Re: HREF and variables
| From: | James Lyon | Date: | Tue, 30 May 2000 11:43:12 +0000 |
| Subject: | Re: HREF and variables | ||
| References: | 1 | Groups: | php.db php.general |
| Request: | Send a blank email to php-db+get-97@lists.php.net to get a copy of this message | ||
> Is there a way to pass variables via <A HREF> without the variable values
> being visible in the browser. I use a hidden type in forms that transfers
> them OK but statements such as:
>
> echo "[ <a href='members_query_form.phtml?DB=$DB&TA=$TA'>MEMBER
> SEARCH</a> ]";
>
> show the database and table names to the user which I would like to avoid.
You can POST variables, but a hacker can still find / mess with these.
Try sessions in PHP4 or store your information in a database in PHP3.
In PHP3, I use MySQL and pass only a single unique ID which I look up in the
database for everything I want. The user can't have any clue what the number
14987 means, because it's random but I can use it to track a single "session"
throughout my scripts.