Cookie加密

时间:2016-05-25 10:38:15

标签: php cookies encryption

所以,这有效,但我担心跨站点请求伪造,这是否足以防止它出现?也许还有更好的方法吗?

$userCookie = password_hash($_GET['username'], PASSWORD_DEFAULT);

    if(isset($_GET['remeberMe'])){
        $year = time() + 31536000;
        setcookie('remember_me', $userCookie, $year);

        if($_GET['remeberMe']) {
        setcookie('remember_me', $userCookie, $year);
        }
        elseif(!$_GET['remeberMe']) {
            if(isset($_COOKIE['remember_me'])) {
                $past = time() - 100;
                setcookie(remember_me, gone, $past);
            }
        }
    }

0 个答案:

没有答案