RE: [PHP] Deleting session vars
| From: | Maxim Maletsky | Date: | Tue, 31 Oct 2000 11:32:46 +0000 |
| Subject: | RE: [PHP] Deleting session vars | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-22917@lists.php.net to get a copy of this message | ||
wait a minute, sessions are using cookies, it's authenticating the UNIQUE
SID registered in my browser,
so at the same time Maxim and Boris can browse the same area.
Your server simply checks for my cookie (if session started), gets the SID
and pulls the data out from Hard Drive.
If you register something into the database you need then UPDATE staff SET
whatever=whatever WHERE SID=$SID, so in this case we do not overwrite each
other.
right?
tell me I am wrong...
I think I just misunderstood your question ..
-----Original Message-----
From: Boris Crismancich [mailto:crismancich@wettermacher.de]
Sent: Tuesday, October 31, 2000 8:24 PM
To: Maxim Maletsky
Subject: Re: [PHP] Deleting session vars
Imagine youre on a page and youre member... you log in with your name and
your password.
name="name" value="Maxim"
name="password" value="dunno"
are submitted to the PHP script.
_____________________________
script:
Session Var "userid" is registered.
If name and pasword are correct,
userid is set to name: $userid = $name;
______________________________
Now youre surfing through the Site saving sth to your Profile.
Now your friend wants to enter his Profile (Same computer, sessions still
registered)
and loggs in with following Form data:
name="name" value="Boris"
name="password" value="askme"
Now the same Login Script registers "userid"
and now should look wether askme is the right
password for Boris, but sadly $name still contains
Maxim. So there seems to be sth like a reference between
$name and $userid, but I have not set it.
When I leave out Session_start(), anything works ok.
But then I cant register Boris as new User ID.