講師 Brad Traversy ( http://bit.ly/37qv5Ev )已經從事程式設計工作 12 年,教學工作近 5 年。 他是 Traversy Media 的所有者,這是一個成功的網頁應用程式開發 YouTube 頻道,專注於從 HTML5 到像 Angular 這樣的前端框架以及像 Node.js、 PHP 和 Python 這樣的伺服器端技術。
這門課 Brad Traversy 將教你為 Bootcamp Directory App 建立一個真實世界的後端
從這 12 小時的課程,你會學到
1. Bootcamp Directory App 的實戰後端 RESTful API
2. HTTP 基礎 (Req/Res Cycle, 狀態碼等)
3. 進階 Mongoose Queries (查詢)
4. JWT/Cookie 認證
5/ Express & Mongoose 中介軟體 (地理編碼、授權、錯誤處理等)
6. API 安全性 (NoSQL 注入,XSS 保護,速率限制)
7. API 文件和佈署
🔥 udemy 目前 NT360 特價中,請更新優惠折扣碼 ( http://bit.ly/2O0wbOm )
https://softnshare.com/nodejs-api-masterclass/
同時也有22部Youtube影片,追蹤數超過28萬的網紅ジェットダイスケ/JETDAISUKE,也在其Youtube影片中提到,パスワードを入力した瞬間から暗号化、クラウドに保管。 http://virusbuster.jp/pm/trial/trial5.htm ←ダウンロード ※この動画はWindowsストアアプリ版のレビューです。 お気に入りのウェブサイトに自動ログイン、IDとパスワードを毎回入力する手間は不要。無料...
「cookie php」的推薦目錄:
- 關於cookie php 在 軟體開發學習資訊分享 Facebook 的最佳貼文
- 關於cookie php 在 โปรแกรมเมอร์ไทย Thai programmer Facebook 的最佳解答
- 關於cookie php 在 iThome Security Facebook 的最讚貼文
- 關於cookie php 在 ジェットダイスケ/JETDAISUKE Youtube 的精選貼文
- 關於cookie php 在 吳老師教學部落格 Youtube 的精選貼文
- 關於cookie php 在 MosoGourmet 妄想グルメ Youtube 的最佳解答
- 關於cookie php 在 Setting Cookies & $_COOKIE super global in PHP in Hindi 的評價
cookie php 在 โปรแกรมเมอร์ไทย Thai programmer Facebook 的最佳解答
+++ access token คืออะไรใน facebook ++++
😋 ปกติ facebook เปิดให้เว็บ (รวมทั้งแอพ) ที่เราเขียนขึ้น
สามารถใช้ระบบ login ของ facebook ได้
ทำให้เว็บนั้นได้สิทธิเข้าถึงข้อมูลส่วนตัวของ user นั้นๆ บน facebook
....
Continue Reading+++ What is access token on Facebook ++++
😋 Facebook is usually open for web (including apps) that we write up.
Facebook login system can be used
Make that web access to user's personal information on Facebook.
.
And in many sites, we must have seen.
Just have an account on Facebook, you can log in.
No need to waste time. Fill out a new subscription.
:
In this post will quote
Using Facebook Login
Behind that success, Facebook will give away access token
So that any web can manage user login
:
Before talking about access token, let me go back to the age of 2534
When "Timberners-Lee" delivered the world's first website.
It's a common thing that human beings use to be.
:
❣ but my weaknesses.... is in the heart
Hey, it's not the weaknesses of the website.
Well it uses HTTP potocol
Which is stateless. Don't remember any status.
The meaning is that Server is very short of memory. Alzheimer's disease.
When it gets request from browser
I don't remember where it came from???
Who sent it, I can't remember anymore!!!!!
:
🤔 to solve this cuddle nha technically
He will give you a server to send session id (or session token)
Which session id is something we can't read and long
It will be sent to browser. Keep this in the cookie.
.
.. Wrong is not that cookie.. but cookies are text
Server will send session id to browser
Keep the value in cookies (keep text on browser side)
:
Programming time on server side
Like PHP when using session _ start ();
Will tell browser to collect session id in text photos such as
PHPSESSID=tqb4s5q7k25234eabbvs11dp02
(session id is a random code)
:
But if it's another language, it may be seen in other words.
E.g. JSSIONID (JAVA EE), PHPSESSID (PHP), and ASPSESSIONID (Microsoft ASP).
.
😉 Even here session id... may think it's a ID code.
