Jump to content

Is it secure to use $_SESSION in a login script?


JJohnsenDK

Recommended Posts

Hey

 

Im trying to make my own login script, which works, but im afarid that the security is at the lowest.

 

When a user logs in a store the user_id in $_SESSION['user'], then i use that session variable to see

if the user have logged on.

 

For example

 

if(isset($_SESSION['user'])){

  echo "Welcome";

}

 

To me it seems that this is to simple to be secure. What do you guys thing?

that's pretty much what i do.

if it's just a membership system for a site, you should be fine with that. if there's money involved, you'll want a secure server. You might want to think about htaccess... but read that article above. You can never be too careful, but like Einstein said: "everything should be made as simple as possible - but no simpler".

 

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.