How to prevent multiple authentication in a web application / website?

There is a site with a registered user area, all of them have their own user / pass.

The problem is that some of them are trying to share authentication information with others to help them finish the job.

There is no way to restrict by ip-address, because for each dynamic ip is provided.

What could be the best solution? store sessions in a database? how to recover if they do not exit the system properly?

thank

+3
source share
5 answers

-: session_save_handler, , (session_id char, session_data blob, session_user int or char). / , , DELETE , - , "" , , //, - , , , , - , / .

+1

- ilogin/, .

, - , , .

+1

Loïc Février , , .

, 2 , - /​​ , .

0

. , IP-, , ping DB X IP- IP-, , ..

IP-, , . ( ), , /. , , .

0

-

, . , .

a) , , : . → . → .

b) . , . → . → .

(IP-?) , . , reset . , . , - . - . 5 . , - , , .

0

Source: https://habr.com/ru/post/1766769/


All Articles