3 ms·
You're welcome! Forgive me if this is obvious but there is one corner case worth mentioning with the Fu Cookie approach. The Fu Cookie authenticator expires.
by mdakin 19y ago
You're welcome!
Forgive me if this is obvious but there is one corner case worth mentioning with the Fu Cookie approach. The Fu Cookie authenticator expires. Be sure to consider what happens if this expiration happens in the middle of some complex user-operation. Ideally you will save the user's state, reauthenticate and then automatically resume the interrupted operation. It is possible to do this all using cookies or hidden form fields rather than maintaining a data-structure (or closure ;) ) on the server-side. If you do use cookies/form fields consider HMACing the operation-state data in the same manner that you HMAC the Fu Cookie authenticator.