Bug #18563 Updated: Problem with Session ID as hidden POST Variable
| From: | sniper@php.net | Date: | Thu, 25 Jul 2002 12:10:49 +0000 |
| Subject: | Bug #18563 Updated: Problem with Session ID as hidden POST Variable | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-15176@lists.php.net to get a copy of this message | ||
ID: 18563
Updated by: sniper@php.net
Reported By: bruno.baketaric@wob.ag
-Status: Open
+Status: Won't fix
Bug Type: Feature/Change Request
Operating System: Linux
PHP Version: 4.2.1
New Comment:
Either add it manually or change the form=fakeentry to form=action in
php.ini directive url_rewriter.tags
Previous Comments:
------------------------------------------------------------------------
[2002-07-25 08:02:36] bruno.baketaric@wob.ag
Posting the (URL-based) session variable as hidden form value can lead
into a problem if the user hits the Browsers RELOAD-button on the
following page (usually some kind of "thank you"-page). In this case
the session id is gone.
Sure, this is no Problem if you use cookies - but well, I just hate
them and quite often I even must not (!) use them.
Solution: make the session id be added to the action attribute of the
form (again) when PHP is working in "trans-sid"-mode.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=18563&edit=1