Please Critique my PHP authentication efforts

后端 未结 6 491
你的背包
你的背包 2021-02-01 09:42

After posting this a while back, I decided to create my own Registration / Authentication capability in PHP. I\'d love anyone to point out the flaws / opportunities for improve

6条回答
  •  失恋的感觉
    2021-02-01 10:08

    If I get the flow right, then if I know your username and site name, go to the site name and give you a cookie with the username (since sessions, after all, are saved as cookies), I'm in - no password needed? Isn't that a flaw?

提交回复
热议问题