PHP 4.0 Bug #8179 Updated: session.referer_check malfunctions
| From: | sniper@php.net | Date: | Fri, 15 Dec 2000 15:17:05 +0000 |
| Subject: | PHP 4.0 Bug #8179 Updated: session.referer_check malfunctions | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-41479@lists.php.net to get a copy of this message | ||
ID: 8179
Updated by: sniper
Reported By: snubber@seahat.com
Old-Status: Open
Status: Closed
Bug Type: *Session related
Assigned To:
Comments:
From http://www.php.net/manual/reg.session.php:
---------------------------------------------------------
session.referer_check contains the substring you want to
check each HTTP Referer for. If the Referer was sent by
the client and the substring was not found, the embedded
session id will be marked as invalid. Defaults to the
empty string
---------------------------------------------------------
--Jani
Previous Comments:
---------------------------------------------------------------------------
[2000-12-08 16:26:35] snubber@seahat.com
the session.referer_check option in the php.ini file seems to cause php to restart the session on
every page of the same site when enabled.
If you turn on the referer check, and enable 'warn me before accepting cookies' in
netscape you will see PHP setting a cookie for a new session every time session_start() is called.
---------------------------------------------------------------------------
Full Bug description available at: http://bugs.php.net/?id=8179