RE: [PHP-DB] Passing values
| From: | Dean Hall | Date: | Mon, 21 Aug 2000 16:36:08 +0000 |
| Subject: | RE: [PHP-DB] Passing values | ||
| References: | 1 | Groups: | php.db |
| Request: | Send a blank email to php-db+get-2232@lists.php.net to get a copy of this message | ||
On Mon, 21 Aug 2000, Chad Day wrote:
> I always see this reply.. pass hidden form fields.. but users can download
> the html, modify it client-side, and send back false data.. so I don't think
> this is a very secure way of passing data between pages. What would work
> better (besides session variables?)?
>
Just a note: I've heard that if you propogate session variables
client-side with GET, they don't propogate in POSTs; you have to stick
them in hidden form tags. The good thing about the session ID is it
(hopefully) is cryptographically unique and cannot be spoofed.