Re: Sessions w/o cookies and the "Back" button
| From: | Andreas Pour | Date: | Tue, 10 Oct 2000 15:43:08 +0000 |
| Subject: | Re: Sessions w/o cookies and the "Back" button | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-19368@lists.php.net to get a copy of this message | ||
"Boget, Chris" wrote:
>
> > Something you might try is redirecting the user to a
> > session-start page (which could be a splash page) with
> > a META-REFRESH tag of 1 second which has the
> > session id in the refresh tag if a user hits your site w/out
> > a session id.
>
> So my index page would basically set the session. Ok. But
> what if someone uses the back button to go back to this
> page. The problem I am experiencing will still occur...
Well, the nice thing with this approach is, you can embed the SID in the
url for the index page (since you are redirecting to that page).
Actually, if you don't mind the ugly SID in the URL, you can skip the
redirection to the index page and just redirect to the same page with an
SID appended to the URL. I.e., if someone hits your site with no
session ID, just do a redirect to the same page (including query) and
append the SID to it. That way if someone hits back and the page is
reloaded, the SID will still be in the URL being requested from your
server.
>
> > (I don't recommend 0 seconds for a refresh tag b/c it
> > effectively disables the back button to get past your site).
It means don't use '<META HTTP-EQUIV="Refresh" CONTENT="0; URL=some
other page">'; try it with a test page and then try to "back" out past
that page and you will see how annoying it is.
Ciao,
Andreas Pour
http://www.kde.com/ : Everything KDE
http://apps.kde.com/: The Latest in KDE Applications