Yup, that would work, except now, if you need to change the key because of whatever reason (employee leaves, server is compromised et al), there is a bit of a mess to work out. | [reply] |
Pretty simple as they are just session data holders, just change the secret string that mods the hash if an employee leaves. The cgi should be written well enough to deal with bad/missing data cookies and give the user another chance to provide it. As far as the server being compromised -- lol you have more to worry about then the cookie hash =) the hacker cacn do far more damage with other means available to them at that point.
-Waswas
| [reply] |