4 ms·
I agree don't use IP as a part of token - it will require user to re-authenticate very often. And don't forget about the salt. Store password something like SH
by k0ban 16y ago
I agree don't use IP as a part of token - it will require user to re-authenticate very often.
And don't forget about the salt. Store password something like SHA-1(MD5(password)+password)