Re: RE:[PHP] session_register vs. $_SESSION superglobal
| From: | Pushpinder Singh | Date: | Tue, 23 Mar 2004 16:14:19 +0000 |
| Subject: | Re: RE:[PHP] session_register vs. $_SESSION superglobal | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-181346@lists.php.net to get a copy of this message | ||
I am using PHP with register_globals ON... since I don't have access to the host environment.
The way I use sessions is:
session_start();
........ do some database connection and checking here.....
if (condition is met) {
$_SESSION['valid_user'] = $_POST['login'];
}
Is this approach safe ?? Pl let me know. Also I use if (isset($_SESSION['valid_user'] ) ) to check if the user is logged in on secure pages.
Please comment.
Thanks in advance
Pushpinder Singh
___________________
Web Dev
On Tuesday, March 23, 2004, at 10:38 AM, Andy B wrote:
first $_SESSION works like this: session_start(); $_session[user]=$_POST[user];//if using register_globals=off $_SESSION[user]=$user;//if register_globals=on..unsafe though