Answer the question
In order to leave comments, you need to log in
Authorization in the web application. Ready algorithm?
Hello. I ask for advice.
My task is to develop an algorithm by which any registered user of a web application can have access to a resource at a time from only one device. I threw an algorithm, tell me how to simplify it, or maybe everything is done differently at all.
The algorithm works through cookies, so it was necessary to think over a protection mechanism for the theft (and substitution) of cookies.
The algorithm itself:
Authorization in the web application:
Answer the question
In order to leave comments, you need to log in
a lot of text
in the cookie, you sew up the device ID,
only a cookie with a different ID arrives - logout for the first cookie
, and on the server, build a security matrix there and all that (if necessary, of course)
theft protection mechanismis called httpS
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question