secure cookie
| From: | Hardy Merrill | Date: | Tue, 07 Nov 2000 15:44:56 +0000 |
| Subject: | secure cookie | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-24105@lists.php.net to get a copy of this message | ||
I asked this question a week or two ago but got no responses -
please help.
I'm wondering how to tell if the user's browser connection
is "secure"? I was trying to use a secure password cookie
to tell, thinking that the secure cookie wouldn't be passed
to the server if the connection wasn't secure(should be
HTTPS if secure), but that doesn't seem to work - the cookie
is being passed even when the connection is NOT secure.
This is how I'm setting the secure cookie:
setcookie("secure_cookie", $secure_cookie, 0, "", "", 1); // 1=secure
Am I doing this wrong? Is there a bug in PHP causing the
"secure" cookie to be sent to the browser even if there is
NOT a secure connection? Is there another way to tell if
the browser has a secure connection?
TIA.
--
Hardy Merrill
Mission Critical Linux, Inc.
http://www.missioncriticallinux.com