dongwu4834 2019-04-14 13:55
浏览 48

假设https用于两者,PHP会话比ajax调用更安全吗?

I'm writing a login system for a web application. Currently I create a php session and generate a token stored in a PHP session variable before any HTML or other output. That token is read in JavaScript from the php session by a simple embedded PHP echo and stored briefly in a javascript variable. It is then sent in all ajax requests and if the token sent in the ajax request doesn't match the token stored in the PHP session, the ajax call is aborted. An alternative would be to make a ajax call DOMContentLoaded to a php script, generate the token, store a hash is mysql, and return the unhashed token via ajax response and store it in a JavaScript variable. On subsequent ajax calls within the same page, I could return a new token each time to be used in a subsequent ajax call.

My question is whether the storing the token primarily in the PHP Session but still reading it via php echo into a JavaScript variable is more secure than returning the token via ajax and storing it in a JavaScript variable. The ajax method has the advantage of allowing a new token to be generated and returned on each ajax call.

I have tried updating the token in the php session during an ajax call but client side code that uses PHP echo of the session variable into a JavaScript variable doesn't receive the new value created during the ajax call because the client page hasn't reloaded. This isn't a problem if the token is stored in mysql and returned to the client via ajax.

  • 写回答

0条回答 默认 最新

    报告相同问题?

    悬赏问题

    • ¥17 pro*C预编译“闪回查询”报错SCN不能识别
    • ¥15 微信会员卡接入微信支付商户号收款
    • ¥15 如何获取烟草零售终端数据
    • ¥15 数学建模招标中位数问题
    • ¥15 phython路径名过长报错 不知道什么问题
    • ¥15 深度学习中模型转换该怎么实现
    • ¥15 HLs设计手写数字识别程序编译通不过
    • ¥15 Stata外部命令安装问题求帮助!
    • ¥15 从键盘随机输入A-H中的一串字符串,用七段数码管方法进行绘制。提交代码及运行截图。
    • ¥15 TYPCE母转母,插入认方向