...

View Full Version : user login verification question



gloosemo
10-20-2011, 02:27 AM
I've never worked with databases before.

Generally, is it better to GRANT each person registered to your site some basic privileges and when they log in connect to the database with their login/password, or else is it better to use the same login and password for each user using an account with broader database privileges (but not full privileges), and just verify users by querying a table using the login and password information they logged in with???

Which is more efficient?

Is there major problems with either situation?

Also, what is the general process for validating a users' login and password, with specifics if you can. Do you query a large table of different users looking for a login and password match??



Thanks, G

Old Pedant
10-20-2011, 11:54 PM
Most web-based apps use a single set of credentials and use program logic to control what is seen by the user. This allows the app to access parts of the database that you don't want the users to be able to see (e.g., the app keeps a log of visitors).



Do you query a large table of different users looking for a login and password match??
Yes. Whether or not you encrypt passwords (typically, using a one-way algorithm) depends on the sensitivity of the data.



EZ Archive Ads Plugin for vBulletin Copyright 2006 Computer Help Forum