...

View Full Version : Values stored in $_SESSION / security



themis
08-05-2007, 12:38 PM
I 've created a table named "users" in a database which includes several fields (id, username, password and level are the important ones) and I was wondering which of these 4 values I should store in $_SESSION. For example, if I store the level of a user that visits my website and he change that value after editing the cookie I send him, could he gain privileges that he shouldn 't have? Would a solution to that problem be confirming the data stored in $_SESSION with those in the database? And if yes, is this the aproppriate way of solving that problem? Thnx in advance.

JordanW
08-05-2007, 02:21 PM
As far as I am aware you cannot forge a session or modify it externally. So generally the user level stored in the session would always be correct, but if you definitely want to be secure then checking the session variable with the database would be fine.


~Jordan



EZ Archive Ads Plugin for vBulletin Copyright 2006 Computer Help Forum