Re: trans-sid warning?
| From: | Marko Karppinen | Date: | Tue, 20 Aug 2002 14:09:52 +0000 |
| Subject: | Re: trans-sid warning? | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-87153@lists.php.net to get a copy of this message | ||
Xavier:
So you wish to prevent your users from forging GET/POST values and are willing to rely on client-side cookies ? How is that any safer ? On Tue, 2002-08-20 at 09:18, Marko Karppinen wrote:Who said I was using cookies? I'm not. I asked if session.use_only_cookies worked (ie. prevented supplying the sid in GET/POST parameters) without actually setting cookies on. mkBy the way, does session.use_only_cookies work with session.use_cookies=off?