Re: Re: trans-sid warning?

From: Date: Wed, 14 Aug 2002 10:08:04 +0000
Subject: Re: Re: trans-sid warning?
References: 1 2 3 4 5 6  Groups: php.dev 
Request: Send a blank email to php-dev+get-86808@lists.php.net to get a copy of this message
Dan Hardiker wrote:
How you can tell a cookie to be stored in RAM rather than on the HDD, Im not sure ... but that might mean I need to brush up.
do not set a lifetime and it won't be stored on disk and live in browser ram until browser is terminated has been so ever since netscape came up with cookies
Now this is where the code dev needs an IQ above 3. *Use IP and Browser String authentication* eg: Load up the session ID given, check the ip and browser string (possibly even referrer) and if they dont match, squeel.
IPs might change due tu proxy farms or DHCP leases expiring and getting renewed with a different IP -- Hartmut Holzgraefe hartmut@six.de http://www.six.de/ +49-711-99091-77

« previous php.dev (#86808) next »