【发布时间】:2020-07-08 13:34:07
【问题描述】:
我正在使用 Python 微服务 (falcon) 和 postgres 数据库在 VueJS 中构建一个小型用户平台。我需要一些帮助来理解生成会话 id 的正确流程,以及是否有任何关于如何改进这种方法的建议以及我应该考虑的其他方法。
目前,这些是用于身份验证的步骤。
1)user sends username/password
2)if user exists in db, then I am generating a session_id (example: c8c83009-55b6-442a-b934-c6629aa20ac6)
the api layer stores this session_id in redis, and I would plan to pull in some relevant session data like email address, name, address, billing account id for stripe, etc.
3)I return the session_id as a cookie (set-cookie). Then on future requests for each page, the browser is passing the api the cookie (with session_id) with this session id.
这是正确的方法吗? session_id 应该是如上所示的“纯文本”格式,还是我需要 md5 或对其应用某种类型的散列?对于像 redis 这样的缓存存储,我应该将 session_id 保存为键,还是最好使用电子邮件地址,但将 session_id 保留为值之一。这是发出 session_id 的典型方法,还是应该有一些额外的东西与 session_id 一起,以防有人获得 session_id?
只是想看看人们如何处理身份验证和授权会话,如果您有任何您认为有用的好资源,请分享!
【问题讨论】:
标签: python python-3.x authentication session