Re: Sessions and URLs without ? or &

From: Date: Wed, 06 Dec 2000 20:52:18 +0000
Subject: Re: Sessions and URLs without ? or &
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-28985@lists.php.net to get a copy of this message
In my opinion, using session IDs in the URL can be risky, in so far as it is possible for a spider to go crazy and bring down your site with endless requests (as I have had unfortunate experience with). But the benefits can certainly outweigh the risks. A list of known HTTP_USER_AGENTs of search engines can be found online (sorry that I don't have an URL handy). And as you suggest, you can search for each of these before putting a session ID in the URL. For added protection, perhaps you can put the session ID as the first directory in your URLs and block all session dirs in robots.txt. In other words, you could turn the URL http://www.foo.bar/products/widget into http://www.foo.bar/sessions/session12345fgr/products/widget only when you check to see that it isn't a known spider, and ban all robots from /sessions/ in robots.txt. HTH me@artwells.com http://www.artwells.com/ That which indicates nothing introduces everything. On Wed, 6 Dec 2000, Andy Clarke wrote: > I am using sessions to track the user's movements around a website and as I > can't rely on the user accepting cookies, I am passing this from page to > page as part of the URL. > > On the basis of the recent mailings on simple, search engine-friendly URLs, > I would like to use links from page to page in the form > http://www.foo.bar/products/widget > > I presume that the session ID would have to be passed as another > "directory-like" parameter at the end of the URL - ie in the form > http://www.foo.bar/products/widget/234ji8h8h34j32h48sdf (or > whatever), but > this seems undesirable as the session ID will be included in the link from > the search engine. > > It means, for instance, that every visitor coming from the search engine > will have the session ID in their URL. It also negates the other main > benefit of passing parameters in this way - that the url is short and > logical (people typing in the URL will not know that they don't need the > "234ji8h8h34j32h48sdf" section to go the the correct product page). > > What is the best solution to this problem? One way that I can see would be > to find out whether the visiting browser is a web-crawling robot and leave > off the session ID section of the URLs for all non-human visitors to the > site. Would HTTP_USER_AGENT help with this, and if so, what would I have to > look for in it? > > Alternatively, is there a way of passing the session ID from one page to > another without using cookies and without it appearing in the URL? > > Any alternative suggestions would also be appreciated. > > > Thanks > > Andy Clarke > > > ----------------------------- > Andy Clarke > 78 West Kensington Court > Edith Villas > London W14 9AB > > Phone: 44 (0)20 7602 3382 > Mobile: 07947 418177 > Email: andy@kinonet.com > ----------------------------- > > > >

« previous php.general (#28985) next »