Storing login information in Cookies

前端 未结 7 1555
不思量自难忘°
不思量自难忘° 2021-02-05 22:06

I want to save user\'s authentication information in browser cookie for persistent login. As they say, its never safe to store any secret info (such as password) in cookie, but

7条回答
  •  面向向阳花
    2021-02-05 22:43

    you don't have so much of a choice when it comes to store user info on client side...

    You can try to make some encryption using the client IP as the key. This way even if the cookie is copied to the hacker computer and if he doesn't notice that the IP is the key of the encryption you'll have some descent protection of user's info.

    Facebook is doing something this way, proof is everytime you try to log in from another connection point you have to go throught the user verification system...

    So look for some reversible encryption and this should make your day ;)

提交回复
热议问题