drb56625 2015-02-17 08:52
浏览 164
已采纳

在session_id()中存储userId

(I was looking some tips for php session security but in my total ignorance I miss lot of basic things. I'm doing a very basic web game without login but I need to store session)

If is safe store $_SESSION['logged_in'] = TRUE; ...

Is not safe, then, store userId in session_id like session_id(userId) when all players knows other users Id? If not, what is the diference?

  • 写回答

1条回答 默认 最新

  • dtyrxmoj20617 2015-02-17 09:11
    关注

    It is safe, not.

    But it depends on the context. Of course, it has nothing to do with $_COOKIE['logged_in']=true, which, for sure, is unsafe.

    But the following is unsafe too

     session_id($user_id);
     $_SESSION['logged_in']=true;
    

    Because session_id will be stored in a cookie, and this way you can forge another user_id.

    You have to remember that Session variables are stored on the server, and cookie in the browser. So if you consider your server as a self place, it is safe, as long as you can't forge your identification cookies to fake your session.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 #MATLAB仿真#车辆换道路径规划
  • ¥15 java 操作 elasticsearch 8.1 实现 索引的重建
  • ¥15 数据可视化Python
  • ¥15 要给毕业设计添加扫码登录的功能!!有偿
  • ¥15 kafka 分区副本增加会导致消息丢失或者不可用吗?
  • ¥15 微信公众号自制会员卡没有收款渠道啊
  • ¥100 Jenkins自动化部署—悬赏100元
  • ¥15 关于#python#的问题:求帮写python代码
  • ¥20 MATLAB画图图形出现上下震荡的线条
  • ¥15 关于#windows#的问题:怎么用WIN 11系统的电脑 克隆WIN NT3.51-4.0系统的硬盘