3.5 Authentication

In this lesson, I cover authentication: how PHP handles session data, how to store session data and encrypt it, and how to use Redis as a session handler instead of the file system.

I’ll also show you how to make modifications to session cookies in order to prevent JavaScript manipulation of cookies, how to add entropy to the cookie to prevent a brute-force attack, and how to restrict cookies so that they are transmitted only over secure connections.