:
From now on when users click on what on the web page
Browser will be kind.
Secretly sending this session id to server automatically
Make the server recover from Alzheimer's.
... I remember where the request sent this... yay yay
.
So if the request sent in
It has the same session id
It's considered the same friends.
(Computer vocabulary says these request is in the same SESSION)
.
What if it's not the same session id
It's considered that request is not the same people.
:
👉 Benefits of session id
Will be used in conjunction with login / logout mechanism
1) When user name XXX comes in, there will be a session id.
2) When another user name YY does login, there will be a session id as a different ID.
3) When both users do logout, it will expire session id.
:
Question if we went to wash all the cookies in browser what would happen?
- answer for session id will be gone.
- So who secretly login is holding this web? What is that... huhu
- I have to logout automatically for new login... So sad. Haha.
(server doesn't remember us anymore
Because browser doesn't send session id)
:
Session id sounds like good
😨 but using user / password to login will have disadvantage such as
1) Easy to hacker to sneak in session
To wear sesion id (Cross-Site Request Forgery: CSRF)
... Technically, let's not talk about it. Read it on the
2) It is a burden for server to remember the session id. What rights you have and remember other information of user etc.
3) If you want to give the same user, login different devices such as
Web is fine. Mobile phone is good... It will be more difficult. (I have to copy session)
4) and other disadvantage not mentioned
:
😘 but he has a technique to solve the way.
.
Well, use what's called "acces token"
To get access token
I have to login with user / password to exchange it.
... We have to stand in the cat before we get access token.
Then we can use it instead of login
.
Keep us from feeding user / password often
And each user will get access token. Different look alike.
When it's time for user to do logout, access token will expire immediately.
:
😙 Here access token may compare like a key
Or maybe you can see it as a ticket or a pass... It's up to the imagination.
Difference from session id is
1) access token will not be kept in cookies
2) access token will collect information that can be revealed.
e.g. user _ id, rights, expiration date
(Not a burden for server to remember these information)
:
If you use access token with login mechanism, you will see the advantages like
1) Prevent hacker from using session by Cross-Site Request Forgery (CSRF)
2) Can login from mobile phone and just use the same user.
Just giving away access token... It's like Facebook.
(Not stored in browser cookies)
3) The server can leave a hassle login / logout duty... Throw it to authenticate service outside.
4) Server doesn't need to take care of user information.
:
😀 Cut back to see login mechanism with facebook user / password
The concept is as shown in the photo that I posted. (as an example of php)
Simple summary
- user time login
- It will sneak a switch to Facebook to do login instead.
- Then Facebook will throw back access token to our web
- Then user will use it as a pass. No need to login again.
:
There are many types of access token of Facebook such as
-User Access Token
- App Access Token
- Page Access Token
-Client Token
Each type has different rights. I can't ask for deep.
:
👉 session id and access token all this story
It's a sweet, fragrant hacker. I like it very much.
If they can steal, they can wear a login user.
Then hacker will get all rights like user... done here
.
Except we logout
To make session id or access token expire
Then the hacker will be out of bogs.
:
In the user corner. Just login.
Don't mind access token behind the scenes
But if it's a #programmer, you need to be extra mindful.
Because even four feet know that the philosopher knows.
The biggest giant. Big brother like Facebook.
Still missed it. Let access token out so that it's a big news.
.
👌 So, programming
Let's be mindful about access token. Don't fall off.
Be safe from hakcker to the best
Good luck to all of you.
