Re: secure cookie

From: Date: Tue, 07 Nov 2000 16:58:31 +0000
Subject: Re: secure cookie
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-24127@lists.php.net to get a copy of this message
I also discovered that there's an Apache Environment variable called "HTTPS" - that has a value of "on" if you have a secure connection, or is "empty"(or unset) if you do *NOT* have a secure connection. Wico de Leeuw [wico@cnh.nl] wrote: > Hiya > > if you configured ssl for you server just check if the port the client > connected to was 443 > if so its secure else it is unsecure (80) <? PHP_INFO(); ?> > > Greetz > > Wico > > At 10:44 7-11-00 -0500, Hardy Merrill wrote: > >I asked this question a week or two ago but got no responses - > >please help. > > > >I'm wondering how to tell if the user's browser connection > >is "secure"? I was trying to use a secure password cookie > >to tell, thinking that the secure cookie wouldn't be passed > >to the server if the connection wasn't secure(should be > >HTTPS if secure), but that doesn't seem to work - the cookie > >is being passed even when the connection is NOT secure. > > > >This is how I'm setting the secure cookie: > > > >setcookie("secure_cookie", $secure_cookie, 0, "", "", 1); // > >1=secure > > > >Am I doing this wrong? Is there a bug in PHP causing the > >"secure" cookie to be sent to the browser even if there is > >NOT a secure connection? Is there another way to tell if > >the browser has a secure connection? > > > >TIA. > > > >-- > >Hardy Merrill > >Mission Critical Linux, Inc. > >http://www.missioncriticallinux.com > > > >-- > >PHP General Mailing List (http://www.php.net/) > >To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > >For additional commands, e-mail: php-general-help@lists.php.net > >To contact the list administrators, e-mail: php-list-admin@lists.php.net -- Hardy Merrill Mission Critical Linux, Inc. http://www.missioncriticallinux.com

« previous php.general (#24127) next »