php - login with cookies and sessions -


how can make cookies safe

i want make login sessions , cookies try make

this code

<?php $my_username  =isset($_post['username'])   ? make_it_safe($_post['username'])   :null; $my_userpass  =isset($_post['userpass'])   ? make_it_safe($_post['userpass'])   :null; $saveinfo    =isset($_post['save_info'])  ? make_it_safe($_post['save_info'])  :null;  if(empty($my_username)){   echo "<div class='alert alert-error'>insert username</div>"; }else if(empty($my_userpass)){   echo "<div class='alert alert-error'>insert userpass</div>"; }else { $my_userpass = sha1($my_userpass) ;  $select = $mysqli->query("select * members username='$my_username' , userpass='$my_userpass' limit 1"); $num = $select->num_rows; if($num){ $rows = $select->fetch_array(mysql_assoc);  $id       = $rows ['id']; $username = $rows ['username']; $userpass = $rows ['userpass']; if($username == $my_username && $userpass == $my_userpass){  $_session['id'] = $id ; $_session['username'] = $username ;  if ($saveinfo == 'on'){ setcookie("id",$_session['id'],time()+2592000); setcookie("username",$_session['username'],time()+2592000); } header("location: home.php"); }  }else{ echo "error"; } ?> 

is right way in login cookies , safe?


Comments

Popular posts from this blog

android - Get AccessToken using signpost OAuth without opening a browser (Two legged Oauth) -

org.mockito.exceptions.misusing.InvalidUseOfMatchersException: mockito -

google shop client API returns 400 bad request error while adding an item -