Re: session security

From: Date: Tue, 11 Feb 2003 05:08:44 +0000
Subject: Re: session security
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-94145@lists.php.net to get a copy of this message
> Can anyone point me to a possible solution for this? 1. Use SSL. 2. Throw away an existing session id, if a user authenticated successfully (e.g. destroy the old session, and copy the data into a new one). 3. Provide a logout button which destroys the session. - Sascha

« previous php.dev (#94145) next »