Knowledgebase

Authentication and Sessions Print

  • webdevelopment, password, domainrenewal, security, woocommerce, performance, guide, howto
  • 0

Establishing who someone is.

WHAT AUTHENTICATION IS

Establishing identity.

WHAT AUTHORISATION IS

Determining what they may do.

WHAT TO USE

Established libraries and framework facilities.

WHY

Password hashing, session handling and token issuance are easy to implement subtly wrong.

WHAT TO NEVER DO

Store passwords in a recoverable form Use general-purpose hashing for passwords Write your own scheme

WHAT TO USE FOR PASSWORDS

An algorithm designed for the purpose, which is deliberately slow.

WHAT SESSION APPROACHES EXIST

Server-side sessions, referenced by a cookie Tokens carried by the client

WHAT TO CONFIGURE ON COOKIES

Secure transmission only Inaccessible to scripts Restricted cross-site sending A sensible expiry

WHAT TO DO ON SIGN-IN

Regenerate the session identifier.

WHAT TO DO ON PASSWORD CHANGE

Invalidate other sessions.

WHAT TO IMPLEMENT

Rate limiting on authentication attempts A second factor, where warranted

WHAT TO CHECK ON EVERY PROTECTED ACTION

That the user is entitled to that specific record.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot