RE: [PHP-DB] Passing values

From: Date: Mon, 21 Aug 2000 16:36:08 +0000
Subject: RE: [PHP-DB] Passing values
References: 1  Groups: php.db 
Request: Send a blank email to php-db+get-2232@lists.php.net to get a copy of this message
On Mon, 21 Aug 2000, Chad Day wrote: > I always see this reply.. pass hidden form fields.. but users can download > the html, modify it client-side, and send back false data.. so I don't think > this is a very secure way of passing data between pages. What would work > better (besides session variables?)? > Just a note: I've heard that if you propogate session variables client-side with GET, they don't propogate in POSTs; you have to stick them in hidden form tags. The good thing about the session ID is it (hopefully) is cryptographically unique and cannot be spoofed.

« previous php.db (#2232) next »