Jump to content

Is this the correct way?


newbtophp

Recommended Posts

Hi,

 

Is this the correct way to go by setting cookies for my login 'remember' functionality?, I've posted the relevant login and logout code.

 

Login:

 

<?php
session_start();

//some code...

if (isset($_POST['remember'])) {

$expire = time() + 1728000; // Expire in 20 days

$site_domain = 'phpfreaks.com'; //example

$_SESSION['username'] = $_POST['username']; //don't worry this has been validated 

$username = $_SESSION['username'];

//some sql query to fetch code..

$code = $row['code'];

setcookie('username', $username, $expire, NULL,  ".$site_domain", NULL, TRUE);

setcookie('code', $code, $expire, NULL, ".$site_domain", NULL, TRUE);

}
?>

 

Logout:

 

<?php
session_start();

if (isset($_COOKIE['username'])) {

$expire = time() - 1728000; // Expire in 20 days

$site_domain = 'phpfreaks.com'; //example

$username = $_SESSION['username'];

//some sql query to fetch code..

$code = $row['code'];

setcookie('username', $username, $expire, NULL, ".$site_domain", NULL, TRUE);

setcookie('code', $code, $expire, NULL, ".$site_domain", NULL, TRUE);

}

unset($_SESSION['username']);

$_SESSION = array();

session_destroy();
?>

 

Please tell me if it looks good to go and/or any improvements.

 

PS:

 

I want it accessible on all areas of the domain (including subdomains and paths etc.), and HTTP ONLY (so js can't access it) - I believe I've set the right parems?

Link to comment
https://forums.phpfreaks.com/topic/211068-is-this-the-correct-way/
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.