douzhicong5965 2011-10-26 00:05
浏览 62

使用访问令牌验证用户

I use the common method of $_SESSION to authenticate logged in members; but it is recommended not to use $_SESSION['ID'] with simple numeric ID as it can be faked. I was thinking of assigning a temporary access token (similar to facebook), then store it in mysql row of the user upon successful login. Then, when a user want to edit his profile

if ($_SESSION[access_token] = ACCESS TOKEN (captured from mysql)) {edit profile}

The disadvantage of this system is that upon every login, we need a mysql write query; but I think the security is significantly high. And of course, I need to INDEX access token column.

Is it a practical method? Do I need to improve something in this scenario?

  • 写回答

0条回答 默认 最新

    报告相同问题?

    悬赏问题

    • ¥15 Vue3 大型图片数据拖动排序
    • ¥15 划分vlan后不通了
    • ¥15 GDI处理通道视频时总是带有白色锯齿
    • ¥20 用雷电模拟器安装百达屋apk一直闪退
    • ¥15 算能科技20240506咨询(拒绝大模型回答)
    • ¥15 自适应 AR 模型 参数估计Matlab程序
    • ¥100 角动量包络面如何用MATLAB绘制
    • ¥15 merge函数占用内存过大
    • ¥15 使用EMD去噪处理RML2016数据集时候的原理
    • ¥15 神经网络预测均方误差很小 但是图像上看着差别太大