Posted By Sara on 07 Mar 2007 7:56 AM I miss not having to sign in every time I come to the forums. Is there any way to alter the log-in stuff so that I can stay logged in indefinitely, if I want, on one computer? This feature is coming back, There are a few security issues that I need to resolve - because the login is now tied to everything on the site - including purchases, it is important to protect user accounts more carefully; Login cookies are *extremely* easy to hack.
I've designed a system that will define three levels of login - the first of which can be remembered and will allow access to things like forums, etc... the second will keep a session that expires after not visiting a Skydive Secure site for longer than 20 minutes, this will protect personal financial data, the third will require a second password - and will only protect administrative functions.
I want to get phase 1 of Tandem reservations and Gift Certificates out of beta testing and onto the live site before I go back and fix up Skydive Secure's login model. You may see persistant logins as quickly as a few weeks from now.
|