Bug #18563: Problem with Session ID as hidden POST Variable
| From: | bruno dot baketaric at wob dot ag | Date: | Thu, 25 Jul 2002 12:02:36 +0000 |
| Subject: | Bug #18563: Problem with Session ID as hidden POST Variable | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-15172@lists.php.net to get a copy of this message | ||
From: bruno.baketaric@wob.ag
Operating system: Linux
PHP version: 4.2.1
PHP Bug Type: Feature/Change Request
Bug description: Problem with Session ID as hidden POST Variable
Posting the (URL-based) session variable as hidden form value can lead into
a problem if the user hits the Browsers RELOAD-button on the following
page (usually some kind of "thank you"-page). In this case the session id
is gone.
Sure, this is no Problem if you use cookies - but well, I just hate them
and quite often I even must not (!) use them.
Solution: make the session id be added to the action attribute of the form
(again) when PHP is working in "trans-sid"-mode.
--
Edit bug report at http://bugs.php.net/?id=18563&edit=1
--
Fixed in CVS: http://bugs.php.net/fix.php?id=18563&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=18563&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=18563&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=18563&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=18563&r=support
Expected behavior: http://bugs.php.net/fix.php?id=18563&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=18563&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=18563&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=18563&r=globals