⭐ in reply to Cookie based authentication: Is it secure?
If I logged in to your site from a public terminal and left the browser open, anyone else could potentially use my cookie.
For some applications, this is enough security. For others, you might save a timestamp of the user's last access and require reauthentication if X minutes/hours/days have passed since the last transaction.
In general, if you don't store too much information in a cookie and if you realize the implications of what I've said above, this is a decent method of saving state.
|
---|