Hi,
I would do;
1) User logs in, and an entry is added to a login table (alongside their sessionID)
2) The sessionID is then saved to the cookie,alongside their IP address (i.e "e554f4354554-255.232.32.32"), to give uniqueness.
3) When they access pages, you can look at the cookie.. and confirm the sessionID exists, as is indeed valid.
If someone just happened to "copy" the cookie over; although the session ID may work, the IP address would be different... and thus you could confirm this wasn't the person who logged in first, and thus reject them =)
Hope that helps.
Cheers
Andy (mod)
andy@ultranerds.co.uk
IMPORTANT: I've now moved to ultranerds.co.uk, and the .com will no longer work! Want to give me something back for my help? Please see my
Amazon Wish List GLinks ULTRA Package (plugins total "value" $3,325 & rising, for just $350)| GLinks ULTRA Package PRO (plugins total "value" $5,625 & rising, for just $500) Support Forum | Links SQL Plugins | DMOZ Dumps | UltraNerds | ULTRAGLobals Plugin |
Pre-Made Template Sets |
FREE GLinks Plugins! Compare our different Plugin packages *new* Free CSS Templates