Alex Rivera | Logout

What should I store in cookies to implement "Remember me" during user login

Asked 2009-12-07T07:43:28.640
14

I have a login system in place for my website, the details of the user which are stored in the database are userid(unique for every user and identifier), email address(unique), display name(not unique), password and membersince.
Now what should I store in the cookies? I was thinking about storing just the userid in the cookie with an expiration date and then if the user revisits my website after signing up check for the cookie and log him in( which kind of doesn't look right to me) and destroy the cookie if he decides to log out.
*A little explanation would also be very helpful. Thanks

Edit
Report

2 Answers

1

PHP has built-in session management that does exactly what you're looking for:

http://us.php.net/manual/en/book.session.php

I wouldn't recommend storing the user_id in the cookie. Instead, you can generate a unique token and associate the token with users in your database, and check & regenerate the token on each request. Again, this is a bit redundant, because session management is already built into PHP.

answered 2009-12-07T07:46:07.480
-2

Simply add the cookie expires to 2 days or the number of days you want to remember the user and save the cookie.

answered 2009-12-07T07:51:44.360

Your Answer