dongpao1905 2015-07-12 16:42
浏览 70

无数据库访问的跨站点身份验证

I own 2 websites A and B. This means I can put any code on each of the websites and run it there. However, I can't access the database of the other website from one of the sites.

Recently, I needed a way to make a link on website A to website B but I needed the user to be automatically authenticated on website B when he clicks on the link if he was authenticated on website A.

So what I have done is the following :

  • Create a page on website A that redirects to a page on website B giving it as a parameter the username and id encrypted along with a passphrase (using the mcrypt library)
  • Check on website B using curl if the id belongs to the same user as the username and in this case accept the connection.

This works well. However, I feel like this is not really the way to go as it is not really secure. For now, those are toy websites so I don't really care.

Is there a better way to perform cross-site authentication ?

  • 写回答

2条回答 默认 最新

  • dst8922 2015-07-12 22:28
    关注

    You may want to look into Single Sign On (SSO) solutions. You can have your users log in via a social identity provider like Facebook or Google, or you can have your website issue the tokens itself.

    I'm not a PHP developer, so I can't help you with libraries or frameworks.

    评论

报告相同问题?

悬赏问题

  • ¥50 用易语言http 访问不了网页
  • ¥50 safari浏览器fetch提交数据后数据丢失问题
  • ¥15 matlab不知道怎么改,求解答!!
  • ¥15 永磁直线电机的电流环pi调不出来
  • ¥15 用stata实现聚类的代码
  • ¥15 请问paddlehub能支持移动端开发吗?在Android studio上该如何部署?
  • ¥20 docker里部署springboot项目,访问不到扬声器
  • ¥15 netty整合springboot之后自动重连失效
  • ¥15 悬赏!微信开发者工具报错,求帮改
  • ¥20 wireshark抓不到vlan