Re: Sessions w/o cookies and the "Back" button

From: Date: Tue, 10 Oct 2000 17:01:49 +0000
Subject: Re: Sessions w/o cookies and the "Back" button
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-19387@lists.php.net to get a copy of this message
Hi, It seems you do not understand how browsers handle redirction. You cannot hit a "back" button to a page using redirection -- it is not in the history. So if someone goes to: http://www.mysite.com/somewhere/page.php and you immediately redirect them (using 'header(Location .. . .)') to: http://www.mysite.com/somewhere/page.php?SID=blahblahblah then only the latter will be in the browser's history, not the former. Now of course if they leave your site altogether and come back (or if they use an off-site link to enter your site during their session) the session will be lost, nothing can be done about that if they don't use cookies. Ciao, Andreas Pour http://www.kde.com/ : Everything KDE http://apps.kde.com/: The Latest in KDE Applications "Boget, Chris" wrote: > > > Why not use your index page to start the session and register > > any variables needed then, and then use a header("Location ... > > to send them to a new page where they actually see stuff? > > This is the suggestion that Andreas made. And that is all well > and good. But if, for whatever god knows reason, a user click > the back button all the way to that page (like if they were trying > to get back and click it one too many times), then it will hit the > page that starts the session, registers the variable, etc., etc. yadda > yadda and all their previous session information is _lost_. Gone. > This page will start a brand new session, redirect them back to > the index page and the user will have to start all over. > > This is not an issue if the user has their browser allow cookies. > However, if cookies are disabled the user is screwed and I'm > trying to find a way to avoid that. One way is to include java > script on that first page that does: > > history.forward(); > > so if they hit the back button, it'll automatically send them to > the page they should be at so the session isn't restarted (well, > another session will be started but they'll still have their old > session ID in the URL). My question was posed to find out if > there is another way besides the above. I'm seeing now that > there probably isn't one. > > Chris

« previous php.general (#19387) next »