Re: secure cookie
| From: | Hardy Merrill | Date: | Tue, 07 Nov 2000 16:58:31 +0000 |
| Subject: | Re: secure cookie | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-24127@lists.php.net to get a copy of this message | ||
I also discovered that there's an Apache Environment variable
called "HTTPS" - that has a value of "on" if you have a secure
connection, or is "empty"(or unset) if you do *NOT* have a
secure connection.
Wico de Leeuw [wico@cnh.nl] wrote:
> Hiya
>
> if you configured ssl for you server just check if the port the client
> connected to was 443
> if so its secure else it is unsecure (80) <? PHP_INFO(); ?>
>
> Greetz
>
> Wico
>
> At 10:44 7-11-00 -0500, Hardy Merrill wrote:
> >I asked this question a week or two ago but got no responses -
> >please help.
> >
> >I'm wondering how to tell if the user's browser connection
> >is "secure"? I was trying to use a secure password cookie
> >to tell, thinking that the secure cookie wouldn't be passed
> >to the server if the connection wasn't secure(should be
> >HTTPS if secure), but that doesn't seem to work - the cookie
> >is being passed even when the connection is NOT secure.
> >
> >This is how I'm setting the secure cookie:
> >
> >setcookie("secure_cookie", $secure_cookie, 0, "", "", 1); //
> >1=secure
> >
> >Am I doing this wrong? Is there a bug in PHP causing the
> >"secure" cookie to be sent to the browser even if there is
> >NOT a secure connection? Is there another way to tell if
> >the browser has a secure connection?
> >
> >TIA.
> >
> >--
> >Hardy Merrill
> >Mission Critical Linux, Inc.
> >http://www.missioncriticallinux.com
> >
> >--
> >PHP General Mailing List (http://www.php.net/)
> >To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> >For additional commands, e-mail: php-general-help@lists.php.net
> >To contact the list administrators, e-mail: php-list-admin@lists.php.net
--
Hardy Merrill
Mission Critical Linux, Inc.
http://www.missioncriticallinux.com