4 ms·
Sorry for the dumb question, but I see some negative comment about this link ... so what's the good approach to implement secure persistent login in a web appli
by mickeyben 16y ago
Sorry for the dumb question, but I see some negative comment about this link ... so what's the good approach to implement secure persistent login in a web application ?
- justincormack 16y agoFirst you probably want to make authentication stateless rather than having a server side database. Something like a cookie containing encrypt( salt + expiry + username) is normal and can be validated without a database access. Second you take your security advice from a professional not someone who does not seem to know what they are talking about.
- angelbob 16y agoIf you need to ask, I recommend starting with an existing implementation that has been vetted by security folks smarter than you or I. I use Devise, based on Warden, for Ruby on Rails. Depending on your platform, that may not work for you.
- mickeyben 16y agoAfter many years of Rails (and other frameworks), I know now that I NEED to review the code of plugins written by folks smarter than you or I. I don't count the times I had to remove plugins from my application. I use Warden and saw there was a rememberable strategy in Devise that I could use. I also read I can secure the cookies to be only send over SSL. I was hoping some further explanations on that since Devise doesn't seem to do it.
- angelbob 16y agoThat's true. And yes, devise doesn't do that by default. Basically, you'll want to have Devise (or better yet, all of Rails) set to only use secure cookies. Unfortunately, most Rails apps run without SSL, so that's not going to be the default any year soon. At this point, you really do have to pay money for a good SSL certificate, or self-sign and then people have to click through an ominous-looking dialog to use your site.