Re: session security
| From: | Sascha Schumann | Date: | Tue, 11 Feb 2003 05:08:44 +0000 |
| Subject: | Re: session security | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-94145@lists.php.net to get a copy of this message | ||
> Can anyone point me to a possible solution for this?
1. Use SSL.
2. Throw away an existing session id, if a user authenticated
successfully (e.g. destroy the old session, and copy the
data into a new one).
3. Provide a logout button which destroys the session.
- Sascha