Is this a reasonable way to implement 'remember me' functionality

前端 未结 3 1397
执念已碎
执念已碎 2020-12-31 17:49

If a user logs into the site, and says \'remember me\', we get the unique identifier for the user, encrypt this with RijndaelManaged with a keysize of 256 and place this in

3条回答
  •  夕颜
    夕颜 (楼主)
    2020-12-31 18:26

    How important is the information that is being remembered? If it's not going to be anything very personal or important, just put a GUID in the cookie.

    Including the IP address in the calculation is probably a bad idea, as it would make users using public networks be instantly forgotten.

    Using brute force to find GUIDs is ridiculous, as there are 2128 possibilities.

提交回复
热议问题