Re: Sessions w/o cookies and the "Back" button
| From: | Andreas Pour | Date: | Tue, 10 Oct 2000 14:22:21 +0000 |
| Subject: | Re: Sessions w/o cookies and the "Back" button | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-19351@lists.php.net to get a copy of this message | ||
"Boget, Chris" wrote:
>
> > If a user's browser does not accept cookies, if that
> > user presses the back button (particularly to the
> > page that initially started the session), a new session
> > is started and all the previous session information
> > is lost.
> > Is there any way that I can prevent this short of
> > 'disabling' the use of "Back" button to go to that
> > page?
> > Any insight would be very appreciated!
>
> Anyone?
I think the answer is "no" if you want reliability. You can try keying
off the IP number, but that's ineffective for people using proxies or
dynamic IPs.
Something you might try is redirecting the user to a session-start page
(which could be a splash page) with a META-REFRESH tag of 1 second which
has the session id in the refresh tag if a user hits your site w/out a
session id. (I don't recommend 0 seconds for a refresh tag b/c it
effectively disables the back button to get past your site and that --
along with popup windows when you leave a site -- is enough to put the
site on my blacklist).
Ciao,
Andreas Pour
http://www.kde.com/ : Everything KDE
http://apps.kde.com/: The Latest in KDE Applications