Re: sessions and trans-sid problem/question
| From: | Jean-Christian Imbeault | Date: | Fri, 22 Nov 2002 08:25:13 +0000 |
| Subject: | Re: sessions and trans-sid problem/question | ||
| References: | 1 2 3 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-125572@lists.php.net to get a copy of this message | ||
Ernest E Vogelsinger wrote:
Definetely yes.After reading Justin's post I realized that.
What I usually do (I also have session cookies switched off) is to send the user a session cookie when he logs in. This way I can use cookieless sessions, but when it comes to sensitive areas I can be sure that bookmarking or giving away the SID wouldn't automatically transfer the login session...I don't get what you mean here. Can you explain a bit more? Sounds like what I need but I don't understand. You say you have cookies switched off but send the user a cookie ... a contradiction.
I always recomment NOT using session.auto_start. It effectively disables making objects session-persistentI didn't know that but it doesn't matter as I don't do OO in PHP. Being also a Java programmer I can't wrap my brain around how PHP does pseudo-OO. Jc