Answer the question
In order to leave comments, you need to log in
Authorization on secret cookies, is this a bad practice in my case?
Good day. There was a need to make a simple user account.
Approximate number of 100-200 per day. Is it so bad to check the login and password and give a secret, immutable cookie? So that the user with its presence would have access to the office, but without it. Inside, for example, store the login hash. To give out data on it in the office.
I've seen them do this in Flask sometimes.
I see no reason to pull a heavy solution for a simple task.
If it's not bad?
Answer the question
In order to leave comments, you need to log in
In general, this is not bad with some caveats:
1. Sessions cannot be revoked
2. Something changing and critical cannot be stored there, because
all previous cookies you set will be valid even if you set a new one
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question