叙事任务记录
  • ¥20 海浪数据 南海地区海况数据,波浪数据
  • ¥20 软件测试决策法疑问求解答