:
:
Written by Thai programmer thai programmer
:
+++++++++++++
Reference
1) https://developers.facebook.com/docs/php/howto/example_facebook_login?locale=th_TH
2) https://developers.facebook.com/docs/facebook-login/access-tokens?locale=th_THTranslated
cookie php 在 iThome Security Facebook 的最讚貼文
【8/16~8/22】一周資安新聞回顧
1⃣研究人員再揭PHP反序列化安全漏洞,恐使WordPress曝露遠端程式攻擊風險
2⃣繼Meltdown、Spectre後,主流處理器再爆新攻擊手法L1TF
3⃣16歲青少年駭入蘋果伺服器偷走90GB的資料
4⃣傳美國政府要求臉書解密Messenger協助辦案
5⃣鎖定金融領域的新惡意程式Marap現身
6⃣Avast:3.2萬個IoT伺服器在網路上門戶洞開
7⃣GDPR上線後,歐洲新聞網站的第三方Cookie數量減少二成
8⃣Chrome漏洞可能外洩使用者隱私資料
9⃣開源電子健康紀錄系統OpenEMR爆數個嚴重漏洞,病患隱私與系統安全拉警報
🔟研究:中國駭客以後門程式滲透美阿拉斯加州政府及企業網路
cookie php 在 ジェットダイスケ/JETDAISUKE Youtube 的精選貼文
パスワードを入力した瞬間から暗号化、クラウドに保管。
http://virusbuster.jp/pm/trial/trial5.htm ←ダウンロード
※この動画はWindowsストアアプリ版のレビューです。
お気に入りのウェブサイトに自動ログイン、IDとパスワードを毎回入力する手間は不要。無料版では5つまでのIDとパスワードを管理、6つ以上を管理したい場合でも月額150円(税込)で有償版を利用できます。「パスワードマネージャー」Windowsストアアプリ版ならWindows 8 のUIでも(※)。
※ ご利用にはトレンドマイクロアカウントが必要です。
人気声優の花澤香菜さんが歌う「パス☆マネ」主題歌とトレンドマイクロ「パスワードマネージャー」無料版は以下のURLよりダウンロードできます。
http://www.trendmicro.co.jp/pasumane/
映像:タンゲフィルムズ
楽曲制作協力:アニプレックス
※この動画は、Windows 8アプリレビューサイト「MADO-APP!(マドアプ)」のタイアップ記事用に作成したレビュー動画です。記事は以下のURLリンクにて
http://mado-app.com/3498 ←記事リンク:パスワードマネージャー使って大切なサイトのパスワードをクラウド管理してみた
関連ブログ記事:
大切なパスワードさえ憶えきれない私たちのために
http://gajetdaisuke.com/archives/13128_200000.php
cookie php 在 吳老師教學部落格 Youtube 的精選貼文
ASP.NET 3.5程式設計第9次上課
這次上課主要是用實例解說ASP.NET提供的重要物件:
Cookie、Session、Applaction,也提到Response+Request+Server物件,
以上六個物件與ASP、JSP、PHP的使用是相同的,所以若能掌握以上六個物件,
對於未來處理其他網頁呈式有很大的幫助。
最後也補充非常重要的觀念,就是如何存取文字檔案,
我覺得這部分的重要性不會低於資料庫的存取,
以往一般人在學習成式的時候,都會以資料庫存取為目標,
但資料庫的存取對一般人來說,真的有點複雜,
光了解資料庫就很花時間,但相對文字檔非常簡易,
只要記事本就能產生。若是簡單資料,建議用文字檔即可,
例如計數器的總數,存在 Applaction 伺服氣重開機就消失,
存在資料庫又有點麻煩,若存成文字檔就非常適合。
但要如何讀寫文字檔呢?
1.宣告+引用FSO物件(其實他就是DLL檔)。
2.用FSO的OpenTextFile方法開啟文字檔。
3.讀取檔案內的文字到字串變數中。
4.變數+1
5.寫回去文字檔案。
6.記憶體中請除FSO物件。
以上是FSO物件的使用流程。課程影音:
01cookies新增&讀取
02coolie多鍵
03sessiond登入&登出
04Applaction物件計數器&Session
05將計算器改成圖檔
06用FSO開啟文字檔案
-------------------------------------------
01cookies新增&讀取
02coolie多鍵
03sessiond登入&登出
04Applaction物件計數器&Session
05將計算器改成圖檔
06用FSO開啟文字檔案
公告:
此影音課程謹提供本班學員復習用,非學校必須提供課程服務,
是老師私下提供,勿再向外傳送,若非學員請勿加入論壇,敬請悉知。
吳老師教學網:
http://3cc.cc/10g
部落格:
http://terry55wu.blogspot.com/
論壇:
http://groups.google.com/group/itctcaspnet?hl=zh-TW
YOUTUBE:
http://www.youtube.com/view_play_list?p=CB9790A2D1F998E3
ASP.NET 3.5,吳清輝老師,文化大學,推廣部,人力加值,程式設計,WEB2.0,線上教學
cookie php 在 MosoGourmet 妄想グルメ Youtube 的最佳解答
コレって、名前は"クッキー"なんですね。。。ドーナツ分類かと思ってました。小さくなったローズネットクッキーが4個入ってます。普通の大きさだと食べきる最後がちょっとクドクテつらい時があるので、こりゃーちょーどええわ。
cookie php 在 Setting Cookies & $_COOKIE super global in PHP in Hindi 的美食出口停車場
... <看更多>