Re: PHP 4.0 Bug #4495 Updated: trans-sid failure on forms

From: Date: Fri, 19 May 2000 19:47:45 +0000
Subject: Re: PHP 4.0 Bug #4495 Updated: trans-sid failure on forms
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-18987@lists.php.net to get a copy of this message
> All, I did end updoing the hidden form field thing. But my thoughts are > the whole point of trans-sid is to be just that, transparent. And by having > to code in a hidden form field with the SID, then its not completely > transparent... Also answer me this, why shouldn't it append the SID to a > form post? > Danny: That was simply a statement of opinion from me, as I interpret the RFC (2068): The GET method means retrieve whatever information (in the form of an entity) is identified by the Request-URI. If the Request-URI refers to a data-producing process, it is the produced data which shall be returned as the entity in the response and not the source text of the process, unless that text happens to be the output of the process. Get accepts relativeURI = net_path | abs_path | rel_path rel_path = [ path ] [ ";" params ] [ "?" query ] The POST method is used to request that the destination server accept the entity enclosed in the request as a new subordinate of the resource identified by the Request-URI in the Request-Line. Post accepts absoluteURI = scheme ":" *( uchar | reserved ) scheme = 1*( ALPHA | DIGIT | "+" | "-" | "." ) Note that POST does not allow a ? in its Request-Line.... I could be misreading this, though. Here's an idea: page1.php <?php Set-Cookie("sess_id", $SID); Header("Location: /page2.php"); ?> page2.php <?php echo "<form method=\"" . ( ($test) ? "POST" : "GET")... ?> This will let you use POST where URL rewriting is not neccesary, due to use of cookies... > Thanks! > Danny >

« previous php.dev (#18987) next »