3

This question Is a result of various questions I had today about cookies.

As you know it's not save to handle the login process with cookies.

But how can I set a cookie when I am logged in and to be automatically loggedon when I restart my browser?

If I redirect based on the existense of the cookie this is dangerous as someone else could just create a cookie. So what's the way to deal with this?

sanders
  • 9,976
  • 25
  • 81
  • 123

1 Answers1

5

Yes, an auto-login cookie does present a vulnerability, but you can mitigate some of these with various techniques, such as ensuring a cookie value can only be used once.

For more details, take a look at

And see these other fine StackOverflow answers

Community
  • 1
  • 1
Paul Dixon
  • 277,937
  • 48
  • 303
  • 335