in reply to Implementing Cookies
The MD5 checksum allows me to verify (in a relatively secure manner) that the username stored in the cookie is the one I assigned to that cookie in the first place.
I keep track of "users browsing" by keeping a DB table with a username and datestamp, and each time they hit any of the CGIs (the sites I deal with are generally entirely generated from perl CGIs anyway), I update the datestamp, thus keeping track of who's on and who's not. I run a cronjob every half-hour to remove idlers.
Someone has already mentioned that IPs aren't a particularly affective way of tracking user sessions. I would agree with this, multiple cache proxies are often implemented at large ISPs, and this will make your IP address often times rather redundant.
JP,
-- Alexander Widdlemouse undid his bellybutton and his bum dropped off --
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: Implementing Cookies
by filmo (Scribe) on Nov 20, 2001 at 23:50 UTC |