javascript - Can people modify/create cookies on my websites domain? -


i have website , making login system using cookies user can stay logged in, believe can't sessions. wanted know if malicious user create or modify existing cookies on domain. know can delete them, that's fine, can create or modify them?

anyone can control browser, like. can create, edit , delete cookies.

for reason, cookies should long , random (or @ least random-looking point of being indistinguishable random).

they should meaningful server, should able relate them user, not meaningful outside server. should long enough , complex enough guessing 1 statistically impossible.

your server should careful not make assumptions cookie values receives. instance, submit cookie 2,000 characters in - mustn't cause crash.


Comments

Popular posts from this blog

How has firefox/gecko HTML+CSS rendering changed in version 38? -

javascript - Complex json ng-repeat -

jquery - Cloning of rows and columns from the old table into the new with colSpan and rowSpan -