Re: extract($_POST)

From: Date: Wed, 23 Oct 2002 14:23:08 +0000
Subject: Re: extract($_POST)
References: 1 2 3  Groups: php.general 
Request: Send a blank email to php-general+get-121100@lists.php.net to get a copy of this message
You are correct. I'd never considered using the URL due to lack of security; that is, a user can add URL parameters that hijack the session and make it do bad things, or expose data that you (the developer) do not want exposed. ----- Original Message ----- From: "@ Edwin" <copperwalls@hotmail.com> To: "Rick Emery" <remery@emeryloftus.com> Cc: <ed@home.homes2see.com>; <php-general@lists.php.net> Sent: Wednesday, October 23, 2002 9:19 AM Subject: Re: [PHP] extract($_POST) Hello, I don't think that's what the manual says: ----------> Passing the Session ID There are two methods to propagate a session id: * Cookies * URL parameter The session module supports both methods. Cookies are optimal, but since they are not reliable (clients are not bound to accept them), we cannot rely on them. The second method embeds the session id directly into URLs. http://www.php.net/manual/en/ref.session.php - E On Wednesday, October 23, 2002 10:49 PM "Rick Emery" <remery@emeryloftus.com> wrote: > Ed, > > Elsewhere, you stated that you will not use cookies, because one-third > of your constituency will have cookies turned off. yet, you will use > sessions. Sessions processing depends on cookies being on. ..[snip]...

« previous php.general (#121100) next »