Well, I looked at them and a few others--
Just another thing...None of them had any secure ways to continue the session...
I could do it w/o a cookie but then if the user doesn't close the page, they'll stay logged in...
If I get a cookie with a self delete time of something like 30minutes since last access, then, it would be much better if the user forgets to log out?
EDIT: Can someone give me a link where it explains the creation of the cookie and how to check if the cookie is valid as a header on the beginning of each secure page...
And, if the username is stored in the cookie, then someone could easily edit their cookie to have to username of someone they think is also logged in? So I would have to...put the ip address of the login and it would check if the ip address in the cookie and the ip address accessing the secure site match?? Well, actually now that I think about it again the cookie will have a random session id in it so it would be highly unlikely for an account to be hijacked..
Thanks 😉