Cookie semi-security.

From: Date: Wed, 24 Jan 2001 22:06:50 +0000
Subject: Cookie semi-security.
Groups: php.general 
Request: Send a blank email to php-general+get-36495@lists.php.net to get a copy of this message
Stupid question, but I'm stumped. I'm passing a persons id through a cookie, then using that to determine if they're allowed to be doing what they're trying to do (change listings, etc.). Right now, I'm getting the value of the cookie by just accessing $cookie_id, without anything fancy. The problem is, if someoen just denies a cookie and adds ?cookie_id=9 at the end, they might as well be the person with an id of 9. Is there a way for me to check and be sure that that value came from a cookie, and not the url bar?

« previous php.general (#36495) next »