Remember me Cookie best practice?

前端 未结 7 1626
感动是毒
感动是毒 2020-12-01 05:30

I read about many old questions about this argument, and I thought that the best practice is to set up a cookie with username,user_id and a random

7条回答
  •  心在旅途
    2020-12-01 06:20

    if your cookies are stolen anyone can log into your accounts. it's actually what firesheep does. the security lies in the random token. the whole system assumes cookies can't be stolen. the only other way to get in then is to guess the random token. if you make it long enough it should be nigh-impossible.

提交回复
热议问题