token - Laravel "remember_token" -
is safe use remember_token
in users table authenticating user application?
what purpose of token? currently, i'm using in forms check whether user logged in - if token not present, show login screen. each time user logs out, token regenerated.
no it's not supposed used authenticate, it's used framework against "remember me" cookie hijacking. value refreshed on login , logout, if cookie hijacked malicous person, logging out making hijacked cookie useless since doesn't match anymore.
Comments
Post a Comment