RE: [PHP] Deleting session vars

From: Date: Tue, 31 Oct 2000 11:32:46 +0000
Subject: RE: [PHP] Deleting session vars
Groups: php.general 
Request: Send a blank email to php-general+get-22917@lists.php.net to get a copy of this message
wait a minute, sessions are using cookies, it's authenticating the UNIQUE SID registered in my browser, so at the same time Maxim and Boris can browse the same area. Your server simply checks for my cookie (if session started), gets the SID and pulls the data out from Hard Drive. If you register something into the database you need then UPDATE staff SET whatever=whatever WHERE SID=$SID, so in this case we do not overwrite each other. right? tell me I am wrong... I think I just misunderstood your question .. -----Original Message----- From: Boris Crismancich [mailto:crismancich@wettermacher.de] Sent: Tuesday, October 31, 2000 8:24 PM To: Maxim Maletsky Subject: Re: [PHP] Deleting session vars Imagine youre on a page and youre member... you log in with your name and your password. name="name" value="Maxim" name="password" value="dunno" are submitted to the PHP script. _____________________________ script: Session Var "userid" is registered. If name and pasword are correct, userid is set to name: $userid = $name; ______________________________ Now youre surfing through the Site saving sth to your Profile. Now your friend wants to enter his Profile (Same computer, sessions still registered) and loggs in with following Form data: name="name" value="Boris" name="password" value="askme" Now the same Login Script registers "userid" and now should look wether askme is the right password for Boris, but sadly $name still contains Maxim. So there seems to be sth like a reference between $name and $userid, but I have not set it. When I leave out Session_start(), anything works ok. But then I cant register Boris as new User ID.

« previous php.general (#22917) next »