E
E
exhang2019-02-06 11:15:13
PHP
exhang, 2019-02-06 11:15:13

How to secure sessions on a mobile site?

Went into a stupor. The site has an authorization, a basket. It seems that the site can be considered less secure, if the session id is stolen from the user, the site should check the useragent and IP address, and if they do not match what is in the database, then close the session in order to prevent data theft. With useragent it is more or less clear, but what to do with IP? If we go somewhere and look at the site, we reconnect from the mob. networks on wifi or just the connection breaks, the IP changes, then the session is essentially lost, but this is no longer user friendly. How to be?

Answer the question

In order to leave comments, you need to log in

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question