Bug #18563 Updated: Problem with Session ID as hidden POST Variable

From: Date: Thu, 25 Jul 2002 12:10:49 +0000
Subject: Bug #18563 Updated: Problem with Session ID as hidden POST Variable
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-15176@lists.php.net to get a copy of this message
ID: 18563 Updated by: sniper@php.net Reported By: bruno.baketaric@wob.ag -Status: Open +Status: Won't fix Bug Type: Feature/Change Request Operating System: Linux PHP Version: 4.2.1 New Comment: Either add it manually or change the form=fakeentry to form=action in php.ini directive url_rewriter.tags Previous Comments: ------------------------------------------------------------------------ [2002-07-25 08:02:36] bruno.baketaric@wob.ag Posting the (URL-based) session variable as hidden form value can lead into a problem if the user hits the Browsers RELOAD-button on the following page (usually some kind of "thank you"-page). In this case the session id is gone. Sure, this is no Problem if you use cookies - but well, I just hate them and quite often I even must not (!) use them. Solution: make the session id be added to the action attribute of the form (again) when PHP is working in "trans-sid"-mode. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=18563&edit=1

« previous php.bugs (#15176) next »